Problem Statement
Which access control model enforces that subjects cannot read up and cannot write down, typically used in high-security systems?
Explanation
In Mandatory Access Control systems the OS enforces a central policy that limits how subjects (processes) can access objects based on security labels. The classic Bell-LaPadula model states ‘no read up’ and ‘no write down’ to preserve confidentiality. MAC is commonly discussed in OS security contexts.
