CISSP-ISSMP · Question #193
Which of the following divisions of the Trusted Computer System Evaluation Criteria (TCSEC) is based on the Mandatory Access Control (MAC) policy?
The correct answer is C. Division B. The TCSEC (Orange Book) organizes security into four hierarchical divisions. Division B - Mandatory Protection - is specifically based on the Mandatory Access Control (MAC) policy, where access decisions are made by the system based on security labels assigned to subjects…
Question
Which of the following divisions of the Trusted Computer System Evaluation Criteria (TCSEC) is based on the Mandatory Access Control (MAC) policy?
Options
- ADivision A
- BDivision D
- CDivision B
- DDivision C
How the community answered
(34 responses)- A6% (2)
- C91% (31)
- D3% (1)
Explanation
The TCSEC (Orange Book) organizes security into four hierarchical divisions. Division B - Mandatory Protection - is specifically based on the Mandatory Access Control (MAC) policy, where access decisions are made by the system based on security labels assigned to subjects (users/processes) and objects (files/resources), and users cannot override these controls. Division B includes three levels: B1 (Labeled Security), B2 (Structured Protection), and B3 (Security Domains). Division C uses Discretionary Access Control (DAC), Division D is minimal protection with no defined security policy, and Division A (Verified Protection) extends Division B with formal mathematical verification of the security model.
Topics
Community Discussion
No community discussion yet for this question.