Domain 3 - System Evaluation and Assurance Levels Flashcards
TCSEC
Trusted Computing Security Evaluation Criteria
Orange Book standard that describes the Trusted Computing Base; most of today’s security models are based on this. Considers only Confidentiality (of CIA triad)
Red Book
Network Systems
ITSEC
European Technology Security Eval Criteria–based on Orange Book, retired now. Considers ll of CIA
ISO/IEC 15408
The Common Criteria
Common Criteria
Global standard. Product evaluation criteria, resulting in EALs (Evaluation Assurance Levels)
TOE under the Common Criteria
Target of Evaluation – the system that is the subject of the CC evaluation
PP under the Common Criteria
Protection profile – the document that identifies security requirements for a class of security devices. Products can comply with more than one PP and customers can focus on products certified agains the PP that meet their requirements
ST under the Common Criteria
Security Target – the document that identifies the security properties of the Target of Evaluation. The ST may have one or more PPs
Certification
Evaluation of security and technical/non-technical features to ensure if it meets specified requirements to achieve accreditation.
Accreditation
Declare that an IT system is approved to operate in predefined conditions defined as a set of safety measures at given risk level.