1) Define the fundamental principles in both the Bell-LaPadula and Biba security models. For each, explicate what sort of security the model is intended to provide the two key properties of the model, as well as then explain why each of the properties makes sense from a security standpoint.
2) What is the difference among inference and aggregation? Give an instance of each and describe at least one way to mitigate each type of vulnerability.
3) Define the difference between least privilege and separation of duty. Which one would you usage to secure an Accounting system and why?
4) When is the usage of qualitative risk analysis desirable to quantitative methods?
5) Label what is DACL and RBACL and how it works. When would you usage one versus another?