Biba model
|
The Biba Model is a formal state transition system of computer security policy that describes a set of access control rules designed to ensure that data is not contaminated.
Features
This security model is directed toward data integrity (rather than security) and is characterized by the phrase: "no write up, no read down". Compare Bell-LaPadula model.
With Biba, users can only create content at or below their own security level (a monk may write a prayer book that can be read by commoners, but a high priest would not be allowed to view the work of the (presumably) less pious monk). Conversely, users can only view content at or above their own security level (a monk may read a book written by the high priest, but may not read a pamphlet written by a lowly commoner).de:Biba Modell