another plea for consistent terminology: MAC != MLS ?

Linda Walsh law at sgi.com
Fri Apr 21 23:12:26 GMT 2000


jont at us.ibm.com wrote:
> MAC = Mandatory Access Control
> MLS = Multi-Level Security ( ~= lattice security ~= bell-la padula )
---
	BTW, a part that can add confusion -- the LSPP Uses the words
"Mandatory Access Control" and that it is to be provided by a BLP style Sensitivity
model AND a Biba style Integrity model (though they don't use the terms BLP and
Biba, they describe it).  They require a minimum of 16 levels of sensitivity
and 16 levels of integrity as well as the ability to define 64 User Definable
Divisions  associated with Sensitivity and 64 User Definable Categories 
associated with Integrity.

-l

--
Linda A Walsh                    | Trust Technology, Core Linux, SGI
law at sgi.com                      | Voice: (650) 933-5338
To Unsubscribe: send mail to majordomo at trustedbsd.org
with "unsubscribe trustedbsd-discuss" in the body of the message



More information about the trustedbsd-discuss mailing list