April 2011
Intermediate to advanced
504 pages
14h 51m
English
Authorization refers to rights and privileges granted to an individual or process that enable access to computer resources and information assets. Once a user's identity and authentication are established, authorization levels determine the extent of system rights that a user can hold. Authorization is related to complete mediation, in which every request by a subject to access an object in a computer system must undergo a valid and effective authorization procedure. This mediation must not be suspended or become capable of being bypassed, even when the information system is being initialized, undergoing shutdown, or being restarted, or is in maintenance mode. Complete mediation entails the following:
Read now
Unlock full access