Methods of Data Processing Restriction in ERP Systems

Pavlo Zhezhnych, Dmytro Tarasov · 2018 IEEE 13th International Scientific and Technical Conference on Computer Sciences and Information Technologies (CSIT) · 2018

Minimizing of risks caused by data processing and related to the violation of information security is an important task of ERP-system management. This paper discusses methods of data processing restriction that largely allow avoiding of situations that lead to information security violations. The proposed methods called CU`D' and CU' are based on discovering of peculiarities of needs to manipulate data at different stages of processing that mean limited usage of Update and Delete data operations. These peculiarities allow forming of transition maps between data processing stages and the corresponding rules of applying of data manipulation operations. The advantage of the developed methods is the possibility of their implementation at the logical level of a database with a set of views without any development of special software units. The methods allow reducing rates of violations of data confidentiality and integrity caused by Update and Delete operations.

Read the paper · More papers on PaperTik