Previous Topic: Identify Resources and Roles

Next Topic: Define Access Control Requirements

Define Task-Assessment Requirements

Task assessment requirements bridge the gap between roles and access-control requirements. When you identify task-assessment requirements, you define the tasks each role performs using the resource.

How this applies to policies:

Although tasks are not specifically defined in policies, you will use this information when assessing access rights for each resource-role pairing in the next section.

To define task-assessment requirements

  1. For each role, identify the tasks the role must perform using the resource.
  2. Enter the task in the Task column, next to the associated resource and role.

More information:

Define Access Control Requirements

How a Security Model Requirements Table Is Created

How Organization and Resource Requirements Are Established

Define Implementation Requirements