Extending the sparcle privacy policy workbench methods to other policy domains
Abstract
A method and system enable a user to develop domain-specific policy workbench. Domains may include, but are not limited to security, autonomic computing, workload management and systems management. The method and system in one aspect determines syntax of a policy in a selected domain and creates an instance of policy workbench specific to the selected domain. In one aspect, the instance of policy workbench includes at least machine-readable encodings of the selected policy and associated mapping. The instance of policy workbench also includes a compliance auditing tool enabled to check events logged at a target system against the selected policy and associated mapping to determine if one or more policy rules have been complied with. In another aspect, domain-specific policy workbench creation machine is provided that automatically creates an instance of domain-specific policy workbench.
Claims
exact text as granted — not AI-modified1 . A method for creating a policy workbench for a given domain, comprising:
analyzing a domain; and providing a domain-specific policy workbench.
2 . The method of claim 1 , wherein the step of analyzing a domain includes:
determining syntax of one or more policy rules associated with the domain.
3 . The method of claim 2 , wherein the step of determining syntax uses an encoding format as a basis.
4 . The method of claim 2 , wherein the step of providing a domain-specific policy workbench includes:
creating a natural language grammar based on the syntax.
5 . The method of claim 1 , wherein the domain specific policy workbench provides an encoded rendering of a given policy.
6 . The method of claim 5 , wherein the encoding is XML-based.
7 . The method of claim 6 , wherein the XML-based encoding uses the OASIS XACML standard.
8 . The method of claim 1 , wherein the domain includes security, autonomic computing, workload management, or systems management, or combination thereof.
9 . The method of claim 1 , wherein providing the domain-specific policy workbench further includes:
providing one or more mappings between one or more policy-rule elements and one or more domain elements.
10 . The method of claim 9 , further including:
obtaining one or more system activity events from a log; using the one or more mappings to translate the one or more system activity events into policy language; and comparing translated events to policy rules.
11 . A method of creating a domain-specific policy workbench, comprising:
determining syntax of a policy in a selected domain; creating an instance of policy workbench specific to the selected domain.
12 . The method of claim 11 , further including:
determining whether creating a policy for the selected domain is feasible, and if it is determined that creating a policy for the selected domain is feasible, performing the step of creating.
13 . The method of claim 11 , wherein the step of creating includes at least:
invoking an authoring tool creation handler to create an authoring tool operable to allow a practitioner to author a selected policy; invoking a policy and mapping data handler creation handler to create a policy and mapping data handler operable to create a policy workbench instance including at least a machine-readable encodings of the selected policy and associated mapping; and invoking a compliance auditing tool creation handler to create a compliance auditing tool operable to allow a practitioner to audit compliance of system activities according to the selected policy and the associated mapping.
14 . The method of claim 13 , wherein the step of creating further includes at least:
invoking a practitioner identification handler to identify one or more practitioners; and invoking a practitioner skill identification handler to determine skills of the one or more practitioners.
15 . The method of claim 13 , wherein the step of creating further includes at least:
invoking a mapping handler to determine one or more mappings between one or more elements of a target system and the selected policy.
16 . A system for creating a domain-specific policy workbench, comprising:
a policy grammar handler operable to determine syntax of a policy in a selected domain; a policy and mapping data handler creation handler operable to create a policy and mapping data handler operable to create a policy workbench instance including at least a machine-readable encodings of the selected policy and associated mapping; and a compliance auditing tool creation handler operable to create a compliance auditing tool operable to allow a practitioner to audit compliance of system activities according to the selected policy and the associated mapping.
17 . The system of claim 16 , further including at least:
a practitioner identification handler operable to identify one or more practitioners; and a practitioner skill identification handler operable to determine skills of the one or more practitioners.
18 . The system of claim 16 , further including at least:
a mapping handler operable to determine one or more mappings between one or more elements of a target system and the selected policy.
19 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform a method of creating a domain-specific policy workbench, comprising:
determining syntax of a policy in a selected domain; creating an instance of policy workbench specific to the selected domain.
20 . The program storage device of claim 19 , wherein the step of creating includes at least:
invoking an authoring tool creation handler to create an authoring tool operable to allow a practitioner to author a selected policy; invoking a policy and mapping data handler creation handler to create a policy and mapping data handler operable to create a policy workbench instance including at least a machine-readable encodings of the selected policy and associated mapping; and invoking a compliance auditing tool creation handler to create a compliance auditing tool operable to allow a practitioner to audit compliance of system activities according to the selected policy and the associated mapping.Join the waitlist — get patent alerts
Track US2008040343A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.