Systems and methods for access control policy management
A computer-implemented method and system for managing access control policies for diverse database tables. The method involves consolidating access control by associating each table with a common set of access control policies, enforcing these policies to control access, and providing automated management without administrator input. The automated management includes auditing the policies, detecting discrepancies, and remedying them by modifying the policies. The system comprises at least one physical processor and memory containing instructions that, when executed, perform the method described.
1 . A computer-implemented method comprising:
consolidating, by a computing device of a security management system, access control to a set of diverse database tables by associating each table in the set of diverse database tables with a set of common access control policies, at least two of the tables in the set of diverse database tables being unrelated but for the set of common access control policies;
enforcing, by the computing device of the security management system, the set of common access control policies to control access to each table in the set of diverse database tables; and
providing, by the computing device of the security management system and without administrator input, automated management of the set of common access control policies.
2 . The computer-implemented method of claim 1 , wherein providing the automated management of the set of common access control policies comprises performing, without administrator input:
auditing the set of common access control policies;
detecting a discrepancy during the audit of the set of common access control policies; and
remedying the discrepancy by modifying the set of common access control policies.
3 . The computer-implemented method of claim 2 , wherein:
detecting the discrepancy comprises determining that the set of access control policies allow unauthorized access to the set of diverse database tables; and
remedying the discrepancy by modifying the set of common access control policies comprises removing the unauthorized access.
4 . The computer-implemented method of claim 2 , wherein:
detecting the discrepancy comprises determining that at least one access control in the set of common access control policies has been removed or modified; and
remedying the discrepancy by modifying the set of common access control policies comprises restoring the at least one access control that had been removed or modified.
5 . The computer-implemented method of claim 1 , wherein providing automated management of the set of common access control policies comprises managing access to a key used to encrypt data stored in the set of diverse database tables.
6 . The computer-implemented method of claim 1 , wherein providing automated management of the set of common access control policies comprises aggregating contextual information about the set of diverse database tables.
7 . The computer-implemented method of claim 6 , wherein the contextual information comprises at least one of access frequency, data lineage, and criticality ranking.
8 . A system comprising:
at least one physical processor; and
physical memory comprising computer-executable instructions that, when executed by the physical processor, cause the physical processor to:
consolidate, by a computing device of a security management system, access control to a set of diverse database tables by associating each table in the set of diverse database tables with a set of common access control policies, at least two of the tables in the set of diverse database tables being unrelated but for the set of common access policies;
enforce, by the computing device of the security management system, the set of common access control policies to control access to each table in the set of diverse database tables; and
provide, by the computing device of the security management system and without administrator input, automated management of the set of common access control policies.
9 . The system of claim 8 , wherein the computer-executable instructions cause the physical processor to provide the automated management of the set of common access control policies by performing, without user input:
auditing the set of common access control policies;
detecting a discrepancy during the audit of the set of common access control policies; and
remedying the discrepancy by modifying the set of common access control policies.
10 . The system of claim 9 , wherein:
detecting the discrepancy comprises determining that the set of common access control policies allow unauthorized access to the set of diverse database tables; and
remedying the discrepancy by modifying the set of common access control policies comprises removing the unauthorized access.
11 . The system of claim 9 , wherein:
detecting the discrepancy comprises determining that at least one access control in the set of common access control policies has been removed or modified; and
remedying the discrepancy by modifying the set of common access control policies comprises restoring the access control.
12 . The system of claim 8 , wherein the computer-executable instructions cause the physical processor to provide the automated management of the set of common access control policies by managing access to a key used to encrypt data stored in the set of diverse database tables.
13 . The system of claim 8 , wherein the computer-executable instructions cause the physical processor to provide the automated management of the set of common access control policies by aggregating contextual information about the set of diverse database tables.
14 . The system of claim 13 , wherein the contextual information comprises at least one of access frequency, data lineage, and criticality ranking.
15 . A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:
consolidate, by a computing device of a security management system, access control to a set of diverse database tables by associating each table in the set of diverse database tables with a set of common access control policies, at least two of the tables in the set of diverse database tables being unrelated but for the set of common access control policies;
enforce, by the computing device of the security management system, the set of common access control policies to control access to each table in the set of diverse database tables; and
provide, by the computing device of the security management system and without administrator input, automated management of the set of common access control policies.
16 . The non-transitory computer-readable medium of claim 15 , wherein the computer-executable instructions cause the computing device to provide the automated management of the set of common access control policies by, without administrator input:
auditing the set of common access control policies;
detecting a discrepancy during the audit of the set of common access control policies; and
remedying the discrepancy by modifying the set of common access control policies.
17 . The non-transitory computer-readable medium of claim 16 , wherein:
detecting the discrepancy comprises determining that the set of common access control policies allow unauthorized access to the set of diverse database tables; and
remedying the discrepancy by modifying the set of common access control policies comprises removing the unauthorized access.
18 . The non-transitory computer-readable medium of claim 16 , wherein:
detecting the discrepancy comprises determining that at least one access control in the set of common access control policies has been removed or modified; and
remedying the discrepancy by modifying the set of common access control policies comprises restoring the at least one access control that had been removed or modified.
19 . The non-transitory computer-readable medium of claim 15 , wherein the computer-executable instructions cause the computing device to provide the automated management of the set of common access control policies by managing access to a key used to encrypt data stored in the set of diverse database tables.
20 . The non-transitory computer-readable medium of claim 15 , wherein the computer-executable instructions cause the computing device to provide the automated management of the set of common access control policies by aggregating contextual information about the set of diverse database tables.