A framework for expressing models of security policy
Dobson, J.E.; McDermid, J.A.
Security and Privacy, 1989. Proceedings., 1989 IEEE Symposium on
Volume , Issue , 1-3 May 1989 Page(s):229 - 239
Digital Object Identifier 10.1109/SECPRI.1989.36297
Summary:The authors first describe some issues that arise from the
interplay between the security requirements for an integrated project
support environment (IPSE) for the development of a trusted system, and
the security requirements of the trusted system itself. All of these
issues derive from security policy and the modeling of security policy.
A framework is then presented which allows security policies to be
expressed in the context of the enterprise whose needs the trusted
system is intended to serve. Finally some possible applications of the
framework are used to indicate how security policies affect design
decision-making, security policy conflict detection, and security risk
evaluation
View citation and abstract |