Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Consider the following Attribute-based Access Control policies: PA: Permit if OR (FINGER_Ok, HANDSHAPE_Ok) PB: Permit if VOICE_Ok PC: Deny if FACE_notok PD: POV(PA,PB) PE: POV

image text in transcribed
image text in transcribed
Consider the following Attribute-based Access Control policies: PA: Permit if OR (FINGER_Ok, HANDSHAPE_Ok) PB: Permit if VOICE_Ok PC: Deny if FACE_notok PD: POV(PA,PB) PE: POV (PD, PC) a) What is the decision returned by the policies PA, PB, PC, PD and PE, if all attributes evaluate to True? [5 Marks] b) What is the decision returned by the policies PA, PB, PC, PD and PE, if all attributes evaluate to Unknown? [5 Marks] c) Find an attribute evaluation such that PE evaluates to Deny. [5 Marks] A financial organisation providing credit cards and short-term loans is collecting and storing all financial transactions done by its customers when they use their credit cards. This information is then used by the organisation to decide whether to accept or deny a loan application from a customer: if their spending behaviour is deemed risky, the loan application will be denied. All transactions are stored in a SQL database, which is available by the organisation's employees through a form written in HTML and Javascript, and protected by a unique password. To comply with GDPR, they do not store in plain text the name of their customers, and use a unique pseudo-identifier for each customer, but they keep the details of each transaction. a) Identify and assess the risk of an Information Disclosure threat, and recommend an avoidance risk control against that threat. [10 Marks] b) Identify and assess the risk of a Spoofing threat, and recommend a mitigation risk control against that threat. [10 Marks]

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Beginning PostgreSQL On The Cloud Simplifying Database As A Service On Cloud Platforms

Authors: Baji Shaik ,Avinash Vallarapu

1st Edition

1484234464, 978-1484234464

More Books

Students also viewed these Databases questions

Question

Evaluate the impact of unions on nurses and physicians.

Answered: 1 week ago

Question

Describe the impact of strikes on patient care.

Answered: 1 week ago

Question

Evaluate long-term care insurance.

Answered: 1 week ago