Models of security in a business setting

Andrew Hawker · 2005

Military models of information system security, on the other hand, assume that secrecy is paramount, and that there is a hierarchy of users, with the extent of a user’s security clearance reflecting his or her seniority. A formal model along these lines was proposed by Bell and La Padula (1973) (see Figure I.1), and in 1983 this was enshrined in the US Department of Defense’s ‘Trusted Computer System Evaluation Criteria’. (This became better known as the ‘Orange Book’, and has been regularly revised as a guide for security levels ever since).

Read the paper · More papers on PaperTik