On Technology Security Standards: BPM, SAML, XACML
Takeaway: BPM security has two main issues: who are you and what do you have access to? In general, the OASIS SAML deals with the first issue, OASIS XACML deals with the latter. With the latter, XACML first defines the mechanics of authorization policies and, second, how to access those polices. The key is you want the service being accessed to be it's own enforcer. Finally, this aspect of enterprise architecture is not only critical to BPMSs, but also to social computing platforms like wiki's.
FYI: ebizQ has an upcoming Webinar on the Best Practices for Business Service Management which you can sign up for right here!