The Protection of Information in Computer Systems


The Protection of Information in Computer Systems is a 1975 seminal publication by Jerome Saltzer and Michael Schroeder about information security. The paper emphasized that the primary concern of security measures should be the information on computers and not the computers itself.
It was published 10 years prior to Trusted Computer System Evaluation Criteria, commonly known as the Orange Book.

Design principles

The following design principles are laid out in the paper: