Am 28.04.2010 13:15, schrieb Jan-Oliver Wagner:

> The problem is: Should this role have the power to decide
> on his own which tasks of which users to review
> or should the users allow access for their tasks to the observer role?

Well, any "auditor" would have to have read access to any tasks,
reports, settings. If you think about a German "Revision", the user is
the one to be controlled -- oh, well the process is to be controlled,
but that for the auditor need to have access to all information.

If you want to let the user decide who may have read-access to his
tasks, you may want to think about delegation and groups. This *may*
become complex soon and *may* lead to the need of interfacing to LDAP.

You may want to define more fine grained access-rights (view reports,
create task, start task, etc.) and map roles to them. Like e.g. Zope
does it (see
<http://docs.zope.org/zope2/zope2book/Security.html#understanding-permissions>).

What do you see behind a "dashboard" role? Some role which only seens
the summaries?

-- 
Schönen Gruß - Regards
Hartmut Goebel
Dipl.-Informatiker (univ.), CISSP, CSSLP

Goebel Consult
Spezialist für IT-Sicherheit in komplexen Umgebungen
http://www.goebel-consult.de

Monatliche Kolumne: http://www.cissp-gefluester.de/
Goebel Consult mit Mitglied bei http://www.7-it.de

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Openvas-discuss mailing list
[email protected]
http://lists.wald.intevation.org/mailman/listinfo/openvas-discuss

Reply via email to