A security engineer is designing a system that must ensure data integrity at all costs, even if it means sacrificing availability. Which access control model and corresponding principle should be applied?
Trap 1: Bell-LaPadula with no read-down
Again, confidentiality focus.
Trap 2: Biba with no read-up
Biba's no read-up (read from higher integrity) is for integrity, but the primary rules are no write-up and no read-down.
Trap 3: Bell-LaPadula with no write-up
Bell-LaPadula focuses on confidentiality, not integrity.
- A
Bell-LaPadula with no read-down
Why it fails: Again, confidentiality focus.
- B
Biba with no read-up
Why it fails: Biba's no read-up (read from higher integrity) is for integrity, but the primary rules are no write-up and no read-down.
- C
Biba with no write-up and no read-down
Biba enforces no write-up (to protect higher integrity) and no read-down (to prevent corruption). This prioritizes integrity over availability.
- D
Bell-LaPadula with no write-up
Why it fails: Bell-LaPadula focuses on confidentiality, not integrity.