An Operating System cannot secure everything

I do not know much about Axiomatics but their ad caught my eye. And got me thinking it was time to write a quick blog entry.

Axiomatics have a product that implements what they call ABAC - Attribute Based Access Control. They state that this goes beyond RBAC - Role Based Access Control. And I agree - from an architectural (i.e., the layers of an onion) viewpoint - that they are correct.

I hope this triggers a thought process in you as it did in me and remember that as you think about how to keep your system secure you need to remember security is implemented layer by layer.

Over the years new technologies appear - and define new layers. Over 30 years ago simple file protection bits was enough, then technologies like sudo became the next layer, and now at the OS level we have RBAC technologies and at application level a new (open) standard - XAMCL .


