Trustworthy Software Initiative (TSI) Flashcards
What is Trustworthy Software Initiative (TSI)
Trustworthy Software Foundation (TSFdn) is a UK organisation with stated aim of improving software
What type of approach must you adopt to determine a software trustworthiness level
TSI recommends a risk based approach
TL0
Software Audience
No requirement for trustworthy software
Control Set
No requirement
TL1
Software Audience
Mass market with Implicit Need (M/I)
Control Set TS Essentials (TSE)
TL2
Software Audience
Mass market with Implicit Need (M/I)
Control Set
Baseline TS controls – subset of TSF
TL3
Software Audience
Mass market with Explicit Need (M/E)
Control Set TS Framework (TSF)
TL4
Software Audience
Niche with Explicit Need (N/E)
Control Set
Comprehensive TS controls – full TSF
What are the Facets Trustworthiness
Safety – the ability of the system to operate without harmful states
Reliability – the ability of the system to deliver services as specified
Availability – the ability of the system to deliver services when
requested
Resilience – the ability of the system to transform, renew, and recover
in timely response to events
Security – the ability of the system to remain protected against accidental or deliberate attacks
Trustworthy Software Essentials is used for what type of software
Software requiring TL1 & TL2
SCUDA is a subset of TSF for software in Scope for Use Coding Practices Use Tools Effectively Defect Management Artefact Management
TL1 & TL2 Trustworthy Software Essentials
Trustworthy Software Framework is used for what type of software
Used for software requiring TL3 & TL4
Organised under Governance, Risk, Controls & Compliance, Personnel, Physical, Procedural & Technical