This document summarizes a lecture on multi-level security. It discusses defining a security policy for an organization through a role-based model. It presents an example security policy for an educational institute, assigning different access levels like "top secret", "secret", and "confidential" to roles including the principal, faculty, staff, students, and daily workers. It emphasizes the importance of formally specifying the security policy to avoid ambiguities and inconsistencies.