Evaluating system integrity
Simon N. Foley · 1998
Conventional models of system integrity tend to be implementation-oriented in that they define integrity in terms of specific controls such as separation of duties, wellformed transactions, and so forth. In this paper we propose a formal definition of integrity that is based on the notion of dependability and is implementation independent. Using a series of examples, we argue that separation of duties, assured pipelines, fault-tolerance, and cryptography may be viewed as implementation techniques for achieving integrity. 1 Introduction Conventional integrity models such as [2, 4, 22] limit themselves to the boundary of the computer system and tend to define integrity in an operational and/or implementationoriented sense. For example, the Clark-Wilson model [4] recommends that well-formed transactions, separation of duties and auditing be used to ensure integrity. However, the model does not attempt to address what is meant by integrity---evaluating a system according to the ClarkWil...