National Academy of Sciences | 150 Year Anniversary

Questions? Call 800-624-6242

| Items in cart [0]

The National Academies Press

PAPERBACK
price:$82.75
add to cart

Rights & Permissions

topleft topright

Computers at Risk: Safe Computing in the Information Age (1991)
Computer Science and Telecommunications Board (CSTB)

Citation Manager

. "F Glossary." Computers at Risk: Safe Computing in the Information Age. Washington, DC: The National Academies Press, 1991.

Please select a format:

BibTeX EndNote RefMan


Page
287
bottomleft bottomright

The following HTML text is provided to enhance online readability. Many aspects of typography translate only awkwardly to HTML. Please use the page image as the authoritative form to ensure accuracy.


Computers at Risk: Safe Computing in the Information Age

Administratively directed access control (ADAC)

Access control in which administrators control who can access which objects. Contrast with user-directed access control (UDAC). See Mandatory access control.

Assurance

Confidence that a system design meets its requirements, or that its implementation meets its specification, or that some specific property is satisfied.

Auditing

The process of making and keeping the records necessary to support accountability. See Audit trail analysis.

Audit trail

The results of monitoring each operation of subjects on objects; for example, an audit trail might be a record of all actions taken on a particularly sensitive file.

Audit trail analysis

Examination of an audit trail, either manually or automatically, possibly in real time (Lunt, 1988).

Authentication

Providing assurance regarding the identity of a subject or object, for example, ensuring that a particular user is who he claims to be.

Authentication sequence

A sequence used to authenticate the identity of a subject or object.

Authorization

Determining whether a subject (a user or system) is trusted to act for a given purpose, for example, allowed to read a particular file.

Availability

The property that a given resource will be usable during a given time period.


Bell and La Padula model

An information-flow security model couched in terms of subjects and objects and based on the concept that information shall not flow to an object of lesser or noncomparable classification (Bell and La Padula, 1976).

Page
287