OpenPMF’s policies are captured in generic terms, rather than in technical security rules. This way, OpenPMF policies typically do not have to change when the application landscape changes.
OpenPMF automatically generates the technical security enforcement rules from those models by automatically analyzing the applications with all their interactions, and inferring which rules are required to enforce the requirements defined in the models. This approach is called “model-driven security”. It applies some of the concepts from model-driven software development to security.
OpenPMF allows you to improve protection, monitoring, testing, and documenting – for your information, users and devices. It turns human-manageable security policies automatically into the matching preventive technical implementation. OpenPMF lets you manage security policies in customizable terms that matter to your organization. OpenPMF ensures policies are manageable even if IT landscapes are large and change dynamically. The result is a significant cost saving, especially with respect to maintenance.
Import, Author and Generate
1. Import
Import information about your organization, including systems/applications, networks, data flows, users and alerts. And Import your existing technical policies as a baseline, for example access control configurations.
2. Author
Author security policies that are intuitive, generic, rich and easy customizable. Policies are technology-neutral, allowing for easy application to many technologies
3. Generate
Generate technical enforcement rules & configurations for example for access control automatically. OpenPMF’s own enforcement infrastructure supports many technologies out-of-the-box, and other technologies on demand. OpenPMF comes with its own enforcement infrastructure, which includes local software agents.

OpenPMF ensures policies are manageable.
OpenPMF allows you to improve protection, monitoring, testing, and documenting – for your information, users and devices. OpenPMFTM turns human-manageable security policies automatically into the matching preventive technical implementation.
OpenPMF lets you manage security policies in customizable terms that matter to your organization. OpenPMF ensures policies are manageable even if IT landscapes are large and change dynamically. The result is a significant cost saving, especially with respect to maintenance.
Want to learn about the benefits of Security Policy Automation? Request a free license for OpenPMF today.
OpenPMF in Detail and Screenshots.
Enforce via OpenPMF’s own runtime. Many technologies out-of-the-box
- Fine-grained Access Control Products (XACML)
- Development Tools (Eclipse IDE & EMF)
- Middleware: OSGi, BPMS BPMN SOA, web app servers, DDS, CORBA/CCM, IIOP ObjectWall
- Network Intrusion Detection Systems
- Identity Management, Directory Services, PMI & PKI, X.509, LDAP
- Databases: PostgreSQL (under dev.)
- Other technologies on demand
Monitor
1) Monitor via OpenPMF’s own runtime. Many technologies out-of-the-box:
- Fine-grained Access Control (XACML)
- Development Tools (Eclipse)
- Middleware: OSGi, BPMS BPMN SOA, web app servers, DDS, CORBA/CCM, IIOP ObjectWall
- Network Intrusion Detection Systems
- Identity Management, Directories, PMI & PKI, X.509, LDAP
- other technologies on demand
2) Import 3rd party alerts: using OpenPMF’s customizable importer
Automatically update & rapidly customize:
- policies when your IT landscape changes
- policies & enforcement for your organization
To update, just import any changes to your IT landscape, and simply regenerate the technical policy at the click of a button.
Customize most features of OpenPMF, including policy features, importers, exporters, enforcement.
OpenPMF is based on standards (Eclipse EMF/MOF, OMG QVT etc.)
We generally favor ‘model driven security’ to actually execute and implement digital dynamic access control.
OpenPMF Security Policy Automation:
Turns human-manageable security policies automatically into the matching technical implementation.
Generates accreditation/compliance evidence automatically.
Reduces cost, improve security, speed up accreditation/compliance.
Supports security for today’s agile, interconnected applications, including Service-Oriented Architecture (SOA), Internet of Things (IoT), privacy by design (PbD), and cloud platforms (PaaS).
Uses model-driven security (MDS) – a unique, patent-pending technology – to simplify policy management more than other approaches (e.g. visual/linguistic).
Includes a model-driven policy authoring tool, a model-driven rule generation tool, an attribute-based authorization policy server, and policy decision/enforcement points.
Is standards-based incl. Ecore/MOF, XMI, XACML, attribute-based access control, etc.
Is very well suited to implement guidance/regulations (NIST 800-53, …)
Can be deployed locally or in the cloud (SaaS).
OpenPMF automates policy management, giving you the assurance that your security mechanisms are actually enforcing the policies you specify.