One of the major threats that an enterprise Information system networks are facing today is the Insider threat. As part of the Insider Threat study, lack of an effective access control mechanism is identified as one of the major causes that facilitated IT sabotage. In this paper we propose a network access control meta model as per ISO/IEC security evaluation criteria - Common Criteria to provide a framework for implementing an Insider threat protection security solution for network computing environment. We used formal specification notation language Z to specify the proposed model. The paper concludes with a case study along with model verification.
Manpreet Singh, Manjeet S. Patterh