Free CISSP Certification Practice Questions:
Which of the following is NOT addressed by the Clark-Wilson Integrity Model?
A) Procedures that take the system from one valid state to another
B) Procedures that test the constrained data items to conform to integrity constraints
C) Data not subject to integrity controls
D) Data subject to integrity controls
E) Procedures that prevent a subject at a lower level of integrity from invoking a subject at a higher level of integrity
-
[Ans: E]
The Clark-Wilson model involves
two primary elements for achieving data
integrity the well-formed transaction
and separation of duties. Well-formed
transactions prevent users from manipulating
data, thus ensuring the internal consistency
of data. Separation of duties prevents
authorized users from making improper
modifications, thus preserving the external
consistency of data by ensuring that data
in the system reflects the real-world
data it represents.
The model defines the following terms:
TP - transaction procedures. Procedures
that take the system from one valid state
to another.
IVP - integrity verification procedures.
Procedures that test the constrained data
items to conform to integrity constraints
CDI - constrained data items.
Data subject to integrity controls.
UDI- unconstrained data items.
Data not subject to integrity controls
On the other hand, the Biba Integrity
Model, NOT the Clark-Wilson model
specifies procedures that prevent a subject
at a lower level of integrity from invoking
a subject at a higher level of integrity.
BACK | NEXT