The Bell–LaPadula security model is a formal, mathematical model for enforcing confidentiality in computer systems that handle information at multiple security levels. It defines how a subject—such as a user or process—may access an object, such as a file, based on their security levels and permissions.
How Bell–LaPadula controls access
The model represents a system as a set of states and rules governing how it may move between them. A system is considered secure when its state and permitted transitions preserve the specified confidentiality policy. The rules apply to modeled subjects, objects, security levels, and access modes; using labels alone does not establish that a real system is secure.
As an Amazon Associate I earn from qualifying purchases.
Security levels can include both a classification and categories or compartments. The model compares them using a dominance relation, rather than assuming that every level is just a point on one simple rank.
The two core confidentiality rules
Simple security property: no read up
A subject may read an object only if the subject’s clearance dominates the object’s classification. In plain terms, a subject cannot read information at a level above its clearance. This is the simple security property described in the IETF’s RFC 4949.
#1 Best Overall
*-property: no write down
The *-property restricts writing so that a subject cannot disclose higher-level information by writing it to a lower-level object. The familiar shorthand is “no write down”; RFC 4949 also calls this the confinement property. Together, the read and write restrictions limit information flows that could violate confidentiality.
Mandatory labels and discretionary permissions
Bell–LaPadula includes a discretionary security property as well as mandatory rules based on security levels. The discretionary property concerns whether a subject has permission to perform a particular access mode on an object, often represented with an access matrix. A subject therefore needs both the relevant discretionary permission and authorization under the mandatory label rules. These are distinct checks: a permission does not override a conflicting classification rule. The NIST-hosted proceedings of the 9th National Computer Security Conference discuss the simple security and tranquility properties.
What the model does—and does not—cover
Bell–LaPadula is a confidentiality policy model. It does not by itself provide a complete account of system integrity, availability, or every security threat. RFC 4949 contrasts it with Biba, an integrity-policy model whose rules are duals of corresponding Bell–LaPadula rules. The distinction matters: controlling who can read or disclose classified information is not the same as ensuring that data remains accurate or trustworthy.
Recommended Free Tools
History and the tranquility principle
The IETF attributes Bell–LaPadula to David Bell and Leonard LaPadula at MITRE in 1973. The UC Davis Security Lab’s computer-security history archive lists related 1973 reports and the authors’ 1976 Secure Computer System: Unified Exposition and MULTICS Interpretation, which collected earlier material and adapted rules to the evolving Multics security-kernel design.
Rank #3
Tranquility—the principle that security levels do not change in ways that undermine the policy—must be described with its formulation in mind. RFC 4949 includes tranquility among the model’s properties, but the NIST-hosted proceedings explain that the original 1973 version included it and the 1976 version removed it to allow controlled changes to active-object security levels. How such changes are controlled depends on the application, so tranquility is not an unqualified rule of every Bell–LaPadula formulation.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




