Architects designing a multilevel public-safety records system must choose a classic model based on protection goals. When the dominant requirement is stopping unauthorized disclosure across clearance levels, which selection is most appropriate?
Select an answer to reveal the explanation.
Short Explanation
Pick the model the way gear gets picked for a mission: secrecy problem? Use a confidentiality model. Integrity problem? Use an integrity model. Do not grab Biba just because the word model sounds fancy.
Full Explanation
Security models should be chosen by mapping required properties to model strengths. Preventing unauthorized disclosure across multilevel clearances aligns with confidentiality-focused models such as Bell-LaPadula. Integrity models do not automatically provide equivalent confidentiality guarantees, and shared passwords contradict multilevel control objectives.