A computer security policy defines the goals and elements of an organization's computer systems. The definition can be highly formal or informal. Security policies are enforced by organizational policies or security mechanisms. A technical implementation defines whether a computer system is secure or unsecure. These formal policy models can be categorized into the core security principles of: Confidentiality, Integrity and Availability. For example the
Bell LaPadula model is a confidentiality policy model, whereas
Biba model is an integrity policy model.
See more at Wikipedia.org...