Cyber8836 Trusted OS Policy Flashcards
What is the RVM
The reference validation Mechanism
What is meant by a trusted OS?
A trusted OS is an OS that is responsible for policy enforcement.
In respect to Trusted OS what is Policy?
A set of well defined, consistent, implementable rules that have been clearly expressed.
What is mandatory access control (MAC)?
Access control mandated based on characteristics of the object and the user in the form of labels.
What is Discretionary Access Control (DAC)?
Access control based on the owners discretion, normal ACLS.
How to you address the scale of access matrixes?
Role based Access Control addresses the scale of access matrixes, by creating roles.
What are the access control primitives?
RBAC - Roles assigned to people
ABAC - Attributes assigned to users, objects, environment, compared.
CBAC - People in a photo, Context based.
What is sensitivity?
The equivalent of classification.
Unclass
confedential
secret
TS
What are compartments?
Special subset of records.
What does a subjects label specify?
Their Clearance.
What does a company group belong to?
A company group belongs to a unique conflict class.
What is the Chinese Wall access control policy?
A subject S can have access to objects from one and only one company group within a conflict class.
What is the Clark Wilson Policy spec?
Users/roles (U)
Constrained Data Items (CDI)
Transformation procecedures (TP)
A user performs only authorized TP on CDI it has access to.
it is an application oriented policy model