Access Specifications

The list of users from whom the security label is revoked can optionally be followed by keywords that specify the type of access to data that the security policy of the label protects
  • FOR WRITE ACCESS

    These keywords restrict the label to the write access rules of IDSLBACRULES, namely IDLSBACWRITEARRAY, IDLSBACWRITESET, and IDLSBACWRITETREE.

  • FOR READ ACCESS

    These keywords restrict the label to the read access rules of IDSLBACRULES, namely IDLSBACWREADARRAY, IDLSBACREADSET, and IDLSBACREADTREE.

  • FOR ALL ACCESS

    These keywords apply the label to all of the read and write access rules that are listed above. If the REVOKE SECURITY LABEL statement includes no FOR ... ACCESS specification, this option takes effect as the default.

For more information about these IDSLBACRULES rules for label-based read and write access, see Rules Associated with a Security Policy. For information about exemptions to these rules that can be granted for a specific security policy, see Rules on Which Exemptions Are Revoked.