SLIDE 6 6
TCSEC Requirements
Security policy What security (access to resoruces) is required in the system/product Accountability How the system links individuals to actions and audit orderly behavior Functionality What does the system to be secure Assurance How certain can we be that the functionality is correct Documentation How well is the functionality and the development documented Quality Is the defined security enforced in the expected way
TCSEC Hierachy
Class D – Minimal Protection (unrated) Class C – Discretionary Protection
C1 Discretionary security protection C2 Controlled Access protection
Class B – Mandatory Protection
B1 Labeled Security Protection B2 Structured Protection B3 Security Domains
Class A – Verified Protection
A1 Verified Design