Page 152 - CISSO_Prep_ Guide
P. 152
permissions from the perspective of the user, and one from the
perspective of the protected asset/building. This is the concept
of an information management model (IMM). An information
management model describes the relationships between subjects
and objects and the rules that must be set up to manage that
relationship.
The information management model starts by identifying all
users and all objects and then documenting the rules that will be
enforced between those entities.
Subjects
A subject is an entity that requests a service from another entity.
For example, a user trying to access a building. Since the subject