certslothcertsloth
CISSP/Topic 12

ISC2 / Professional

Security Models, Trusted Computing and Cryptanalysis

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Confidentiality keeps secrets; integrity protects trustworthy change.

Must remember

Bell–LaPadula addresses confidentiality: no read up and no write down in its classic formulation. Biba addresses integrity: no read down and no write up. Clark–Wilson protects integrity through well-formed transactions, authorized transformation procedures and separation of duties. Brewer–Nash changes access based on prior activity to prevent conflicts of interest. Match the property, not just a memorized phrase.

The reference monitor mediates access, must resist tampering and be small enough to analyze. The trusted computing base includes components whose correct operation is necessary for policy enforcement. Reduce complexity, isolate privileges, fail securely and validate every relevant access; a secure default should not require users to opt into basic protection.

Memory isolation, privilege rings, process boundaries, ASLR and nonexecutable memory address different exploitation paths. A TPM can protect keys and support measured-boot evidence; an HSM protects cryptographic operations. Measured boot reports measurements; secure boot enforces an approved boot chain. Neither guarantees application-level authorization.

Cryptanalytic scenarios differ by attacker knowledge: ciphertext-only, known-plaintext, chosen-plaintext and chosen-ciphertext. Side-channel, timing and fault-injection attacks exploit implementation behavior rather than necessarily defeating the mathematical algorithm. A strong cipher with exposed keys still fails. Pass-the-hash reuses a credential representation; it is not the same as decrypting a password.

Symmetric key length and asymmetric key length are not directly comparable security measures. Plan cryptographic agility so algorithms, protocols and keys can change. Quantum risks affect algorithm families differently; use current approved standards and inventory dependencies rather than guessing that all encryption becomes equally obsolete.

System lifecycle decisions include requirements, design, implementation, integration, verification, validation, operations and secure retirement. Verification checks conformance to specification; validation checks whether the result satisfies the intended need.

Choose under exam pressure

Requirement Choice and reason
Stop lower-integrity input corrupting trusted data Integrity-oriented controls/model.
Prove a boot state to a verifier Measured boot/attestation with a trustworthy verification process.
Unexpected timing reveals key-dependent behavior Analyze implementation side channels, not only algorithm strength.

Traps

  • A security model is an abstraction, not a complete deployment architecture.
  • Secure boot and measured boot are related but different.

Active recall

1. Bell–LaPadula primarily protects what?

Confidentiality.

2. Biba primarily protects what?

Integrity.

3. Why should a reference monitor be small?

Its mediation and policy enforcement must be analyzable and reliably correct.

4. Does a side-channel attack need to break the cipher mathematically?

No. It can exploit timing, power or other implementation leakage.

5. Verification versus validation?

Verification checks the specification; validation checks the actual intended need.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.