This course will cover advanced topics in security policies. We will look at the types of policies, including mandatory, discretionary, role-based, and information flow. We will also review confidentiality, integrity, and privacy policies. Students will understand mathematical models and formal reasoning about policies, and system architectural considerations for enforcing policies. The course will introduce traceability of mechanism to policy and of policy to mechanism. Students will understand and perform policy composition, as well as assessing the suitability of policies for particular uses.