A reference monitor is

[t]he security engineering term for IT functionality that (1) controls all access, (2) cannot be by-passed, (3) is tamper-resistant, and (4) provides confidence that the other three items are true.[1]
[a] [c]oncept of an abstract machine that enforces Target of Evaluation (TOE) access control policies.[2]

