ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringEasy
A security architect is designing a system for handling highly sensitive government intelligence. The primary concern is preventing unauthorized disclosure of information, even if a subject has legitimate access at a lower classification level. Which security model is most appropriate for this requirement?
- ABiba Security Model
- BBrewer and Nash Model
- CClark-Wilson Security Model
- DBell-LaPadula Security Model
Show answer & explanationAnswer & explanation
Correct answer: D. Bell-LaPadula Security Model
The Bell-LaPadula Security Model is specifically designed to enforce confidentiality, preventing subjects from reading information at a higher classification level (no read-up) and writing information at a lower classification level (no write-down). This directly addresses the requirement of preventing unauthorized disclosure.
Why the other options are wrong
- A. The Biba Model focuses on integrity, preventing data corruption.
- B. The Brewer and Nash (Chinese Wall) Model prevents conflicts of interest, not general confidentiality enforcement.
- C. The Clark-Wilson Model focuses on data integrity through well-formed transactions and separation of duties.
Bell-LaPadula Model
A state machine model focused on enforcing confidentiality by preventing unauthorized access to classified information.
- Developed for military systems.
- Emphasizes 'no read-up' and 'no write-down' rules.
- Primarily concerned with preventing information disclosure.
Memory trick: Bell-LaPadula Locks Down Confidentiality.