On the buzzword 'security policy'
- 10 December 2002
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
- p. 219-230
- https://doi.org/10.1109/risp.1991.130789
Abstract
It is pointed out that, although the term 'security policy' is fundamental to computer security, its conflicting meanings have obscured important conceptual distinctions, especially where concerns other than confidentiality are involved. A clearer definition is needed to clarify routine technical discourse, facilitate resolution of key research issues, and establish the scope of security research and standardization efforts. The terms security policy objective, organization security policy, and automated security policy are proposed. These terms are based on simple generalizations of ideas that underlie the trusted computer system evaluation criteria (TCSEC). Yet, they describe a view of security that is more precise, more general, and different than 'confidentiality, integrity, and assured service'. Their usefulness in clarifying conceptual and terminological issues is illustrated through examples.Keywords
This publication has 8 references indexed in Scilit:
- A model for specifying multi-granularity integrity policiesPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Concerning 'modeling' of computer securityPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Using mandatory integrity to enforce 'commercial' securityPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- A policy model for denial of servicePublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- A specification and verification method for preventing denial of serviceIEEE Transactions on Software Engineering, 1990
- Some conundrums concerning separation of dutyPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1990
- A Comparison of Commercial and Military Computer Security PoliciesPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1987
- On hierarchical design of computer systems for critical applicationsIEEE Transactions on Software Engineering, 1986