SECURITY POLICY TOOL

Network, System, IoT, and Cloud data breach often occur due to the presence of unintended access control holes that leave online resources unprotected:

  • Did you verify your XACML rules/policies in terms of security (NIST SP 800-192) before operations?
  • Do you know if there are any hidden privilege leaks (see Access Control Error Types) in your access control rules/policies?
  • Do you want to save time and cost in development of XACML policies?
  • Do you want to acquire more customers to improve their access control security?

Security Policy Tool is a leading access control solution that equips you to answer “Yes” to all the above capabilities. It allows you to easily develop highly secure access control rules/policies, to extinguish the threat of cyber-attacks and insiders exploiting access control security vulnerabilities.


Security Policy Tool helps you ensure that your access control policies are fully secure before implementing them into an Access Control System.

PRODUCT FEATURES

Please click the icon of the topic you’d like to learn more about or simply begin scrolling to view all information in order.

Security Policy Tool

Getting Started

Download and start using Security Policy Tool today

Designing Access Control Policies

ABAC, MLS, Workflow access control policy modeling

Testing/Verifying Access Control Policies

Combinatorial Test Suite and Individual Security Requirement testing

Identifying Errors in Your Access Control Policies

User-friendly testing result presentation for efficient error inspection

XACML Editor

Getting Started

Download and start using the Security Policy Tool - XACML Editor today

Creating XACML Policies

Intelligent and assistive XACML policy creation and editing

SECURITY POLICY TOOL




Getting Started

To get access to Security Policy Tool you first need to create an account…

  • Haven’t signed up or downloaded yet? Click here!
  • Load Security Policy Tool and if prompted enter in the Username and Password you created during sign-up
  • Click on Blank Project (left) to begin exploring
  • Create access control policies, test your policies for errors, and analyze your results all in one user-friendly framework




Designing Access Control Policies

Security Policy tool makes designing and modeling your access control policies easy…

  • Define Your Attributes (Subjects, Resources, Actions, etc.)
  • Define Inheritance Privileges for hierarchical organizations
  • Begin Modeling Your Policies (ABAC, Multilevel, Workflow)
  • Verify, Review, Search, and Manage a number of rules and policies effectively
  • Export your policies, giving you full power of your own system




Testing/Verifying Access Control Policies

Due to the complex nature of designing access control policies, errors can easily occur. Security Policy Tool enables you to systematically test your policies to help you prevent access control leaks (e.g. data breach) as a result of these errors…

  • Test one or multiple policies through a merging or a combining policy testing process
  • Create individual security requirements to test your policy for specific access requests
  • Combinatorial Test Suite enables you to automatically generate (>99 %) testing coverage by pairwise or all-pairs attribute combinatorial algorithms.
  • Verify the effectiveness (i.e., Permit or Deny) of your policy in comparison to these security requirements or test cases
  • Test for Separation of Duty errors to ensure there are no conflicts among two or more security requirements






Identifying Errors in Your Access Control Policies

Security Policy Tool has powerful analyzing functions to help policy authors inspect and correct access control errors…

  • View individual security requirements vs. actual policy rules
  • Verify the absence of conflicts of interest among rules with separation of duty
  • Resource accessibility for a given Subject and the rule combining algorithms
  • Subject accessibility for a given Resource and the rule combining algorithms

XACML EDITOR




Getting Started

To get access to the XACML Editor you first need to create an account…

  • Haven’t signed up or downloaded yet? Click here!
  • Load Security Policy Tool and if prompted enter in the Username and Password you created during sign-up
  • Click on XACML Editor (right) to begin exploring
  • Create and edit your access control XACML (2.0, 3.0) policies in one user-friendly place




Creating Your Policies

This XACML Editor included within Security Policy Tool has been developed with efficiency and user-friendliness in mind…

  • GUI & Text-based Editing
  • XACML 2.0/3.0 Compatibility
  • Editing Intelligence
  • XACML Syntax Checker and Indicator
  • Import/Export Management