Page 153 - CISSO_Prep_ Guide
P. 153
initiates the activity - it requests access; it is considered to be
"active." Most subjects will have a level of clearance or
permissions that indicate what they are permitted to do.
Examples of a subject would include users, clients, programs,
processes, and applications.
Objects
Objects are the protected asset that provides the requested
service to the subject. A subject asks for something - the object
then provides the service as requested. Since the object does not
initiate the activity, it is considered to be passive - it will remain
in its current state until it is acted upon by a subject. Examples
of an object would include files, databases, memory, printers,
networks, applications, processes, programs, books, and
buildings, to name but a few. Some entities may be either a
subject or an object depending on the situation. A user may
access a program - in which case the user is the subject, and the
program is the object, or a program may want to save data to a
hard drive in which case the program is the subject and the
memory the object.