No Read Up (Simple Security Property)

The Bell-LaPadula rule that a subject cannot read data classified above their clearance. Confidentiality's ceiling: a Secret clearance never opens a Top Secret file.

Full guide: Bell-LaPadula: No Read Up, No Write Down (CISSP)

No Read Up is the first rule of the Bell-LaPadula model, formally the Simple Security Property. A subject may read an object only if the subject’s clearance dominates the object’s classification. A Secret-cleared analyst can read Secret and below; Top Secret stays closed. The rule is intuitive, which is exactly why it is normally paired with its stranger sibling.

Dominates is doing real work in that sentence. The comparison is a lattice operation over both level and compartment, so a Top Secret clearance still fails against a Secret document in a compartment the subject does not hold. Scenarios that mention compartments or code words are usually testing that second half.

Where the rule sits among its siblings

RuleModelFormal nameProtectsDirection blocked
No Read UpBell-LaPadulaSimple Security PropertyConfidentialityReading from higher classification
Star Property (No Write Down)Bell-LaPadula*-propertyConfidentialityWriting to lower classification
No Read DownBibaSimple Integrity PropertyIntegrityReading from lower integrity
No Write UpBibaStar Integrity PropertyIntegrityWriting to higher integrity

Simple governs reading, Star governs writing. Together, No Read Up and the Star Property make confidentiality airtight: you cannot look above your level, and you cannot leak what you know below it. In mandatory access control terms, No Read Up is the read half of the lattice comparison performed on every access. The Biba model mirrors the rule as No Read Down, protecting integrity instead of confidentiality.

A worked case

An analyst holds Secret clearance with no compartment access. Three documents sit in the repository: a Confidential planning note, a Secret assessment, and a Secret assessment inside a restricted compartment.

The first two open, because Secret dominates both. The third is refused despite matching on level, because the subject’s compartment set does not include the object’s. Nothing about the analyst’s job or intent enters the decision, and no administrator can grant an exception without changing the clearance itself, which is what makes the control mandatory rather than discretionary.

The source

The property is defined in D. E. Bell and L. J. LaPadula, Secure Computer System: Unified Exposition and Multics Interpretation, MITRE Technical Report MTR-2997 Rev. 1 (1976). The paper states three rules, not two: the simple security property, the *-property, and a discretionary security property requiring that the access also be allowed by an access matrix. The third is the one candidates most often forget exists.

Exam relevance: the property names and their rules are worth memorising together, because questions in this area tend to use the formal names rather than the plain-English ones. Anything “Simple” governs reading and anything “Star” governs writing. Then identify the model: reading restricted upward is Bell-LaPadula and confidentiality, reading restricted downward is Biba and integrity. Where a scenario mentions compartments, expect the answer to turn on domination rather than on level alone.

Frequently asked questions

What is the Simple Security Property?
The Simple Security Property is the Bell-LaPadula rule usually stated as No Read Up: a subject may read an object only if the subject's clearance dominates the object's classification. A Secret-cleared analyst may read Secret and below, and Top Secret stays closed. Simple is the convention marking the rule that governs reading, in both Bell-LaPadula and Biba.
What does dominates mean in the Simple Security Property?
Dominates is the lattice comparison the rule actually performs, and it has two parts. The subject's clearance level must be at least the object's classification level, and the subject's compartments must include all of the object's compartments. A Top Secret clearance without the right compartment therefore fails to dominate a Secret document inside that compartment, which is why clearance level alone never settles the question.
How does No Read Up differ from need-to-know?
No Read Up is a mandatory rule enforced by the system from labels, and it cannot be waived by the person holding the data. Need-to-know is a separate restriction asking whether the subject has a business reason for that specific information, and in a labelled system it is usually carried by the non-hierarchical categories or compartments rather than by the level. Clearing the level check therefore does not grant access on its own, since a subject can hold ample clearance and still lack the compartment. Bell-LaPadula's third rule, the discretionary security property, is a further requirement that an access matrix permits the access too.