tailieunhanh - CIS 551 / TCOM 401 Computer and Network Security

Entities that currently regulate an element of critical infrastructure that has been defined as higher risk should be responsible for oversight. Enforcement of these standards should be incorporated into already established safety or security reviews. Any element of critical infrastructure that has processes or technology that exceed the established standard should be deemed compliant with the standard. The Department of Homeland Security should work with other regulators to help coordinate security standards across sectors and within sectors subject to multiple regulators. . | CIS 551 TCOM 401 Computer and Network Security Spring 2006 Lecture 6 Announcements Reminder - Project 1 is due TODAY - Mail your .tar file to Karl by midnight tonight. Some of today s slides are adapted from slides by John Mitchell 2 6 06 CIS TCOM 551 2 Recap from last time We ve been studying Acess Control Mechanisms - Access control lists - Capabilities - Unix Windows OS access control - Stack inspection Today - Discretionary access control DAC - Mandatory access control MAC - Information-flow security 2 6 06 CIS TCOM 551