Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Monday, November 26, 2007

On Policies and Policy Management: Present and Future …

I have recently given a presentation on the topic of Policies and Policy Management. My presentation is available online, here.

This topic is extremely complex, considering the variety of aspects to be kept into account. This presentation reflects my (high-level) view about current status and some of the potential future research areas.

In the introduction part I tried to describe the concepts of policy and policy management from a wide perspective, highlighting some of the open issues and involved complexity. I’ve also described some of current HPL R&D work in the space of policy management applied to identity and privacy management.

I have then highlighted a few future R&D activities in this space that might be worth exploring. They include:
  • Policy Refinement Process
  • “Federated Policy Management” in Organisations
  • Management of “Sticky Policies” in Information Flow
  • Content-aware Access Control in Collaborative (Enterprise Web 2.0) Environments driven by Policies
  • Overall Policy Lifecycle Management

Last but not least, I described again the opportunity of getting involved in the newly created W3C Policy Languages Interest Group and contributing to it.

Your comments and input are welcome.

--- NOTE: my original HP blog can be found here ---


No comments: