Showing posts with label Access Control. Show all posts
Showing posts with label Access Control. Show all posts

Wednesday, 16 August 2017

What are the best app development companies in India?

Application Development includes research, new development, modifications, reuse, re- engineering, maintenance or any other activity that results in the finished application. As market changes, the way we do our business and spending on IT activities of our business also changes. This dynamic change not only creates pressure but also open the doors to new opportunities. Therefore today, IT giants must stay on the cutting edge of providing complex solutions with less time-to-market in an affordable manner to its customers.



iFour Technolab Pvt Ltd helps organizations to effectively manage their applications through customized solutions. We provide value to our clients by leveraging our techniques and practices to satisfy our customers’ requirements.
Some of our value adding features in our services is:
  • Domain Knowledge: Our deep industry knowledge and technical expertise to deliver effective results. We provide services to reduce costs and increase productivity.
  • Customized Application: Customized solutions to support individual business needs. We develop applications that are scalable, secure and easily maintainable.
  • Application Maintenance Support: We ensure that our applications are working effectively and efficiently supporting all business requirements. We offer continuous maintenance and support services to ensure long term value adding to our customers.
iFour Technolab Pvt. Ltd. provides application development services in India for various platforms like web, desktop and mobile that includes iOS, Android and Windows mobile. We understand the importance of technology and platform selection and conduct a special walkthrough with customer to discuss and select the right technology platform that suits your requirement and IT infrastructure. We use cutting edge technology for application development and ensure that it is in sync with your IT infrastructure.  Throughout the project lifecycle our focus is on the organization and providing measurable results.

Monday, 12 September 2016

Access Control Domain

custom application development companies

Access control Domain encompasses :

  • Discretionary, Mandatory, and Non-Discretionary models 
  • Identification methods, Authentication methods
  • Accountability, monitoring, and auditing practices 
  • Intrusion detection systems/Intrusion Prevention Systems 
  • Likely threats to access control practices and technologies 
  • A Framework that dictates how Subjects access Objects

The types of Access Control are :

  • DAC
  • MAC
  • RBAC 

Discretionary Access Control – DAC

A system that uses discretionary access control (DAC) allows the holder of the resource to specify which subjects can access specific resources. This model is called discretionary as the control of access is based on the discretion of the owner.

For example, a manager for a definite department in the Custom software development company might be made the holder of the files and resources within his/her domain.

The most common application of DAC is through ACLs, which are spoken and fixed by the owners and enforced by the operating system.


  • DAC permits the privileges i.e. granting and revoking of access control to be left to the discretion of the individual users
  • It is highly flexible 
  • Not appropriate for –
    -- High assurance systems, e.g. a military system 
    -- Many complex commercial security requirements 
  • It is Identity-based 


Mandatory Access Control –MAC

In a mandatory access control (MAC) model, users and data owners do not have asmuch liberty to determine who can access files. The operating system makes the final conclusion and can outweigh the users’ wishes.

This model is much more structured and strict and is based on a security label system. Users are provided a security clearance (secret, top secret, confidential, and undefined), and data is classified in the same way. The clearance and grouped data is stored in the security labels, which are bound to the specific subjects and objects.

A given IT infrastructure in software development company can implement MAC systems in many places and at different levels. OS uses MAC to guard files and directories.
Database management systems apply MAC to regulate access to tables and views. Best commercially available application systems apply MAC, often independent of the operating systems and/or DBMSs on which they are installed.

OS constrains the ability of a subject or initiator to access or perform some operation on the object. Subject is usually a process thread and objects are constructs like files, tcp/udp ports, shared memory segments etc.

Whenever Subject tries to access Object, an authorization rule enforced by the operating system kernel inspects the security attributes and chooses whether access can take place.
Information classification is necessary, label-based

  • Well suited to the requirements of government and industry organizations that process classified and sensitive information 
  • Such environments usually require the ability to control actions of individuals beyond just an individual's capability to access information permitting to how that information is labeled based on its sensitivity 


RBAC 

  • In RBAC model, a role is well-defined in terms of the tasks and operations that the role will need to carry out, whereas a DAC sketches which subjects can access what objects. 
  • RBAC uses a centrally administrated set of controls to determine how subjects and objects act together. This type of model allows access to resources to be based on the role the user holds within the company example Software Development Company
  • A role can be thought of as a set of transactions that a user or set of users can perform within the context of an organization i.e. a collection of permissions.
  • A transaction can be thought of as a transformation procedure plus a set of associated data items 
  • Roles are group oriented; created for job functions 
  • Roles are plotted on the principle of least privilege 
  • Role-based access control policy bases access control decisions on the functions a user is permitted to perform within an organization 
  • RBAC provides a means of naming and describing many-to-many relationships between individuals and rights 
  • A user has access to an object based on the assigned role. 
  • Roles are defined based on job functions. 
  • Permissions are defined based on job authority and responsibilities within a job function. 
  • Operations on an object are invocated based on the permissions. 
  • The object is concerned with the user’s role and not the user. 


Conclusion: 

Thus, the Custom Software Development Company should carry out structured ways for Access Control and assigning roles to the employees based on the privileges. This leads to secure access and intact security in the company or a firm which restrict the entities from using unauthorised information.