ArticleslgStudy

computer science

The Protection of Information in Computer Systems

The Protection of Information in Computer Systems is a computer science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand The Protection of Information in Computer Systems rather than just read about it. In short: The Protection of Information in Computer Systems is a 1975 seminal publication by Jerome Saltzer and Michael Schroeder about information security. The paper emphasized that the primary concern of security measures should be the information on computers and not the computers itself.

Key takeaways

  • The Protection of Information in Computer Systems belongs to computer science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect The Protection of Information in Computer Systems to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of The Protection of Information in Computer Systems from memory before moving on to harder problems.

Reference excerpt

The Protection of Information in Computer Systems is a 1975 seminal publication by Jerome Saltzer and Michael Schroeder about information security. The paper emphasized that the primary concern of security measures should be the information on computers and not the computers itself. It was published 10 years prior to Trusted Computer System Evaluation Criteria, commonly known as the Orange Book.

Design principles The following design principles are laid out in the paper:

Economy of mechanism: Keep the design as simple and small as possible. Fail-safe defaults: Base access decisions on permission rather than exclusion. Complete mediation: Every access to every object must be checked for authority. Open design: The design should not be secret. Separation of privilege: Where feasible, a protection mechanism that requires two keys to unlock it is more robust and flexible than one that allows access to the presenter of only a single key. Least privilege: Every program and every user of the system should operate using the least set of privileges necessary to complete the job. Least common mechanism: Minimize the amount of mechanism common to more than one user and depended on by all users. Psychological acceptability: It is essential that the human interface be designed for ease of use, so that users routinely and automatically apply the protection mechanisms correctly. Work factor: Compare the cost of circumventing the mechanism with the resources of a potential attacker. Compromise recording: It is sometimes suggested that mechanisms that reliably record that a compromise of information has occurred can be used in place of more elaborate mechanisms that completely prevent loss.

See also Common Criteria Secure by design Defense in depth

References

External links Saltzer, Jerome; Schroeder, Michael (April 17, 1975). "The Protection of Information in Computer Systems". Symposium on Operating Systems Principles.

Worked examples

Example 1 — a first encounter with The Protection of Information in Computer Systems

Start with the simplest possible case. Write down what The Protection of Information in Computer Systems claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In computer science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to The Protection of Information in Computer Systems before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about The Protection of Information in Computer Systems ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of The Protection of Information in Computer Systems

In research
The Protection of Information in Computer Systems appears in computer science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses The Protection of Information in Computer Systems in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
The Protection of Information in Computer Systems is common in secondary-school and first-year university syllabi. It links to neighbouring topics Computer science papers, Computer security software, Computer security stubs, so understanding it makes those chapters shorter.
In everyday life
Look for The Protection of Information in Computer Systems outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “The Protection of Information in Computer Systems” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study The Protection of Information in Computer Systems in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what The Protection of Information in Computer Systems means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain The Protection of Information in Computer Systems out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is The Protection of Information in Computer Systems in simple terms?

The Protection of Information in Computer Systems is a 1975 seminal publication by Jerome Saltzer and Michael Schroeder about information security. The paper emphasized that the primary concern of security measures should be the information on computers and not the computers itself.

Why does The Protection of Information in Computer Systems matter?

Because it connects several computer science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study The Protection of Information in Computer Systems?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on The Protection of Information in Computer Systems.

Tags

  • Computer science papers
  • Computer security software
  • Computer security stubs
  • Software design

Keep exploring