The specification and implementation of “commercial” security requirements including dynamic segregation of duties
Simon N. Foley · 1997
A framework for the specification of security policies is proposed.It can used to formally specify confidentiality and integrity policies, the latter can be given in terms of Clark-Wilson style access triples.The tiamework extends the Clark-Wilson model in that it can be used to specify dynamic segregation of duty.For application systems where security is critical, a multilevel security based approach is defined.Security policies for less critical applications can be implemented using standard Unix based systems.Both implementation strategies are based on the standard protection mechanisms that are provided by the respective systems.Permission to m&e digitnl/h.udcopies of all or part of this material for personal or classroom use is gmnted without fee provided thnt the copies xc not made or distributed for profit or commercinl advnntnge, the COPYright notice, thetitle ofthe publication and its date appear, and notice is given that copyright is by permission ofthe ACM, Inc.To copy otherwise, to