29.1. Introduction29.2. Requirements and Policy29.2.1. Requirements29.2.2. Threats29.2.2.1. Group 1: Unauthorized Users Accessing Role Accounts29.2.2.2. Group 2: Authorized Users Accessing Role Accounts29.2.2.3. Summary29.3. Design29.3.1. Framework29.3.1.1. User Interface29.3.1.2. High-Level Design29.3.2. Access to Roles and Commands29.3.2.1. Interface29.3.2.2. Internals29.3.2.3. Storage of the Access Control Data29.4. Refinement and Implementation29.4.1. First-Level Refinement29.4.2. Second-Level Refinement29.4.3. Functions29.4.3.1. Obtaining Location29.4.3.2. The Access Control Record29.4.3.3. Error Handling in the Reading and Matching Routines29.4.4. Summary29.5. Common Security-Related Programming Problems29.5.1. Improper Choice of Initial Protection Domain29.5.1.1. Process Privileges29.5.1.2. Access Control File Permissions29.5.1.3. Memory Protection29.5.1.4. Trust in the System29.5.2. Improper Isolation of Implementation Detail29.5.2.1. Resource Exhaustion and User Identifiers29.5.2.2. Validating the Access Control Entries29.5.2.3. Restricting the Protection Domain of the Role Process29.5.3. Improper Change29.5.3.1. Memory29.5.3.2. Changes in File Contents29.5.3.3. Race Conditions in File Accesses29.5.4. Improper Naming29.5.5. Improper Deallocation or Deletion29.5.6. Improper Validation29.5.6.1. Bounds Checking29.5.6.2. Type Checking29.5.6.3. Error Checking29.5.6.4. Checking for Valid, not Invalid, Data29.5.6.5. Checking Input29.5.6.6. Designing for Validation29.5.7. Improper Indivisibility29.5.8. Improper Sequencing29.5.9. Improper Choice of Operand or Operation29.5.10. Summary29.6. Testing, Maintenance, and Operation29.6.1. Testing29.6.1.1. Testing the Module29.6.2. Testing Composed Modules29.6.3. Testing the Program29.7. Distribution29.8. Conclusion29.9. Summary29.10. Research Issues29.11. Further Reading29.12. Exercises