Page 275

The University of SydneyPage 22Bell-La PadulaModel–The *-Property: Subject S with clearance (LS , CS) can have writeaccess to object O with classification (LO,CO) only if (LS,CS) ≤ (LO,CO). –No Write Down

–Does this rule make sense? Why?–This makes sure that subjects cannot accidentally or intentionally share confidential information by writing to an object at a lower security level.

SubjectObject

WriteWriteWrite

Security Levels