How does User-SDL-Policy Enforcement Work?
Interactions
Building Blocks
In the diagram below you cans see how end users and administrators interact with various NC Protect core architectural building blocks such as:
-
PEP (Policy Enforcement Point)
-
PAP (Policy Administration Point)
-
PDP (Policy Decision Point)
-
PIP (Policy Information Point)
Also see NC Protect v9.x Deployment Architecture
User Interaction Details
Use the diagram below in addition to these steps to envision the interaction between users and NC Protect v9.x components.
-
Data and user attributes are defined in the PIP and mapped within the PAP.
-
Administrator creates a data access policy via the PAP user interface.
-
Policies are committed within the PAP Data Access Policies repository.
-
End Users accesses the Secure Document Library.
-
Access request and user attributes are captured by the PEP.
-
The PEP obtains data attributes from SharePoint. These attributes are passed to PDP for access evaluation.
-
PDP makes decision and sends results to the PEP to enforce the decision.
