Security label
A classification level, plus any categories or compartments, bound to an object or subject so that mandatory access control can compare it with a clearance and decide access.
A security label is the sensitivity marking a system binds to an object, such as a file or record, and in labelled systems to each subject too. A label commonly has two parts: a hierarchical classification level such as Confidential, Secret or Top Secret, and non-hierarchical categories or compartments that restrict access to a named project or group. Mandatory access control compares the subject’s security clearance with the object’s label, and because levels and categories combine into a lattice, these are called lattice-based models.
NIST SP 800-53 Rev. 5 covers labels under AC-16, Security and Privacy Attributes. Its discussion describes labelling as associating attributes with subjects and objects inside the system so the system can enforce policy, and separates it from marking, the human-readable form on media and printouts. The value a label carries comes from data classification, a decision of the data owner; the label is the form of that decision a system can enforce.
Exam relevance: a scenario is likely to ask what a mandatory access control system compares when it decides a request, or to set a system label against a printed marking. Candidates are expected to attach labels to objects and clearances to subjects, and to recognise compartments as a reason a high clearance can still be refused.