Outline for February 12, 2007
-
Greetings and Felicitations!
-
CISS
-
Intended for medical records; goals are confidentiality, authentication of annotators, and integrity
-
Patients, personal health information, clinician
-
Assumptions and origin of principles
-
Access principles
-
Creation principle
-
Deletion principle
-
Confinement principle
-
Aggregation principle
-
Enforcement principle
-
Comparison to Bell-LaPadula: lattice structure but different focus
-
Comparison to Clark-Wilson: specialization
-
ORCON
-
Originator controls distribution
-
DAC, MAC inadequate
-
Solution is combination
Here is a PDF version of this document.