∙access to database objects.
Logging facilities should be accessible only to the administrator and include for him/her respective facilities for viewing and reviewing stored events by the above parameters and archiving these.
The following should be indicated during logging:
∙time and date of the user login/logout into/out of the system and of the system loading/shutdown;
∙the identifier of the user initializing the process;
∙the result of the action (successful or unsuccessful – unauthorized).
When files or database objects are accessed, specification of the access object and the code of the operation requested for are also logged.
The integrity assurance subsystem should ensure:
∙integrity of the IASS software and database.
∙integrity of the IASS database in the DBMS through isolation of this from users and online recovery on the part of the administrator.
No class 3 A&C systems have a cryptosystem.
Hereinafter, requirements to class 3 A&C systems are set forth. An access control subsystem should:
∙identify communication channels by physical addresses;
∙control the access of subjects to secured OS resources in accordance with the access matrix based on a discrete principle;
∙control the access of subjects to the DBMS objects in accordance with the access matrix by sampling, modification, insert, deletion and other operations;
∙limit user access to secured objects using only strictly specified processes;
∙realize a mandate principle of access control;
∙control information flows using the subject and object secrecy attribute;
∙transmit data over the network together with secrecy attributes which should be secured.
Unauthorized operations on networked data and unauthorized duplication of data should be safely identified as an error and logged respectively.
We shall clarify the requirement of the access control mandate principle. Theoretically, there are two basic principles (or models) to control access to resources. These are a discrete model and a mandate model. When the discrete principle of access to objects is realized, each object contains an access control listing, i.e. a list of users with a permit of access. An access matrix is specified for each user, that is, what action exactly the given user