Outline for April 26, 2006
Reading: text, §7.2—7.4
- Greetings and felicitations!
- Office hours changed, due to talk at noon
- Bad typo in book relevant to homework;
in Definition 3—21, number 3, it should be τ(X), not
τ(Y)
- CISS
- Intended for medical records; goals are confidentiality,
authentication of annotators, and integrity
- Patients, personal health information, clinician
- Assumptions and origin of principles
- Access principles
- Creation principle
- Deletion principle
- Confinement principle
- Aggregation principle
- Enforcement principle
- Comparison to Bell-LaPadula: lattice structure but different focus
- Comparison to Clark-Wilson: specialization
- ORCON
- Originator controls distribution
- DAC, MAC inadequate
- Solution is combination
- Role-based Access Control (RBAC)
- Definition of role
- Partitioning as job function
- Containment
Version of April 28, 2006 at 6:48 AM
You can also obtain a PDF version of this.