Lecture 11: April 21, 2021
Reading: text, §4.4–4.6, G
Due: Homework 2, due April 21, 2021; Lab 2, due May 5, 2021
-  Types of Access Control
	
	-  Mandatory access control
	
 -  Discretionary access control
	
 -  Originator-controlled access control
	
 
 -  High-level policy languages
	
	-  Characterization
	
 -  Example: Ponder
	
 
 -  Low-level policy languages
	
	-  Characterization
	
 -  Example: tripwire configuration file
	
 
 -  Example policies
	
	-  UC Davis Allowable Use Policy
		
		-  Rights and responsibilities
		
 -  Privacy
		
 -  Enforcement
		
 -  Unacceptable conduct
		
 
	 -  University Electronic Communications policy
		
		-  General provisions
		
 -  Allowable use
		
 -  Privacy and confidentiality
		
 -  Security
		
 -  Retention and disposition
		
 
	 -  User advisories
	
 -  UC Davis implementation