Chapter 3 Flashcards
What is a subject
Generally an individual, process, or device causing information to flow among objects or change to the system state.
What is are characteristics of a subject
It is active, it initiates a request for access to resources or services.
Requests a service from an object
Should have a level of permissions that relates to its ability to access services or resources.
Define an object
Anything that a subject attempts to access is a referred to as an object
What are some characteristics of objects
Passive - a device, process, person, user, program, server, client or other entity that responds to a request for service.
By definition, objects do not contain their own access control logic
May have a classification.
What is an access rule
An instruction developed to allow or deny access to an object by comparing the validated identity of the subject, to an ACL
What are some characteristics of rules
Compare mulitple attributes to determine appropriate access
allow or deny access to an object
Define how much access is allowed
Apply time-based access
What do controls do
Limit risk to a tolerable level.
Logical and physical controls when combined, limit risk
define CPTED
Crime Prevention through environmental design
approaches the challenge of creating safer workspaces through passive design elements