Authorization in Action
暫譯: 行動中的授權

Windley, Phil

  • 出版商: Manning -滿千折百
  • 出版日期: 2026-09-22
  • 售價: $2,720
  • 貴賓價: 9.5$2,584
  • 語言: 英文
  • 頁數: 426
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1633435172
  • ISBN-13: 9781633435179
  • 相關分類: Penetration-test
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Get the eBook free when you register your print book at Manning.

Stale permissions and manual access policy enforcement are a constant security risk. Dynamic authorization--automatic systems that eliminate permanent access grants and manual review-and-revise processes--can radically improve access control. This practical, focused book shows you how to switch from crude yes/no permissions to flexible, policy-driven rules that adapt instantly.

Access control needs evolve as users require short-term data access, location-based services, temporary work assignments, or changing employment status. Dynamic authorization systems adapt access in real time. This book presents a view of dynamic authorization that merges role-based, attribute-based, and relationship-based models into a single framework. You'll learn exactly how dynamic authorization works, as well as the governance, architecture, and team structures necessary to sustain the approach in the enterprise.

Authorization in Action shows you how to:

- Establish RBAC, ABAC, and ReBAC for dynamic authorization
- Design adaptive access control policies
- Implement policy-based access control (PBAC)
- Integrate decision logic with organizational data
- Establish clear authorization governance structures

About the book

Authorization in Action comes to life through the all-too-real access control struggles facing the fictional ACME Corp's customer, HR, and engineering systems. Step-by-step walkthroughs make these examples concrete, while real-world incidents--like the Target data breach--show what's at stake when authorization goes wrong. You'll implement a dynamic authorization framework integrating the Cedar authorization policy language and the RBAC, ABAC, and ReBAC models, and you'll design adaptive policies that reflect real business rules. Plus, you'll build governance structures with clear ownership, aligned teams, and processes to review, audit, and evolve at scale.

About the reader

For IT workers, executives, directors, and product managers who know the basics of systems architecture.

About the author

Phil Windley is co-founder and organizer of the Internet Identity Workshop and Executive Director of the IIW Foundation, advancing human-centered digital identity. He was Founding Chair of the Sovrin Foundation (2016-2020) and most recently served as Senior Software Development Manager at AWS Identity.

商品描述(中文翻譯)

在Manning註冊您的印刷書籍時可免費獲得電子書。

過時的權限和手動訪問政策執行始終是一個安全風險。動態授權——自動系統消除永久訪問授權和手動審查及修訂過程——可以徹底改善訪問控制。本書實用且專注,展示了如何從粗糙的是/否權限轉變為靈活的、政策驅動的規則,這些規則能夠即時適應。

隨著用戶對短期數據訪問、基於位置的服務、臨時工作任務或變更的就業狀態的需求,訪問控制需求也在不斷演變。動態授權系統能夠實時調整訪問。本書呈現了一種動態授權的觀點,將基於角色(RBAC)、基於屬性(ABAC)和基於關係(ReBAC)的模型合併為一個單一框架。您將學習動態授權的具體運作方式,以及在企業中維持該方法所需的治理、架構和團隊結構。

授權實踐將教您如何:

- 建立動態授權的RBAC、ABAC和ReBAC
- 設計自適應訪問控制政策
- 實施基於政策的訪問控制(PBAC)
- 將決策邏輯與組織數據整合
- 建立清晰的授權治理結構

關於本書

授權實踐通過虛構的ACME Corp客戶、HR和工程系統所面臨的真實訪問控制挑戰而生動呈現。逐步的操作指導使這些例子具體化,而現實世界的事件——如Target數據洩露——則顯示了當授權出錯時的風險。您將實施一個動態授權框架,整合Cedar授權政策語言以及RBAC、ABAC和ReBAC模型,並設計反映真實商業規則的自適應政策。此外,您還將建立具有明確所有權、對齊團隊和流程的治理結構,以便進行審查、審計和大規模演變。

關於讀者

本書適合了解系統架構基礎的IT工作者、高管、主管和產品經理。

關於作者

Phil Windley是互聯網身份研討會的共同創始人和組織者,以及IIW基金會的執行董事,推進以人為本的數字身份。他曾擔任Sovrin基金會的創始主席(2016-2020),最近擔任AWS身份的高級軟體開發經理。

作者簡介

Phil Windley is co-founder and organizer of the Internet Identity Workshop and Executive Director of the IIW Foundation, advancing human-centered digital identity. He was Founding Chair of the Sovrin Foundation (2016-2020) and most recently served as Senior Software Development Manager at AWS Identity.

作者簡介(中文翻譯)

菲爾·溫德利是網路身份工作坊的共同創辦人和組織者,以及IIW基金會的執行董事,致力於推進以人為中心的數位身份。他曾擔任Sovrin基金會的創始主席(2016-2020),最近則在AWS身份擔任高級軟體開發經理。

最後瀏覽商品 (20)