[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[TERMINOLOGY]



Below is an extract from David's message with my editorial changes :), which
proposes several resource-related definitions. 

Does anybody have any text edition suggestions for the definitions below? I
suggest to refer to these definitions after we converge on them.

  A RESOURCE is the kind of entity to which access must be controlled.  

Examples of RESOURCEs would be: records in a specific database, drug
prescriptions, medical professionals' credentials, and so on.

  A RESOURCE INSTANCE is a specific example of the entity to
which access must be controlled.  

Examples of RESOURCE INSTANCEs would be: one record in a specific database, a
drug prescription for a specific patient, and the medical
credentials for a specific doctor.

  A RESOURCE ID is the handle, or name, by which a RESOURCE INSTANCE can be
uniquely identified.

  RESOURCE SECURITY METADATA is a set of information, which
is either externally associated with a RESOURCE (e.g., provided
as a label on a file), or is a subset of the data that comprises the RESOURCE
(e.g., the HIV-Result field of a blood-test record),
that is used explicitly by one or more HRAC policies as the
basis for an access decision.

Konstantin

----------------
Broadcast message to hrac-rfp from Konstantin Beznosov <beznosov@baptisthealth.net>.
Go to http://cadse.cs.fiu.edu/omg/hrac-rfp to browse the mail list archive.