Domain 3 - System Evaluation and Assurance Levels Flashcards

1
Q

TCSEC

A

Trusted Computing Security Evaluation Criteria

Orange Book standard that describes the Trusted Computing Base; most of today’s security models are based on this. Considers only Confidentiality (of CIA triad)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Red Book

A

Network Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ITSEC

A

European Technology Security Eval Criteria–based on Orange Book, retired now. Considers ll of CIA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO/IEC 15408

A

The Common Criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Common Criteria

A

Global standard. Product evaluation criteria, resulting in EALs (Evaluation Assurance Levels)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

TOE under the Common Criteria

A

Target of Evaluation – the system that is the subject of the CC evaluation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

PP under the Common Criteria

A

Protection profile – the document that identifies security requirements for a class of security devices. Products can comply with more than one PP and customers can focus on products certified agains the PP that meet their requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ST under the Common Criteria

A

Security Target – the document that identifies the security properties of the Target of Evaluation. The ST may have one or more PPs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Certification

A

Evaluation of security and technical/non-technical features to ensure if it meets specified requirements to achieve accreditation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Accreditation

A

Declare that an IT system is approved to operate in predefined conditions defined as a set of safety measures at given risk level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly