is permitted to undertake with respect to the given object. For files, for example, the access matrix realizes the following rights: read, write, add, create, delete, rename and execute (for exacutable files).
When a mandate principle of access control is realized, each object and subject is assigned a double attribute. The first part of the attribute should reflect one of five secrecy levels: “unclassified”, “restricted” and so on. The second attribute part should reflect one of topical categories. In this, the following rules should be observed:
∙a subject is granted the right to read information only in the event that the subject secrecy level is higher than or equal to the secrecy level of the object and the category of the object either coincides with or is a subset of the subject category;
∙a subject may get the right to write with respect to an object in the event that the object secrecy level is higher than or equal to the secrecy level of the subject, and the subject category either coincides with or is a complete subset of the category (group) of the object.
More details on access to information based on the discrete principle are given in the “Operating Systems” section.
For data networking, the requirements of Gostekhkomissiya establish that this should involve facilities that prevent transmission of data to an object of a secrecy level lower than that of the data transmitted.
The logging and accounting subsystem should:
∙log output of classified printed documents as hard copies;
∙log attempts of software access to the following secured access objects: networks components and fragments, ports, peripherals and processes;
∙log all errors of network data exchange revealed;
∙automatically account for created secured objects by giving them additional labels used in the access control subsystem;
∙clear (zero, initialize, depersonalize) vacated storage areas in computers and segregated external carriers. Clearing is done by a double random entry into any vacated storage area used to store secured information.
Printout of classified documents requires automatic labeling of sheets by numbers and accounting requisites. Simultaneously, an account card should be made out for the document with specified logging parameters.
Requirements to the integrity and cryptography support subsystems coincide in full with requirements to similar subsystems of Class 3 A&C systems.
Requirements to class 1 A&S systems include all requirements to class 2 and 3 A&C systems.