{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,4,3]],"date-time":"2022-04-03T00:44:49Z","timestamp":1648946689511},"reference-count":80,"publisher":"Elsevier","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2002]]},"DOI":"10.1016\/s0065-2458(01)80030-9","type":"book-chapter","created":{"date-parts":[[2011,9,16]],"date-time":"2011-09-16T21:35:39Z","timestamp":1316208939000},"page":"185-235","source":"Crossref","is-referenced-by-count":7,"title":["Security policies"],"prefix":"10.1016","author":[{"given":"Ross","family":"Anderson","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frank","family":"Stajano","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jong-Hyeon","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/S0065-2458(01)80030-9_bib1","isbn-type":"print","author":"Amoroso","year":"1994","ISBN":"http:\/\/id.crossref.org\/isbn\/0133055418"},{"key":"10.1016\/S0065-2458(01)80030-9_bib2","article-title":"Computer Security Technology Planning Study","author":"Anderson","year":"1972"},{"key":"10.1016\/S0065-2458(01)80030-9_bib3","series-title":"12th Annual Computer Security Applications Conference","isbn-type":"print","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1109\/CSAC.1996.569669","article-title":"Starlingt: Interactive Link","author":"Anderson","year":"1996","ISBN":"http:\/\/id.crossref.org\/isbn\/081867606X"},{"key":"10.1016\/S0065-2458(01)80030-9_bib4","series-title":"Proceedings of the IEEE Symposium on Research in Security and Privacy","first-page":"30","article-title":"A Security Policy Model for Clinical Information Systems","author":"Anderson","year":"1996"},{"key":"10.1016\/S0065-2458(01)80030-9_bib5","series-title":"Proceedings of the Annual Computer Security Applications Conference 1999","article-title":"How to Cheat at the Lottery (or, Massively Parallel Requirements Engineering","author":"Anderson","year":"1999"},{"issue":"11","key":"10.1016\/S0065-2458(01)80030-9_bib6_1","first-page":"874","article-title":"The DeCODE Proposal for an Icelandic Health Database","volume":"84","author":"Anderson","year":"1998","journal-title":"L\/oeknabladhidh (The Icelandic Medical Journal"},{"key":"10.1016\/S0065-2458(01)80030-9_bib7","author":"Anderson","year":"1999","journal-title":"Comment on the Security Targets for the Icelandic Health Database"},{"key":"10.1016\/S0065-2458(01)80030-9_bib8","isbn-type":"print","author":"Anderson","year":"2001","ISBN":"http:\/\/id.crossref.org\/isbn\/0471389226"},{"issue":"11","key":"10.1016\/S0065-2458(01)80030-9_bib9","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1145\/188280.188291","article-title":"Why Cryptosystems Fail","volume":"37","author":"Anderson","year":"1994","journal-title":"Communications of the ACM"},{"key":"10.1016\/S0065-2458(01)80030-9_bib10","isbn-type":"print","author":"Anderson","year":"1996","ISBN":"http:\/\/id.crossref.org\/isbn\/0727910485"},{"key":"10.1016\/S0065-2458(01)80030-9_bib11","series-title":"Proceedings of Security Protocols Workshop '99","article-title":"Jikzi: A New Framework for Secure Publishing","author":"Anderson","year":"1999"},{"key":"10.1016\/S0065-2458(01)80030-9_bib12","unstructured":"Ross John Anderson and Jong-Hyeon Lee: \u201cJiki\u2014A New Framework for Security Policy, Trusted Publishing and Electronic Commerce\u201d. Computer Communications to appear."},{"key":"10.1016\/S0065-2458(01)80030-9_bib13","series-title":"Proceedings of the 5th USENIX UNIX Security Symposium","first-page":"66","article-title":"Practical Domain and Type Enforcement for UNIX","author":"Badger","year":"1995"},{"key":"10.1016\/S0065-2458(01)80030-9_bib14","article-title":"Secure Computer Systems: Mathematical Foundations","volume":"Vol. I\u2013III","author":"Bell","year":"1974"},{"key":"10.1016\/S0065-2458(01)80030-9_bib15","series-title":"Seventeenth National Computer Security Conference","first-page":"227","article-title":"BFE Applicability to LAN Environments","author":"Benkart","year":"1994"},{"key":"10.1016\/S0065-2458(01)80030-9_bib16","first-page":"365","article-title":"KSOS-Development Methodology for a Secure Operating System","author":"Berson","year":"1979"},{"key":"10.1016\/S0065-2458(01)80030-9_bib17","article-title":"Integrity Considerations for Secure Computing Systems","author":"Biba","year":"1975"},{"key":"10.1016\/S0065-2458(01)80030-9_bib18","article-title":"The Key Note Trust-Management System Version 2","author":"Blaze","year":"1999"},{"key":"10.1016\/S0065-2458(01)80030-9_bib19","series-title":"Proceedings of the IEEE Symposium on Research in Security and Privacy, Research in Security and Privacy","article-title":"Decentralized Trust management","author":"Blaze","year":"1996"},{"key":"10.1016\/S0065-2458(01)80030-9_bib20","series-title":"Proceedings of the 8th National Computer Security Conference","first-page":"18","article-title":"A Practical Alternative to Hierarchical Integrity Policies","author":"Boebert","year":"1985"},{"key":"10.1016\/S0065-2458(01)80030-9_bib21","series-title":"1989 IEEE Symposium on Security and Privacy","first-page":"206","article-title":"The Chinese Wall Security Policy","author":"Brewer","year":"1989"},{"key":"10.1016\/S0065-2458(01)80030-9_bib22","series-title":"13th Annual Computer Security Application Conference","isbn-type":"print","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1109\/CSAC.1997.646170","article-title":"Simple Assured Bastion Hosts","author":"Cant","year":"1997","ISBN":"http:\/\/id.crossref.org\/isbn\/0818682744"},{"key":"10.1016\/S0065-2458(01)80030-9_bib23","article-title":"Data Communications Networks Directory","author":"CCITT","year":"1988"},{"key":"10.1016\/S0065-2458(01)80030-9_bib24","series-title":"1987 IEEE Symposium on Security and Privacy","first-page":"184","article-title":"A Comparison of Commerical and Military Computer Security Policies","author":"Clark","year":"1987"},{"issue":"11","key":"10.1016\/S0065-2458(01)80030-9_bib25","doi-asserted-by":"crossref","first-page":"1268","DOI":"10.1145\/50087.50089","article-title":"A Field Study of the Software Design Process for Large Systems","volume":"31","author":"Curtis","year":"1988","journal-title":"Communications of the ACM"},{"key":"10.1016\/S0065-2458(01)80030-9_bib26","doi-asserted-by":"crossref","first-page":"1328","DOI":"10.1136\/bmj.318.7194.1328","article-title":"Privacy in clinical information systems in secondary care","volume":"318","author":"Denley","year":"1999","journal-title":"British Medical Journal"},{"key":"10.1016\/S0065-2458(01)80030-9_bib27","first-page":"236","article-title":"A Lattice Model of Secure Information Flow","volume":"19","author":"Dorothy E.","year":"1976"},{"issue":"5","key":"10.1016\/S0065-2458(01)80030-9_bib28","doi-asserted-by":"crossref","first-page":"236","DOI":"10.1145\/360051.360056","article-title":"A Lattice Model of Secure Information Flow","volume":"19","author":"Denning","year":"1976","journal-title":"Communications of the ACM"},{"key":"10.1016\/S0065-2458(01)80030-9_bib29","isbn-type":"print","article-title":"Denning","author":"Dorothy","year":"1982","ISBN":"http:\/\/id.crossref.org\/isbn\/0201101505"},{"issue":"6","key":"10.1016\/S0065-2458(01)80030-9_bib30","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","article-title":"New directions in cryptography","volume":"IT-22","author":"Diffie","year":"1976","journal-title":"IEEE Transactions on Information Theory"},{"issue":"8","key":"10.1016\/S0065-2458(01)80030-9_bib31","doi-asserted-by":"crossref","first-page":"823","DOI":"10.1016\/S1389-1286(98)00018-8","article-title":"The nature of a useable PKI","volume":"31","author":"Ellison","year":"1999","journal-title":"Computer Networks"},{"key":"10.1016\/S0065-2458(01)80030-9_bib32","doi-asserted-by":"crossref","DOI":"10.17487\/rfc2693","article-title":"SPKI Certificate Theory","author":"Ellison","year":"1999"},{"issue":"2\u20133","key":"10.1016\/S0065-2458(01)80030-9_bib33","doi-asserted-by":"crossref","first-page":"159","DOI":"10.3233\/JCS-1993-22-306","article-title":"A High Assurance Window System Prototype","volume":"2","author":"Epstein","year":"1993","journal-title":"Journal of Computer Security"},{"key":"10.1016\/S0065-2458(01)80030-9_bib34","series-title":"Ninth Annual Computer Security Applications Conference","isbn-type":"print","doi-asserted-by":"crossref","first-page":"256","DOI":"10.1109\/CSAC.1993.315434","article-title":"User Interface for a High Assurance Windowing System","author":"Epstein","year":"1993","ISBN":"http:\/\/id.crossref.org\/isbn\/0818643307"},{"key":"10.1016\/S0065-2458(01)80030-9_bib35","series-title":"Proceedings of the 14th Annual National Computer Security Conference","article-title":"Reconciling CMW Requirements with Those of X11 Applications","author":"Faden","year":"1991"},{"key":"10.1016\/S0065-2458(01)80030-9_bib36","article-title":"Information Protection Systems","author":"Fenton","year":"1973"},{"key":"10.1016\/S0065-2458(01)80030-9_bib37","series-title":"15th NIST-NCSC National Computer Security Conference","first-page":"554","article-title":"Role-Based Access Controls","author":"Ferraiolo","year":"1992"},{"issue":"2","key":"10.1016\/S0065-2458(01)80030-9_bib38","doi-asserted-by":"crossref","first-page":"158","DOI":"10.3233\/JCS-1992-1203","article-title":"Aggregation and separation as noninterference properties","volume":"1","author":"Foley","year":"1992","journal-title":"Journal of Computer Security"},{"issue":"7","key":"10.1016\/S0065-2458(01)80030-9_bib39","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/MC.1983.1654440","article-title":"SCOMP: A Solution to the Multilevel Security Problem","volume":"16","author":"Fraim","year":"1983","journal-title":"Computer"},{"key":"10.1016\/S0065-2458(01)80030-9_bib40","series-title":"Proceedings of the 2000 IEEE Symposium on Security and Privacy","first-page":"230","article-title":"LOMAC: Low Water-Mark Integrity Protection for COTS Environments","author":"Fraser","year":"2000"},{"key":"10.1016\/S0065-2458(01)80030-9_bib41","series-title":"Proceedings of the 1982 Symposium on Security and Privacy (SSP '82)","first-page":"11","article-title":"Security Policies and Security Models","author":"Goguen","year":"1990"},{"key":"10.1016\/S0065-2458(01)80030-9_bib42","article-title":"Compartmented Mode, Workstation Evaluation Criteria, Version 1","author":"Graubart","year":"1991"},{"issue":"8","key":"10.1016\/S0065-2458(01)80030-9_bib43","doi-asserted-by":"crossref","first-page":"461","DOI":"10.1145\/360303.360333","article-title":"Protection in Operating Systems","volume":"19","author":"Harrison","year":"1976","journal-title":"Communications of the ACM"},{"issue":"4","key":"10.1016\/S0065-2458(01)80030-9_bib44","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1145\/190748.190750","article-title":"CMW Introduction","volume":"12","author":"Huber","year":"1994","journal-title":"ACM SIGSAC"},{"key":"10.1016\/S0065-2458(01)80030-9_bib45","series-title":"Fairfax 93: 1st ACM Conference on Computer and Communications Security","isbn-type":"print","doi-asserted-by":"crossref","first-page":"118","DOI":"10.1145\/168588.168604","article-title":"A Pump for Rapid, Reliable, Secure Communications","author":"Kang","year":"1993","ISBN":"http:\/\/id.crossref.org\/isbn\/0897916298"},{"key":"10.1016\/S0065-2458(01)80030-9_bib46","series-title":"13th Annual Computer Security Applications Conference","isbn-type":"print","doi-asserted-by":"crossref","first-page":"194","DOI":"10.1109\/CSAC.1997.646190","article-title":"An Architecture for Multilevel Secure Interoperability","author":"Kang","year":"1997","ISBN":"http:\/\/id.crossref.org\/isbn\/0818682744"},{"key":"10.1016\/S0065-2458(01)80030-9_bib47","series-title":"12th Annual Computer Security Applications Conference","isbn-type":"print","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/CSAC.1996.569667","article-title":"A Case Study of Two NRL Pump Prototypes","author":"Kang","year":"1996","ISBN":"http:\/\/id.crossref.org\/isbn\/081867606X"},{"key":"10.1016\/S0065-2458(01)80030-9_bib48","article-title":"A New Mandatory Security Policy Combining Secrecy and Integrity","author":"Karger","year":"2000"},{"key":"10.1016\/S0065-2458(01)80030-9_bib49","article-title":"Designing a reliable publishing framework","author":"Lee","year":"2000"},{"key":"10.1016\/S0065-2458(01)80030-9_bib50","series-title":"Proceedings of Security Protocols Workshop 1999","first-page":"15","article-title":"Auditing against Multiple Policies (Transcript of Discussion)","author":"Lomas","year":"1999"},{"key":"10.1016\/S0065-2458(01)80030-9_bib51","series-title":"Er redete mit dem Vieh, den V\u00f6geln und den Fischen (King Solomon's ring)","author":"Lorenz","year":"1949"},{"issue":"6","key":"10.1016\/S0065-2458(01)80030-9_bib52","doi-asserted-by":"crossref","first-page":"563","DOI":"10.1109\/32.55085","article-title":"A Hookup Theorem for Multilevel Security","volume":"16","author":"McCullough","year":"1990","journal-title":"IEEE Transactions on Software Engineering"},{"key":"10.1016\/S0065-2458(01)80030-9_bib53","series-title":"Encyclopedia of Software Engineering","article-title":"Security Models","author":"McLean","year":"1994"},{"issue":"2","key":"10.1016\/S0065-2458(01)80030-9_bib54","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1016\/0020-0190(85)90065-1","article-title":"A comment on the \u2018basic security theorem\u2019 of Bell and LaPadula","volume":"20","author":"McLean","year":"1985","journal-title":"Information Processing Letters"},{"key":"10.1016\/S0065-2458(01)80030-9_bib55","isbn-type":"print","author":"Moynihan","year":"1999","ISBN":"http:\/\/id.crossref.org\/isbn\/0300080794"},{"issue":"4","key":"10.1016\/S0065-2458(01)80030-9_bib56","doi-asserted-by":"crossref","first-page":"299","DOI":"10.1007\/BF01212405","article-title":"The Formal Specification of Safety Requirements for Storing Explosives","volume":"5","author":"Mukherjee","year":"1993","journal-title":"Formal aspects of Computing"},{"key":"10.1016\/S0065-2458(01)80030-9_bib57","series-title":"12th Annual Computer Security Applications Conference","isbn-type":"print","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1109\/CSAC.1996.569665","article-title":"Implementing Security Policy in a Large Defence Procurement","author":"Nash","year":"1996","ISBN":"http:\/\/id.crossref.org\/isbn\/081867606X"},{"key":"10.1016\/S0065-2458(01)80030-9_bib58_1","unstructured":"National Security Agency \u201cThe NSA Security Manual\u201d. Tech. rep., NSA. URL"},{"issue":"12","key":"10.1016\/S0065-2458(01)80030-9_bib59","doi-asserted-by":"crossref","first-page":"993","DOI":"10.1145\/359657.359659","article-title":"Using Encryption for Authentication in Large Networks of Computers","volume":"21","author":"Needham","year":"1978","journal-title":"Communications of the ACM"},{"key":"10.1016\/S0065-2458(01)80030-9_bib60","author":"Neuman","year":"1993"},{"key":"10.1016\/S0065-2458(01)80030-9_bib61","article-title":"Common Criteria for Information Technology Security Version 2.1","author":"NIST","year":"2000"},{"key":"10.1016\/S0065-2458(01)80030-9_bib62","author":"Public Record Office","year":"1999","journal-title":"Functional Requirements for Electronic Record Management Systems"},{"key":"10.1016\/S0065-2458(01)80030-9_bib63","series-title":"Computer Security Applications Conference","isbn-type":"print","doi-asserted-by":"crossref","first-page":"190","DOI":"10.1109\/CSAC.1998.738618","article-title":"Private Desktops and Shared Store","author":"Pomeroy","year":"1998","ISBN":"http:\/\/id.crossref.org\/isbn\/0818687894"},{"key":"10.1016\/S0065-2458(01)80030-9_bib64","series-title":"V1.0 presented at USENIX 96 and Crypto 96","article-title":"SDSI\u2014A Simple Distributed Security Infrastructure","author":"Rivest","year":"1996"},{"key":"10.1016\/S0065-2458(01)80030-9_bib65","series-title":"IEEE Computer","first-page":"55","article-title":"A Distributed Secure System","author":"Rushby","year":"1983"},{"issue":"2","key":"10.1016\/S0065-2458(01)80030-9_bib66","first-page":"16","article-title":"Computer Security: The Achilles' Heel of the Electronic Air Force?","volume":"30","author":"Schell","year":"1979","journal-title":"Air University Review"},{"key":"10.1016\/S0065-2458(01)80030-9_bib67","article-title":"Preliminary notes on the design of secure military computer systems","author":"Schell","year":"1973"},{"key":"10.1016\/S0065-2458(01)80030-9_bib68","series-title":"Security Protocols, 7th International Workshop Proceedings","article-title":"The Resurrecting Duckling: Security Issues in Ad-Hoc Wireless Networks","author":"Stajano","year":"1999"},{"key":"10.1016\/S0065-2458(01)80030-9_bib69","series-title":"Proceedings of 3rd AT&T Software Symposium","article-title":"The Resurrecting Duckling: Security Issues in Ad-Hoc Wireless Networks","author":"Stajano","year":"1999"},{"key":"10.1016\/S0065-2458(01)80030-9_bib70","series-title":"Proc. 9th National Security Conference","first-page":"175","article-title":"A Model of Information","author":"Sutherland","year":"1986"},{"key":"10.1016\/S0065-2458(01)80030-9_bib71","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-349-12020-8_7","article-title":"Technical Rationale behind CSC-STD-003-85: computer security requirements","author":"US Department of Defense","year":"1985"},{"key":"10.1016\/S0065-2458(01)80030-9_bib72","article-title":"Trusted Computer System Evaluation Criteria","author":"US Department of Defense","year":"1985"},{"key":"10.1016\/S0065-2458(01)80030-9_bib73","article-title":"Models for Secure Computer Systems","author":"Walter","year":"1973"},{"key":"10.1016\/S0065-2458(01)80030-9_bib74","article-title":"Primitive Models for Computer Security","author":"Walter","year":"1974"},{"key":"10.1016\/S0065-2458(01)80030-9_bib75","first-page":"119","article-title":"Security Controls in the ADEPT-50 Time-Sharing System","volume":"vol. 35","author":"Weissman","year":"1969"},{"key":"10.1016\/S0065-2458(01)80030-9_bib76","series-title":"Proceedings of the 1992 IEEE Computer Society Symposium on Security and Privacy (SSP '92)","isbn-type":"print","doi-asserted-by":"crossref","first-page":"286","DOI":"10.1109\/RISP.1992.213253","article-title":"BLACKER: Security for the DDN, Examples of A1 Security Engineering Trades","author":"Weissman","year":"1992","ISBN":"http:\/\/id.crossref.org\/isbn\/0818628251"},{"key":"10.1016\/S0065-2458(01)80030-9_bib77","series-title":"The Cambridge Cap Computer and its Operating System","isbn-type":"print","year":"1979","ISBN":"http:\/\/id.crossref.org\/isbn\/0444003576"},{"key":"10.1016\/S0065-2458(01)80030-9_bib78","article-title":"Security Requirements for System High and Compartmented Mode Workstations","author":"Woodward","year":"1987"},{"key":"10.1016\/S0065-2458(01)80030-9_bib79","isbn-type":"print","author":"Wright","year":"1987","ISBN":"http:\/\/id.crossref.org\/isbn\/0855610980"},{"key":"10.1016\/S0065-2458(01)80030-9_bib80","isbn-type":"print","author":"Zimmermann","year":"1995","ISBN":"http:\/\/id.crossref.org\/isbn\/0262740176"}],"container-title":["Advances in Computers"],"original-title":[],"deposited":{"date-parts":[[2019,6,15]],"date-time":"2019-06-15T20:00:19Z","timestamp":1560628819000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0065245801800309"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2002]]},"references-count":80,"URL":"https:\/\/doi.org\/10.1016\/s0065-2458(01)80030-9","relation":{},"ISSN":["0065-2458"],"issn-type":[{"value":"0065-2458","type":"print"}],"subject":[],"published":{"date-parts":[[2002]]}}}