ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringEasy

A security architect is designing a system for handling highly sensitive government intelligence. The primary concern is preventing unauthorized disclosure of information, even if a subject has legitimate access at a lower classification level. Which security model is most appropriate for this requirement?

  1. ABiba Security Model
  2. BBrewer and Nash Model
  3. CClark-Wilson Security Model
  4. DBell-LaPadula Security Model
Show answer & explanation

Correct answer: D. Bell-LaPadula Security Model

The Bell-LaPadula Security Model is specifically designed to enforce confidentiality, preventing subjects from reading information at a higher classification level (no read-up) and writing information at a lower classification level (no write-down). This directly addresses the requirement of preventing unauthorized disclosure.

Why the other options are wrong

  • A. The Biba Model focuses on integrity, preventing data corruption.
  • B. The Brewer and Nash (Chinese Wall) Model prevents conflicts of interest, not general confidentiality enforcement.
  • C. The Clark-Wilson Model focuses on data integrity through well-formed transactions and separation of duties.

Bell-LaPadula Model

A state machine model focused on enforcing confidentiality by preventing unauthorized access to classified information.

  • Developed for military systems.
  • Emphasizes 'no read-up' and 'no write-down' rules.
  • Primarily concerned with preventing information disclosure.

Memory trick: Bell-LaPadula Locks Down Confidentiality.

More Security Architecture and Engineering questions