Lecture 2 Outline (April 1, 2015)
Lecture 2 Outline (April 1, 2015)
Reading
:
text
, § 13, 18; [Bel07, Mei06, VE06]
Assurance
Trustworthy entities
Security assurance
Trusted system
Why assurance is needed
Requirements
Assurance and the software life cycle
Principles of secure design
Principle of least privilege
Principle of fail-safe defaults
Principle of economy of mechanism
Principle of complete mediation
Principle of open design
Principle of separation of privilege
Principle of least common mechanism
Principle of least astonishment
You can also obtain a PDF version of this.
Version of April 3, 2015 at 12:01AM