Security models turn a policy (“keep secrets secret”, “keep data trustworthy”) into formal rules a system can enforce and evaluators can prove. The exam almost never asks for the math — it describes a property or rule and asks which model it belongs to. This page is built for exactly that move: the big four in detail, the supporting cast, and the directionality traps spelled out.

The big four

Confidentiality · mandatory access control

Bell-LaPadula (BLP)

Built for military classification systems: stop information flowing from high classifications to low ones. Subjects and objects carry labels; the model constrains reads and writes by label.

  • Simple Security Property — no read up (a Secret-cleared user cannot read Top Secret).
  • ★ (Star) Property — no write down (a Top Secret process cannot write into a Secret file, or secrets would leak downward).
  • Strong ★ Property — read/write only at your own level.
  • Discretionary access on top via an access matrix (the ds-property).

Exam tell: any mention of “no read up / no write down”, classifications, or protecting confidentiality with labels = Bell-LaPadula.

Integrity · mandatory access control

Biba

Bell-LaPadula flipped upside down, protecting integrity instead of secrecy: stop bad (low-integrity) data contaminating good (high-integrity) data.

  • Simple Integrity Property — no read down (don't consume data less trustworthy than you).
  • ★ Integrity Property — no write up (don't let less trustworthy processes modify more trustworthy data).
  • Invocation property — can't invoke services at a higher integrity level.

Exam tell: “no read down / no write up” or any question about protecting data trustworthiness = Biba. If the rules look like BLP inverted, it IS Biba.

Integrity · commercial

Clark-Wilson

Commercial integrity without labels: users never touch data directly. All changes go through vetted programs, so integrity comes from how data is changed, not who outranks whom.

  • Access triple — subject → Transformation Procedure (TP) → Constrained Data Item (CDI); never subject → data directly.
  • Well-formed transactions — TPs move CDIs from one valid state to another.
  • IVPs — Integrity Verification Procedures confirm data validity.
  • Separation of duties is enforced by certifying who may run which TP.
  • UDIs — unconstrained (unvetted) inputs that TPs must sanitize.

Exam tell: “well-formed transactions”, “access triple”, or integrity + separation of duties = Clark-Wilson.

Conflict of interest · dynamic

Brewer-Nash (Chinese Wall)

Built for consultancies and brokerages: prevent conflicts of interest. Access rights change dynamically based on what a user has already accessed.

  • Data is grouped into conflict-of-interest classes (e.g. competing banks).
  • Touch Bank A's dataset and the wall goes up: Bank B's dataset in the same class becomes off-limits.
  • The only classic model whose permissions depend on a user's access history.

Exam tell: “conflict of interest”, “consultants serving competitors”, or access that changes based on prior activity = Brewer-Nash.

The trap the exam loves
Bell-LaPadula and Biba are mirror images. BLP protects confidentiality: no read UP, no write DOWN. Biba protects integrity: no read DOWN, no write UP. Fix the pair “BLP = secrets, Biba = trust” and derive the arrows — never memorize four rules separately.

The supporting cast

ModelProtects / doesRemember it by
State machineFoundation: system is secure if every state and transition is secure.The parent idea under BLP and Biba.
Information flowControls where data may move, not just who reads it.BLP/Biba restated as flow rules.
NoninterferenceActions at a high level must be invisible at lower levels.Stops covert signalling, not just direct reads.
Lattice-basedEvery subject/object gets a position in a lattice of labels; access follows least upper / greatest lower bounds.The mathematical scaffolding of MAC.
Graham-DenningHow subjects, objects and rights are managed — eight rules: create/delete subject, create/delete object, and grant/transfer/delete/read access rights.Eight administrative rules.
Harrison-Ruzzo-Ullman (HRU)Extends Graham-Denning: is there any sequence of operations that leaks a right? (Generally undecidable.)Rights-amendment analysis.
Take-GrantDirected graph with four rules — take, grant, create, revoke — showing how rights can propagate between subjects.Four verbs on a graph.
Don’t confuse models with evaluation criteria
TCSEC (the Orange Book), ITSEC and the Common Criteria (EAL 1–7) are frameworks for evaluating systems — they use models, but they are not security models themselves. If the question mentions assurance levels or certification, it’s asking about evaluation criteria, not a model.

Cheat table

If the question says…Answer
No read up / no write downBell-LaPadula
No read down / no write upBiba
Well-formed transactions, access triples, IVPsClark-Wilson
Conflict of interest, access based on historyBrewer-Nash
Eight rules for managing rightsGraham-Denning
Take, grant, create, revokeTake-Grant
High-level actions invisible belowNoninterference
Assurance / EAL levelsEvaluation criteria (Common Criteria), not a model

Drill these as questions in Domain 3 flashcards and exam practice.

Further study: the official ISC2 CISSP Exam Outline. This page is an independently written study summary.

Independent CISSP study aid. CISSP is a registered trademark of ISC2. This resource is not affiliated with or endorsed by ISC2.