Why have domains in DAIS Security?
Linda Gricius (March, 1998): DAIS Security supports three types of domain – principal, policy, and trusted identify domains. The major security advantage in dividing a system into domains is to achieve separation of unrelated parts of an organization – either people/departments or sets of applications/data. By separating the system into domains, the appropriate security controls can be put in place for each domain, and access to information between parts can be controlled. If a domain member deliberately tries to damage the system, the damage they can do will be limited by their domain’s security limitations. The best separation of the security system is most likely to mimic organizational structures that you already have. For example, the reason the Sales department is separate from the Development department is that the two communities deal with different business processes, and consequently have different applications/data and security requirements. Furthermore, the two departments