Security models are formal descriptions of how a system should enforce a security policy. They are abstract, but the exam tests them in predictable ways: which property a model protects and what its rules forbid. Before diving in, remember the vocabulary. The subject is the active entity, such as a user or process. The object is the passive resource, such as a file or record. A lattice-based model arranges security levels in order, with each subject and object assigned a level, and this lattice underlies mandatory access control (MAC).
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.