ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium

A security architect is designing a new system that will handle sensitive government intelligence. The primary requirement is to prevent information from flowing from a higher security level to a lower security level, even if the user has clearance for both. Which security model is best suited to enforce this specific confidentiality requirement?

  1. ABell-LaPadula Security Model
  2. BClark-Wilson Security Model
  3. CBrewer-Nash (Chinese Wall) Model
  4. DBiba Security Model
Show answer & explanation

Correct answer: A. Bell-LaPadula Security Model

The Bell-LaPadula Security Model is specifically designed to enforce confidentiality by preventing information flow from higher security levels to lower security levels, adhering to the 'no write-down' rule. This aligns perfectly with the requirement to protect sensitive government intelligence.

Why the other options are wrong

  • B. The Clark-Wilson model focuses on integrity, specifically preventing unauthorized modification of data through well-formed transactions.
  • C. The Brewer-Nash model prevents conflicts of interest, ensuring that a user cannot access information from competing companies.
  • D. The Biba model focuses on integrity, preventing information flow from lower integrity levels to higher integrity levels.

Bell-LaPadula Security Model

A state-machine model focused on enforcing confidentiality by preventing unauthorized access to classified information.

  • Primarily concerned with confidentiality.
  • Uses 'no read-up' and 'no write-down' rules.
  • Commonly applied in military and government systems.

Memory trick: Confidential Bell rings for secret government documents.

More Security Architecture and Engineering questions