self-garbling virus see polymorphic
sensitive information any information that the loss,
misuse, modification of, or unauthorized access to
could affect the specific interest of the enterprise.
U.S. government and military entities have specific
regulations in this regard.
sensitivity label piece of information that represents the
security level of an object. Sensitivity labels are used by
the TCB as the basis for mandatory access control deci-
sions.
separation of duties practice of dividing the steps in a
system function among different individuals, to keep
a single individual from subverting the process. In
particular, a person doing audit or check functions
should not be the person performing the operation.
Originally part of the Clark-Wilson integ