
A 30-part series examining the security design principles in NIST SP 800-160, Volume 1, Revision 1—what they mean, why they matter, and how they can be applied to systems facing sophisticated adversaries, compromise, and failure.
Domain Separation establishes security boundaries that limit the propagation of compromise across system elements. This article examines how separation of domains, resources, and privileges can contain adversary effects and preserve critical system functions when portions of a system are compromised.
Trust boundaries are only effective when interactions across them are controlled. Mediated Access ensures that every security-relevant interaction is subject to explicit policy enforcement, preventing unauthorized access and limiting the pathways through which compromise can propagate.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.