Abstract:
The multilevel security policy mainly represents the security requirements of military computer systems. It deals almost entirely with controlling the unauthorized dissemination of information, i.e., confidentiality. The “Chinese Wall” policy describes the security requirements of financial service systems, it is not applicable to other kinds of systems. Whereas in commercial world, the concern focuses on controlling the unauthorized modification of information, i.e., integrity. As a result of analyzing various security requirements of different kinds of systems, a new security policy based on role is proposed,which concerns confidentiality and integrity of information in information processing, so it could be applicable to different kinds of systems.