Information Flow Models

Each object and subject are assigned security class and value; info is constrained to flow in directions that are permitted by the security policy.

Based on state machine and consists of objects, state transitions, and lattice (flow policy) states.

Object can be a user

Each object is assigned a security class and value

Information is constrained to flow in the directions permitted by the policy

Non-interference Model

Actions of group A using commands C are not seen by users in Group B using commands D

CISSP Study Concepts for Cryptographic Lifecycle

Algorithm Protocol Governance

Needed Component Parts to an Encryption Strategy

Symmetric for confidentiality (DES, 3

Main Menu