SLIDE 1
Need for an Integration Protection Profile
- Security is a system property
- Existing MILS protection profiles (PPs) are for components
- How do we know that a system composed of evaluated
components is secure?
- And how is the evaluation for the system constructed
from the evaluations of its components?
- This is what the MILS Integration PP (MIPP) must address
- It is an instance of compositional certification
- A bold vision that pushes the state of the art