Outline for September 29, 2023
Reading: text, §14, 4.1–4.2
Due: Homework 1, due October 9; Project teams, question, due Oct 11
- Principles of secure design
- Bases: simplicity, restrictiveness
- Principle of least privilege
- Principle of least authority
- Principle of fail-safe defaults
- Principle of economy of mechanism
- Principle of complete mediation
- Principle of open design
- Principle of separation of privilege
- Principle of least common mechanism
- Principle of least astonishment
- Principle of psychological acceptability
- Policy
- Sets of authorized, unauthorized states
- Secure systems in terms of states
- Defining confidentiality, integrity, availability
- Policy models and mechanisms