5.2 DEFINITION AND USEFULNESS

Copyright(c) Management Analytics, 1995 - All Rights Reserved

The term "control objective" refers to a statement of intent with respect to control over some aspect of an organization's resources, or processes, or both. In terms of a computer system, control objectives provide a framework for developing a strategy for fulfilling a set of security requirements for any given system. Developed in response to generic vulnerabilities, such as the need to manage and handle sensitive data in order to prevent compromise, or the need to provide accountability in order to detect fraud, control objectives have been identified as a useful method of expressing security goals. [Brand80]

Examples of control objectives include the three basic design requirements for implementing the reference monitor concept discussed in Section 6. They are: