May 5, 2017 Outline

Reading: Chapters from revised text, §8
Due: Project Progress Report, May 12; Homework #3, May 19

  1. Chinese Wall Policy
    1. Key result: information can only flow within a CD or from sanitized information
    2. Aggressive Chinese Wall model
    3. Comparison to BLP
    4. Comparison to Clark-Wilson
  2. Clinical Information System Security model
    1. Intended for medical records; goals are confidentiality, authentication of annotators, and integrity
    2. Patients, personal health information, clinician
    3. Assumptions and origin of principles
    4. Access principles
    5. Creation principle
    6. Deletion principle
    7. Confinement principle
    8. Aggregation principle
    9. Enforcement principle
    10. Comparison to Bell-LaPadula: lattice structure but different focus
    11. Comparison to Clark-Wilson: specialization
  3. ORCON
    1. Originator controls distribution
    2. DAC, MAC inadequate
    3. Solution is combination
  4. Role-based Access Control (RBAC)
    1. Definition of role
    2. Partitioning as job function

You can also obtain a PDF version of this. Version of May 5, 2017 at 4:47PM