Policy Languages and Formal Methods

50 chapters

Chapters

  1. 3 Strengths
    Policy Languages and Formal Methods · 2:54
    Exploring the power of deontic logic as a policy language, this chapter breaks down how concepts like obligation, permission, and conditional duty can precisely capture the complex, layered nature of compliance rules.
  2. 2 Why It Matters for Controls
    Policy Languages and Formal Methods · 2:44
    Exploring why precision in policy language is critical for control systems, this chapter reveals how everyday words like "shall" and "may" carry hidden logical weight—and how informal language can mask dangerous contradictions.
  3. 4 Weaknesses
    Policy Languages and Formal Methods · 2:54
    Diving into the critical vulnerabilities that undermine policy languages, listeners will discover how poor accessibility and complex notation — like deontic logic's intimidating symbols — can cause even well-designed security policies to fail in practice.
  4. 5 Where It Is Useful
    Policy Languages and Formal Methods · 2:58
    Diving into the practical applications of deontic logic, this chapter reveals how obligations, permissions, and prohibitions form the invisible backbone of compliance-driven systems and formal policy frameworks.
  5. 6 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:33
    Exploring the limitations of formal logic, this chapter reveals three key scenarios where policy language and logical notation can actually hinder rather than help, guiding listeners on when to stick with plain, human-readable text instead.
  6. 1 What It Is
    Policy Languages and Formal Methods · 3:26
    Deontic logic provides the foundational framework for reasoning about policies, introducing four key operators that capture the essential concepts of obligation, permission, prohibition, and exemption.
  7. 2 Strengths
    Policy Languages and Formal Methods · 2:54
    Exploring the power of SBVR as a policy language, this track breaks down two key strengths that make it stand out, starting with its human-readable structure that allows compliance officers to understand and work with business rules without needing a background in formal logic.
  8. 3 Weaknesses
    Policy Languages and Formal Methods · 3:24
    Diving into the shortcomings of formal policy languages, this chapter examines why standards like SBVR struggled with adoption and explores the key limitations that prevent current approaches from meeting real-world security and compliance needs.
  9. 1 What It Is
    Policy Languages and Formal Methods · 3:29
    Diving into the origins and purpose of SBVR (Semantics of Business Vocabulary and Rules), this chapter explores how the 2008 OMG standard bridges the gap between human-readable business language and machine-processable logic, empowering stakeholders to express rules naturally while enabling computers to interpret them precisely.
  10. 4 Where It Is Useful Already
    Policy Languages and Formal Methods · 5:01
    Explore the real-world applications of SBVR across industries like banking and insurance, and discover how organizations including the European Commission are using it to formalize regulations and bring clarity to complex business rules.
  11. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:41
    Exploring the limitations of SBVR, this chapter reveals the specific real-world scenarios where the language falls short, including time-sensitive emergency response situations that require procedural action rather than semantic rule abstraction.
  12. 1 What It Is
    Policy Languages and Formal Methods · 2:51
    Dive into the origins and purpose of Attempto Controlled English (ACE), a formal controlled language born in 1995 that transforms structured English into precise first-order logic, setting it apart from business-oriented rule languages like SBVR.
  13. 2 Strengths
    Policy Languages and Formal Methods · 2:15
    Diving into the powerful capabilities of ACE as a mature parsing system, listeners will discover how this tool processes natural language with precision, providing clear formal meanings and explicitly flagging ambiguity when it arises.
  14. 4 Where It Is Useful Already
    Policy Languages and Formal Methods · 2:56
    Exploring real-world applications of Attempto Controlled English (ACE), this chapter examines how formal policy languages are already making an impact in biomedical ontologies, requirements engineering, patent law, and government legal translation.
  15. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:56
    Exploring the boundaries of ACE policy language, this chapter reveals the specific scenarios where it falls short, including real-time requirements, SLA constraints, and sequential incident response workflows that demand procedural structure.
  16. 1 What It Is
    Policy Languages and Formal Methods · 2:49
    Dive into Catala, the innovative programming language developed at Inria that bridges the worlds of law and code, bringing clarity and precision to how legal regulations are formally expressed and implemented.
  17. 2 Strengths
    Policy Languages and Formal Methods · 2:49
    Exploring the power of literate programming, this chapter reveals how embedding policy logic directly alongside natural language explanations eliminates the dangerous gap between documentation and running code, keeping compliance airtight and auditors informed.
  18. 3 Weaknesses
    Policy Languages and Formal Methods · 3:15
    Exploring the three key weaknesses of policy languages, this chapter reveals how natural language accessibility masks complex programming requirements, specialized syntax demands, and the gap between who reads policies and who can actually maintain them.
  19. 4 Where It Is Useful Already
    Policy Languages and Formal Methods · 2:47
    Exploring how the Catala programming language bridges the gap between complex legal statutes and executable code, this chapter examines real-world applications in French housing benefits, tax law, and social security systems where formal policy languages are already making an impact.
  20. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:17
    Exploring the boundaries of formal policy languages, this chapter identifies the organizational and human-centered domains where tools like Catala fall short, including risk appetite statements, board governance, and cultural training initiatives.
  21. 1 What It Is
    Policy Languages and Formal Methods · 3:32
    Dive into Rego, the declarative policy language at the heart of cloud native access control, and discover how it evaluates JSON data to make intelligent security decisions.
  22. 2 Strengths
    Policy Languages and Formal Methods · 2:56
    Explore the real-world power of Open Policy Agent (OPA) as it operates at massive scale across industry giants like Netflix, Goldman Sachs, and Pinterest, handling millions of policy decisions across APIs, microservices, and beyond.
  23. 3 Weaknesses
    Policy Languages and Formal Methods · 3:04
    Diving into the three core limitations of Rego as a policy language, exploring how its code-heavy syntax creates barriers for non-technical stakeholders, the training demands it places on teams, and the gaps that emerge between written rules and real-world policy intent.
  24. 4 Where It Is Useful Already
    Policy Languages and Formal Methods · 2:53
    Exploring real-world applications of Rego and formal policy languages, this chapter highlights where these tools have already proven their value, with Kubernetes as a prime example of how policy-driven systems bring structure and verification to complex cloud deployments.
  25. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:57
    Exploring the boundaries of policy-as-code, this chapter reveals the scenarios where formal policy languages like Rego fall short, helping listeners recognize when human judgment, culture, and interpersonal nuance must take precedence over automated enforcement.
  26. 1 What It Is
    Policy Languages and Formal Methods · 3:24
    Dive into Cedar, Amazon's authorization language released in 2023 that makes policy-as-code readable and intuitive, exploring how its English-like syntax and attribute-based access control set it apart from other policy frameworks.
  27. 2 Strengths
    Policy Languages and Formal Methods · 2:55
    Diving into the powerful capabilities of Cedar, AWS's policy language, and its integration with the Lean proof assistant to bring mathematical verification and formal correctness to access control decisions.
  28. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:36
    Exploring the boundaries of Cedar's capabilities, this chapter clarifies where the language falls short — from emergency workflows to vendor management — helping listeners understand that Cedar is purpose-built for authorization decisions, not broader organizational processes.
  29. 4 Where It Is Useful Already
    Policy Languages and Formal Methods · 3:04
    Diving into real-world applications of Cedar, this chapter explores how Amazon's Verified Permissions service leverages the policy language to power fine-grained, application-level authorization for SaaS platforms in the cloud.
  30. 1 What It Is
    Policy Languages and Formal Methods · 2:50
    Dive into the fundamentals of OSCAL (Open Security Controls Assessment Language), the NIST-developed framework that brings clarity and structure to complex compliance processes through machine-readable formats.
  31. 2 Strengths
    Policy Languages and Formal Methods · 2:34
    Exploring how OSCAL tackles the challenge of navigating multiple competing compliance frameworks, this chapter reveals the two core strengths that allow it to unify standards like NIST, ISO, and SOC 2 into a single, framework-agnostic system.
  32. 3 Weaknesses
    Policy Languages and Formal Methods · 2:49
    Diving into the limitations of Cedar, this song unpacks why its laser focus on authorization leaves critical security gaps, from change management to training, and what that means for building a complete policy strategy.
  33. 3 Weaknesses
    Policy Languages and Formal Methods · 3:22
    Diving into the core limitations of OSCAL, this track breaks down why a data format alone falls short of a true policy language, lacking logic evaluation, executability, and the ability to define what controls actually do.
  34. 4 Where It Is Useful Already
    Policy Languages and Formal Methods · 2:34
    Exploring how OSCAL brings structure and standardization to FedRAMP compliance packages, this chapter demonstrates how NIST 800-53 controls are transformed into formatted, machine-readable data that streamlines the authorization process.
  35. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:30
    Exploring the boundaries of OSCAL's design, this chapter clarifies where the framework falls short, helping listeners avoid common misapplications by understanding that OSCAL is built for documentation and exchange—not for authoring policies, enforcing rules, or reasoning through compliance logic.
  36. 3 Weaknesses
    Policy Languages and Formal Methods · 3:49
    Diving into the critical limitations of LegalRuleML, this track breaks down how its XML-based structure creates unnecessary complexity, making rules difficult to read and maintain for both technical and non-technical users alike.
  37. 1 What It Is
    Policy Languages and Formal Methods · 4:52
    Exploring the intersection of law and technology, this opening chapter introduces LegalRuleML, an OASIS standard designed to make legal text machine-readable while preserving its legal integrity.
  38. 4 Where It Is Useful Already
    Policy Languages and Formal Methods · 2:57
    Explore how formal policy languages like LegalRuleML are already making an impact in the real world, from Italy's tax code and Australian legislation to complex EU regulations, revealing the practical applications that researchers and governments are using today.
  39. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:59
    Exploring the practical limitations of LegalRuleML, this chapter highlights the scenarios where its complexity becomes a hindrance rather than a help, particularly for teams prioritizing human-readable documentation over formal XML structures.
  40. 1 What It Is
    Policy Languages and Formal Methods · 3:00
    A journey into the origins of XACML, tracing how OASIS set out in 2003 to build a standardized access control language that goes beyond simple rules by factoring in attributes and context when making decisions.
  41. 2 Strengths
    Policy Languages and Formal Methods · 3:22
    A deep dive into XACML's two decades of evolution, exploring how its maturity makes it the go-to standard for handling complex access control scenarios, from policy combining algorithms to multi-valued attributes.
  42. 3 Weaknesses
    Policy Languages and Formal Methods · 3:06
    Exploring the practical limitations of policy languages like XACML, listeners will discover how verbosity, complexity, and readability challenges can turn straightforward rules into unwieldy, difficult-to-maintain systems.
  43. 4 Where It Is Useful Already
    Policy Languages and Formal Methods · 3:19
    Exploring real-world applications of policy languages in healthcare settings, this chapter breaks down how standards like HL7 and XACML protect sensitive patient data by managing who can access what within complex medical systems.
  44. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:14
    Exploring the boundaries of XACML and Cedar, this chapter reveals the specific scenarios where access control policy languages fall short and why reaching for these tools in the wrong context can slow you down.
  45. 1 What It Is
    Policy Languages and Formal Methods · 2:44
    Dive into the world of compliance-as-code as OpenControl, born from 18F and GSA, replaces outdated spreadsheets with clean, YAML-based frameworks that modernize how organizations document and manage regulatory compliance.
  46. 2 Strengths
    Policy Languages and Formal Methods · 2:59
    Exploring the powerful advantages of policy-as-code, this chapter reveals how plain text editors and Git repositories are all developers need to seamlessly integrate compliance into existing workflows, eliminating the burden of specialized tooling.
  47. 4 Where It Is Useful
    Policy Languages and Formal Methods · 2:52
    Exploring the practical applications of OpenControl, this track breaks down how DevOps teams can leverage the framework to meet demanding compliance standards like FedRAMP and NIST, replacing scattered documentation with streamlined, integrated workflows.
  48. 5 Where It Would Not Be Useful
    Policy Languages and Formal Methods · 2:46
    Exploring the limitations of OpenControl, this chapter reveals the specific scenarios where its simple YAML-based structure falls short, particularly when policies require complex logic, nested conditions, and interdependent rules.
  49. 2 Strengths
    Policy Languages and Formal Methods · 2:27
    Diving into the expressive power of OWL ontologies, 2 Strengths explores how formal semantic structures can provide a rigorous foundation for defining compliance rules, data classification, and encryption requirements through precise properties, constraints, and relationships.
  50. 3 Weaknesses
    Policy Languages and Formal Methods · 2:57
    Diving into the three critical weaknesses of formal policy languages like OWL and SWRL, this chapter examines the real-world gaps between theoretical rigor and practical adoption, revealing why even powerful compliance tools can fall short when faced with business usability challenges.