A new standard security policy language
Mohamed Almorsy, H. M. Faheem · IEEE Potentials · 2009
The rapid increase and complication of threats on organizations' assets makes developing organizational security policies a pressing need. Organizations should develop policies that regulate and control the access of their assets. Security policies define the guidelines that can be used to determine the security measures to be employed in an organization to keep assets secured. Security officers used to write policies in their natural language, resulting in less readable, less maintainable, and ambiguous policy statements. Consequently, the possibility of developing automation systems for policy management was very low. With the increase of business, organizations developed several security policies to control different assets, systems, and data. These policies are often scattered over different environments and different models. That makes them difficult to be tracked for implementation and updates.