3 ms·
> The body said "purpose-based access control" was a term which had been used in the computing industry for 20 years I can find references to "policy-based acc
by jka 4y ago
> The body said "purpose-based access control" was a term which had been used in the computing industry for 20 years
I can find references to "policy-based access control" (same acronym) going back decades (and plenty of mentions of the widely-used and understood RBAC) but not purpose-based access control. Is it the same thing, or is there some confusion here?
- OJFord 4y agoI'm not sure if this [0] (2007) is introducing the term, or just one such model an using the term to describe it. Not obviously associated with Palantir. I hadn't heard it before either. [0] - https://ieeexplore.ieee.org/document/4299765/authors https://ieeexplore.ieee.org/document/4299765/authors
- lloydatkinson 4y agoWell knowing how poorly previous NHS IT projects have gone historically, and how there have always been vast layers of useless middle management in these NHS IT projects, and how much corruption and back room deals are prevalent in the Conservative government it would not surprise me to find out it’s just RBAC under a different name for obfuscation and removal of accountability via vague requirements that turn into deliberate money pits.