Testbusters.net
  Testbusters.net
  Guaranteed Pass!
Free  support
    Test Questions
Home  
Guarantee  
About Us  
FAQ  
Purchase
 Products     Microsoft®    CompTIA®    Cisco®    Subnetting Made Easy
Access Control Techniques
  Mandatory
  Discretionary
Access Control Models
  Lapadula
  Clark-Wilson
  Biba
Intrusions
  DoS Attack
  IDS
WAN Security
  Firewall
  VPN
  Authorization
  Viruses
  Public Keys
  Private Keys
 SY0-101
  Test 1
 N10-003
  Test 44
  Test 12
 Aplus
  Test 11
  Test 1
 W2K
  Test 1
 More Test
Questions
Clark-Wilson Access Control
The Clark-Wilson model addresses integrity, but not confidentiality or availability.
It addresses integrity protection different than the Clark-Wilson model by using a three part relationship versus the lattice method as does the Biba model.
The three part relationship is composed of; Objects may only be accessed through programs eliminating direct access from the subject.
To further protect integrity the Clark-Wilson model utilizes the following two principles; In our three part relationship, programs take the part of well informed transactions, and a subject is required to use a program to access an object.
The programs in use would have limitations as to what they could do or not do to an object. This limits the subject's, object changing capabilities.

The principle of 'separation of duties', states that no single individual may perform a critical function. Critical functions must be separated into two or more parts, and two different subjects are required to modify an object.
This prevents unauthorized modifications to objects.

The Clark-Wilson model requires auditing of object access, and changes, both internally and externally to guarantee integrity.

This categorizes the Clark-Wilson model as a 'restricted interface model'. (Classification-based restrictions only offer subject-specific authorized information and functions)
Simply put, this means that a subject at one level may see, and access data at one level, but a subject at another level will see a different set of data and have access, only to that data.


Copyright ©2002-2006 Testbusters.net. All Rights Reserved.
Testbusters.net is not sponsored, endorsed or affiliated by any associated vendor.
Associated venders include, but are not limited to, Microsoft®, Cisco®, CompTIA®, Novell® etc.