Mandatory Access Control - Degrees of MAC System Strength

Degrees of MAC System Strength

In some systems users have the authority to decide whether to grant access to any other user. To allow that, all users have clearances for all data. This is not necessarily true of a MAC system. If individuals or processes exist that may be denied access to any of the data in the system environment, then the system must be trusted to enforce MAC. Since there can be various levels of data classification and user clearances, this implies a quantified scale for robustness. For example, more robustness is indicated for system environments containing classified Top Secret information and uncleared users than for one with Secret information and users cleared to at least Confidential. To promote consistency and eliminate subjectivity in degrees of robustness, an extensive scientific analysis and risk assessment of the topic produced a landmark benchmark standardization quantifying security robustness capabilities of systems and mapping them to the degrees of trust warranted for various security environments. The result was documented in CSC-STD-004-85. Two relatively independent components of robustness were defined: Assurance Level and Functionality. Both were specified with a degree of precision that warranted significant confidence in certifications based on these criteria.

Read more about this topic:  Mandatory Access Control

Famous quotes containing the words degrees of, degrees, system and/or strength:

    Always the laws of light are the same, but the modes and degrees of seeing vary.
    Henry David Thoreau (1817–1862)

    I was by degrees awakened as from a dream, and feared that my whole life could properly be counted nothing else but a fantastic vision.
    Sarah Fielding (1710–1768)

    Human beings are compelled to live within a lie, but they can be compelled to do so only because they are in fact capable of living in this way. Therefore not only does the system alienate humanity, but at the same time alienated humanity supports this system as its own involuntary masterplan, as a degenerate image of its own degeneration, as a record of people’s own failure as individuals.
    Václav Havel (b. 1936)

    We have not strength enough to follow our reason so far as it would carry us.
    François, Duc De La Rochefoucauld (1613–1680)