Am 28.04.2010 13:15, schrieb Jan-Oliver Wagner: > The problem is: Should this role have the power to decide > on his own which tasks of which users to review > or should the users allow access for their tasks to the observer role?
Well, any "auditor" would have to have read access to any tasks, reports, settings. If you think about a German "Revision", the user is the one to be controlled -- oh, well the process is to be controlled, but that for the auditor need to have access to all information. If you want to let the user decide who may have read-access to his tasks, you may want to think about delegation and groups. This *may* become complex soon and *may* lead to the need of interfacing to LDAP. You may want to define more fine grained access-rights (view reports, create task, start task, etc.) and map roles to them. Like e.g. Zope does it (see <http://docs.zope.org/zope2/zope2book/Security.html#understanding-permissions>). What do you see behind a "dashboard" role? Some role which only seens the summaries? -- Schönen Gruß - Regards Hartmut Goebel Dipl.-Informatiker (univ.), CISSP, CSSLP Goebel Consult Spezialist für IT-Sicherheit in komplexen Umgebungen http://www.goebel-consult.de Monatliche Kolumne: http://www.cissp-gefluester.de/ Goebel Consult mit Mitglied bei http://www.7-it.de
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Openvas-discuss mailing list [email protected] http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss
