CISSP Domain 3: Bell-LaPadula vs Biba (No More Mix-Ups)
On the CISSP, Bell-LaPadula protects confidentiality with read down, write up, while Biba protects integrity with read up, write down - the exact mirror. Reverse one arrow and you fail a question you actually understood, which is why the property direction is the single most-missed item in Domain 3. This Domain 3 deep-dive walks the secure design principles 1st, then the formal security models in exact detail, so the directions become automatic instead of a coin flip. With Mei, Erica, Michael, and Nova, we cover objectives 3.1 and 3.2 and the goal-1st habit that turns model questions from guesswork into a quick, defensible decision.
In this video:
- Least privilege, defense in depth, secure defaults, and fail securely
- Separation of duties, keep it simple, and zero trust (never trust, always verify)
- Privacy by design, the shared responsibility model, and secure access service edge
- Bell-LaPadula and Biba with every property direction and a memory hook for each
- Clark-Wilson’s subject-program-object access triple and well-formed transactions
- Brewer-Nash, the Chinese Wall, and how to sort all four models fast
The next video moves into security capabilities, the trusted platform module, memory protection, and control selection. Anchored to the (ISC)2 CISSP Detailed Content Outline effective April 15, 2024.
▶ Watch next: CISSP Domain 3: TPM, Reference Monitor, and TCB https://www.youtube.com/watch?v=g9wxHkllqY0
📺 Full playlist: CISSP (2026) v2 https://www.youtube.com/playlist?list=PLlIAFxS2964_K3g6WysWnLpifoxilduGi
Chapters
- 0:00 The Property Direction That Fails Candidates
- 3:23 Least Privilege and Defense in Depth
- 5:45 Secure Defaults and Fail Securely
- 7:51 Separation of Duties and Keep It Simple
- 10:12 Zero Trust, Privacy, and Shared Responsibility
- 12:42 Why Security Models Exist at All
- 15:07 Bell-LaPadula: No Read Up, No Write Down
- 17:17 Biba: The Mirror Image
- 19:38 Side by Side Without the Mix-Up
- 21:57 Clark-Wilson and the Access Triple
- 24:25 Brewer-Nash and the Model Family Tree
- 26:48 Think Like a Manager
- 29:21 Quiz Time
- 32:55 Key Takeaways
On the CISSP, Bell-LaPadula protects confidentiality with read down, write up, while Biba protects integrity with read up, write down - the exact mirror. Reverse one arrow and you fail a question you actually understood, which is why...
Key Topics
- The Property Direction That Fails Candidates
- Least Privilege and Defense in Depth
- Secure Defaults and Fail Securely
- Separation of Duties and Keep It Simple
- Zero Trust, Privacy, and Shared Responsibility
- Why Security Models Exist at All
- Bell-LaPadula: No Read Up, No Write Down
- Biba: The Mirror Image