IDEF Functional Model AUTHORIZATION: Difference between revisions

From IDESG Wiki
Jump to navigation Jump to search
m (3 revisions imported: Initial Upload of old pages from IDESG Wiki)
 
 
Line 5: Line 5:
''<< Back to [[Baseline Functional Requirements v1.0|Baseline Functional Requirements Index]]''
''<< Back to [[Baseline Functional Requirements v1.0|Baseline Functional Requirements Index]]''


== "Authorization"==
=="Authorization"==
''Used in the Baseline Functional Requirements v1.0''<br>
''Used in the Baseline Functional Requirements v1.0''<br>


Line 22: Line 22:
| Authorization Decision || Decision to grant and deny access to a resource based on the results of the authorization processes and policies.
| Authorization Decision || Decision to grant and deny access to a resource based on the results of the authorization processes and policies.
|}
|}
[[Category:Authorization]]

Latest revision as of 22:53, 12 April 2020

Error creating thumbnail: File missing
This article is under construction and should not be considered complete.
Last modified by Tomjones

<< Back to IDEF Glossary
<< Back to Digital Identity Management Functions
<< Back to Baseline Functional Requirements Index

"Authorization"

Used in the Baseline Functional Requirements v1.0

"Authorization" is defined in the IDEF Functional Model in part as a "Process of granting or denying specific requests for access to resources."

The Functional Model, published as a PDF here: download link, generally sorts core identity management operations into five categories of activities and services, including identity authorization: a full description of this activity type can be found in that document. Among other things, the Functional Model sets forth the following table of functions included within "authorization" in its Functional Elements Descriptions Matrix:

Authorization Request Process by which ownership of a credential is conferred, confirmed, or associated with a digital identity.
Attribute Control Process of managing and releasing attributes for the purposes of registration or authorization.
Attribute Verification Process of confirming or denying that claimed attributes are correct and meet the pre-determined requirements for authorization; typically, these attributes for authorization have not been bound to the credential or previously available to the organization making the authorization decision.
Authorization Decision Decision to grant and deny access to a resource based on the results of the authorization processes and policies.