Security models turn a policy (“keep secrets secret”, “keep data trustworthy”) into formal rules a system can enforce and evaluators can prove. The exam almost never asks for the math — it describes a property or rule and asks which model it belongs to. This page is built for exactly that move: the big four in detail, the supporting cast, and the directionality traps spelled out.
The big four
Bell-LaPadula (BLP)
Built for military classification systems: stop information flowing from high classifications to low ones. Subjects and objects carry labels; the model constrains reads and writes by label.
- Simple Security Property — no read up (a Secret-cleared user cannot read Top Secret).
- ★ (Star) Property — no write down (a Top Secret process cannot write into a Secret file, or secrets would leak downward).
- Strong ★ Property — read/write only at your own level.
- Discretionary access on top via an access matrix (the ds-property).
Exam tell: any mention of “no read up / no write down”, classifications, or protecting confidentiality with labels = Bell-LaPadula.
Biba
Bell-LaPadula flipped upside down, protecting integrity instead of secrecy: stop bad (low-integrity) data contaminating good (high-integrity) data.
- Simple Integrity Property — no read down (don't consume data less trustworthy than you).
- ★ Integrity Property — no write up (don't let less trustworthy processes modify more trustworthy data).
- Invocation property — can't invoke services at a higher integrity level.
Exam tell: “no read down / no write up” or any question about protecting data trustworthiness = Biba. If the rules look like BLP inverted, it IS Biba.
Clark-Wilson
Commercial integrity without labels: users never touch data directly. All changes go through vetted programs, so integrity comes from how data is changed, not who outranks whom.
- Access triple — subject → Transformation Procedure (TP) → Constrained Data Item (CDI); never subject → data directly.
- Well-formed transactions — TPs move CDIs from one valid state to another.
- IVPs — Integrity Verification Procedures confirm data validity.
- Separation of duties is enforced by certifying who may run which TP.
- UDIs — unconstrained (unvetted) inputs that TPs must sanitize.
Exam tell: “well-formed transactions”, “access triple”, or integrity + separation of duties = Clark-Wilson.
Brewer-Nash (Chinese Wall)
Built for consultancies and brokerages: prevent conflicts of interest. Access rights change dynamically based on what a user has already accessed.
- Data is grouped into conflict-of-interest classes (e.g. competing banks).
- Touch Bank A's dataset and the wall goes up: Bank B's dataset in the same class becomes off-limits.
- The only classic model whose permissions depend on a user's access history.
Exam tell: “conflict of interest”, “consultants serving competitors”, or access that changes based on prior activity = Brewer-Nash.
The supporting cast
| Model | Protects / does | Remember it by |
|---|---|---|
| State machine | Foundation: system is secure if every state and transition is secure. | The parent idea under BLP and Biba. |
| Information flow | Controls where data may move, not just who reads it. | BLP/Biba restated as flow rules. |
| Noninterference | Actions at a high level must be invisible at lower levels. | Stops covert signalling, not just direct reads. |
| Lattice-based | Every subject/object gets a position in a lattice of labels; access follows least upper / greatest lower bounds. | The mathematical scaffolding of MAC. |
| Graham-Denning | How subjects, objects and rights are managed — eight rules: create/delete subject, create/delete object, and grant/transfer/delete/read access rights. | Eight administrative rules. |
| Harrison-Ruzzo-Ullman (HRU) | Extends Graham-Denning: is there any sequence of operations that leaks a right? (Generally undecidable.) | Rights-amendment analysis. |
| Take-Grant | Directed graph with four rules — take, grant, create, revoke — showing how rights can propagate between subjects. | Four verbs on a graph. |
Cheat table
| If the question says… | Answer |
|---|---|
| No read up / no write down | Bell-LaPadula |
| No read down / no write up | Biba |
| Well-formed transactions, access triples, IVPs | Clark-Wilson |
| Conflict of interest, access based on history | Brewer-Nash |
| Eight rules for managing rights | Graham-Denning |
| Take, grant, create, revoke | Take-Grant |
| High-level actions invisible below | Noninterference |
| Assurance / EAL levels | Evaluation criteria (Common Criteria), not a model |
Drill these as questions in Domain 3 flashcards and exam practice.
Further study: the official ISC2 CISSP Exam Outline. This page is an independently written study summary.
Independent CISSP study aid. CISSP is a registered trademark of ISC2. This resource is not affiliated with or endorsed by ISC2.