Security Design Objectives

The PT application collects and displays information of a sensitive nature in addition to information that is public.The challenge for the design team is to define appropriate access for each type of information.

The highest security priority is to protect the privacy of individuals whose personal information, performance, and group affiliations the PT application tracks. This confidential information must be off-limits to unauthorized persons. On the other hand, the application's security design must allow access to public information such as location data; for example, information about locations is helpful to evaluators when they create schedules.

In addition, users must have confidence in the data the application collects. The information that appears on the PT application's Web pages and the information that results from direct queries on the database tables must be current, complete, and validated by one set of rules.

The security goals for the PT application and the Eval database are as follows: