nerdexam
(ISC)2

SSCP · Question #21

The Orange Book is founded upon which security policy model?

The correct answer is B. The Bell LaPadula Model. From the glossary of Computer Security Basics: The Bell-LaPadula model is the security policy model on which the Orange Book requirements are based. From the Orange Book definition, "A formal state transition model of computer security policy that describes a set of access…

Submitted by yuki_2020· Apr 18, 2026Security Concepts and Practices

Question

The Orange Book is founded upon which security policy model?

Options

  • AThe Biba Model
  • BThe Bell LaPadula Model
  • CClark-Wilson Model
  • DTEMPEST

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    86% (44)
  • C
    8% (4)
  • D
    2% (1)

Explanation

From the glossary of Computer Security Basics: The Bell-LaPadula model is the security policy model on which the Orange Book requirements are based. From the Orange Book definition, "A formal state transition model of computer security policy that describes a set of access control rules. In this formal model, the entities in a computer system are divided into abstract sets of subjects and objects. The notion of secure state is defined and it is proven that each state transition preserves security by moving from secure state to secure state; thus, inductively proving the system is secure. A system state is defined to be 'secure' if the only permitted access modes of subjects to objects are in accordance with a specific security policy. In order to determine whether or not a specific access mode is allowed, the clearance of a subject is compared to the classification of the object and a determination is made as to whether the subject is authorized for the specific access mode." The Biba Model is an integrity model of computer security policy that describes a set of rules. In this model, a subject may not depend on any object or other subject that is less trusted than itself. The Clark Wilson Model is an integrity model for computer security policy designed for a commercial environment. It addresses such concepts as nondiscretionary access control, privilege separation, and least privilege. TEMPEST is a government program that prevents the compromising electrical and electromagnetic signals that emanate from computers and related equipment from being intercepted and deciphered.

Topics

#Orange Book#Bell-LaPadula Model#Confidentiality#Security Models

Community Discussion

No community discussion yet for this question.

Full SSCP Practice