May 5, 2017 Outline
Reading: Chapters from revised text, §8
Due: Project Progress Report, May 12; Homework #3, May 19
- Chinese Wall Policy
- Key result: information can only flow within a CD or from sanitized information
- Aggressive Chinese Wall model
- Comparison to BLP
- Comparison to Clark-Wilson
- Clinical Information System Security model
- Intended for medical records; goals are confidentiality, authentication of annotators, and integrity
- Patients, personal health information, clinician
- Assumptions and origin of principles
- Access principles
- Creation principle
- Deletion principle
- Confinement principle
- Aggregation principle
- Enforcement principle
- Comparison to Bell-LaPadula: lattice structure but different focus
- Comparison to Clark-Wilson: specialization
- ORCON
- Originator controls distribution
- DAC, MAC inadequate
- Solution is combination
- Role-based Access Control (RBAC)
- Definition of role
- Partitioning as job function