×

Evaluating removal of access permissions

  • US 8,239,925 B2
  • Filed: 04/26/2007
  • Issued: 08/07/2012
  • Est. Priority Date: 04/26/2007
  • Status: Active Grant
First Claim
Patent Images

1. A method of eliminating membership of a person in a user group which has access permissions to storage elements in an enterprise, the method comprising:

  • initially specifying by a computer a proposed person and a proposed user group in which said proposed person is a member, wherein membership of said proposed person in said proposed user group is proposed to be eliminated;

    thereafter ascertaining actually accessed storage elements which were actually accessed by said proposed person in the past;

    thereafter for each of said actually accessed storage elements, ascertaining which authorized user groups have access permissions thereto;

    thereafter ascertaining in which of said authorized user groups said proposed person has membership;

    thereafter for each of said actually accessed storage elements, ascertaining that said person has membership in at least one of said authorized user groups having access permissions thereto, other than said proposed user group; and

    proceeding to eliminate said membership of said proposed person in said proposed group, only if each of said actually accessed storage elements has access permissions thereto from said at least one of said authorized user groups in which said person has membership, other than said proposed user group.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×