Reference monitor
Term · Cybersecurity · MLC-T-CYB-003491
1. The security engineering term for IT functionality that (1) controls all access, (2) cannot be by-passed, (3) is tamper-resistant, and (4) provides confidence that the other three items are true.
2. A set of design requirements on a reference validation mechanism which as key component of an operating system, enforces an access control policy over all subjects and objects. A reference validation mechanism must be: (i) always invoked (i.e., complete mediation); (ii) tamperproof; and (iii) small enough to be subject to analysis and tests, the completeness of which can be assured (i.e., verifiable).
3. A set of design requirements on a reference validation mechanism that, as a key component of an operating system, enforces an access control policy over all subjects and objects. A reference validation mechanism is always invoked (i.e., complete mediation), tamperproof, and small enough to be subject to analysis and tests, the completeness of which can be assured (i.e., verifiable).
| Identifier | MLC-T-CYB-003491 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-33 [Withdrawn]; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-53 Rev. 5; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003491",
"term": "Reference monitor",
"field": "Cybersecurity",
"definition": "1. The security engineering term for IT functionality that (1) controls all access, (2) cannot be by-passed, (3) is tamper-resistant, and (4) provides confidence that the other three items are true.\n\n2. A set of design requirements on a reference validation mechanism which as key component of an operating system, enforces an access control policy over all subjects and objects. A reference validation mechanism must be: (i) always invoked (i.e., complete mediation); (ii) tamperproof; and (iii) small enough to be subject to analysis and tests, the completeness of which can be assured (i.e., verifiable).\n\n3. A set of design requirements on a reference validation mechanism that, as a key component of an operating system, enforces an access control policy over all subjects and objects. A reference validation mechanism is always invoked (i.e., complete mediation), tamperproof, and small enough to be subject to analysis and tests, the completeness of which can be assured (i.e., verifiable).",
"references": [
"NIST SP 800-33 [Withdrawn]",
"NIST SP 800-53 Rev. 4 [Superseded]",
"NIST SP 800-53 Rev. 5",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/reference-monitor/"
}
Record 3,474 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.