...
[API 2006] Class SecurityManager
[Oaks 2001] Chapter 5: The Access Controller, "Permissions"
[Policy 2002]
[Sun 2006] Permission Descriptions and Risks
...
SEC09-J. Do not base security checks on untrusted sources 09. Platform Security (SEC) SEC11-J. Call the superclass's getPermissions method when writing a custom class loader