1. Consider a desktop publishing system used to produce documents for various organizations. Give an example in which system availability is the most impotent requirement. Please be very brief.

2. The necessity of the “no read up” rule for a multilevel security is fairly obvious. What is the importance of the “no write down” rule?

3. List and briefly define the five alternatives for treating identified risks.

