Reading: text, §4.5, 4.7, 5–5.2.1
Due: Homework #1, due January 22; Project selection, due January 22

Module 14
  1. Policy languages
Module 15
  1. Secure, precise
    1. Observability postulate
    2. Theorem: for any program p and policy c, there is a secure, precise mechanism m* such that, for all security mechanisms m associated with p and c, m*m
    3. Theorem: There is no effective procedure that determines a maximally precise, secure mechanism for any policy and program

Matt Bishop
ECS 235B, Foundations of Computer and Information Security
