Handbook of Information Security: Threats, Vulnerabilities, Prevention, Detection, and Management, Volume 3
by Hossein Bidgoli
Security Policy Enforcement
Cynthia E. Irvine, Naval Postgraduate School
Security as a Negative Requirement
Security as a Constructive Effort
Key Definitions for Describing Technical Policies
Mechanisms for Discretionary Policy Enforcement
Mechanisms for Enforcement of Nondiscretionary (Mandatory) Policies
Criticality of Correct Policy Enforcement
Considerations for the Construction of Secure Systems
Essential Elements for System Protection
INTRODUCTION
Many chapters of this Handbook describe mechanisms that contribute to various facets of security. The arbitrary use of security mechanisms provides no prescription for the achievement of security goals. It is only in their application in the context of organizational objectives for the protection of information and computational assets that security can be assessed. This chapter is intended to discuss the policies that provide a rationale for those mechanisms and to broadly examine their enforcement mechanisms in computer systems. It is intended to focus primarily on fundamental concepts, which remain valid despite their longevity. ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access