Tcsec

TCSEC (Trusted Computer System Evaluation Criteria; commonly called the "Orange Book"), is a standard for computer security that was issued by the US government. It was used in the United States, while Canada used their own CTCPEC, and Europe and several other parts of the world used the competing ITSEC standard. These standards have now been superseded by the Common Criteria. TCSEC was issued by the United States Government National Computer Security Council (an arm of the U.S. National Security Agency) as "Trusted Computer System Evaluation Criteria, DOD standard 5200.28-STD, December 1985". TCSEC defines criteria for trusted computer products. There are four levels, A, B, C, and D. Each level adds more features and requirements:
  • D is a non-secure system.
  • C1 requires user log-on, but allows group ID.
  • C2 requires individual log-on with password and an audit mechanism. (Most Unix implementations are roughly C1, and can be upgraded to about C2 without excessive pain).
Levels B and A provide mandatory access control. Access is based on standard Department of Defense clearances:
  • B1 requires DoD clearance levels.
  • B2 guarantees the path between the user and the security system and provides assurances that the system can be tested and clearances cannot be downgraded.
  • B3 requires that the system is characterised by a mathematical model that must be viable.
  • A1 requires a system characterized by a mathematical model that can be proven.

See also

 

<< PreviousWord BrowserNext >>
valaquenta
glin
ainulindal
of the rings of power and the third age
pale
nmenor
solved board games
dysentery
dnedain
monopsony
uncertainty
loyalist volunteer force
sporangium
atlantic league
southern boobook
troubador
bacteriocin
peptic ulcer
courtly love
meteoroid
impact event
immunoperoxidase
uss constellation
shorten
kitniyot
judenrat
huntington beach, california
spicule
sram
benalla, victoria
history of california
california government and politics
echuca, victoria
tyers, victoria
dipluran
traralgon, victoria
proturan
formaldehyde
chosen plaintext attack
tomsk
generalitat
philip v of spain
picture archiving and communication system
valencia