摘要 |
In an information technology (IT) environment, a technique to manage privileges given to personnel to whom a process is assigned. An information processor includes: a configuration management database that stores resources, personnel, processes, and privileges provided on the resources as configuration items, respectively, the configuration management database prescribing relations between the configuration items including a privilege-dependency relationship between a privilege on a resource and a privilege on another resource required to exercise the privilege, a privilege-request relationship between a process and a privilege required for the process, and a privilege-giving relationship between the personnel and the privilege given to the personnel; and a privilege deriving unit for deriving a goal state of a privilege to be given to corresponding personnel by following the relation with the privilege on the resource required for a process to be executed used as a reference point by referring to the configuration management database. |