¨More and more software is components
–No single context of use
–No single policy context
¨Policies are global, but (successful) design is (hierarchically) decomposed
–The overall security policy must be reduced to something can be locally applied and understood at each component.
–There are too many levels of abstraction to remember at once.
–This leads to a fundamental problem of “focus of attention.”