CBK#6 Security Architecture & Models - Page 7

CBK#6 Security Architecture & Models - Page 1 2 3 4 5 6 7 8 9

Continued … The Orange Book / TCSEC:
Hierarchical division of security levels -
A - Verified protection
B - Mandatory protection
C - Discretionary protection
D - Minimal security
Topics - Security policy, accountability, assurance and documentation
Areas -
Security policy - Must be explicit and well defined and enforced by the mechanisms within the system.
Identification - Individual subjects must be uniquely identified.
Labels - Access control labels must be associated properly with objects.
Documentation - Includes test, design, specification documents, user guides and manuals.
Accountability - Audit data must be captured and protected to enforce accountability.
Life cycle assurance - Software, hardware and firmware must be able to be tested individually to ensure that each enforces the security policy in an effective manner throughout its lifetime.
Continuous protection - The security mechanisms and the system as a whole must perform predictably and acceptably in different situations continuously.
Evaluation levels -
D - Minimal Protection
C1 - Discretionary Security Protection
C2 - Controlled Access Protection
B1 - Labeled Security
B2 - Structured Protection
B3 - Security Domains
A1 - Verified Design

The Red Book / TNI:
TNI - Trusted Network Interpretation.
Addresses security evaluation topics for networks and network components.
It addresses isolated local area networks and wide area internetwork systems.
Security items addressed:
* Communication integrity
-- Authentication
-- Message integrity
-- Nonrepudiation
* Denial of service prevention
-- Continuity of operations
-- Network management
* Compromise protection
-- Data confidentiality
-- Traffic flow confidentiality
-- Selective routing
Ratings -
- None
- C1 - Minimum
- C2 - Fair
- B2 - Good

CBK#6 Security Architecture & Models - Page 1 2 3 4 5 6 7 8 9

CISSP Summary 2002Related links | References

CBK#1 Access Control Systems & Methodology | CBK#2 Telecommunications & Network Security | CBK#3 Security Management Practices | CBK#4 Applications & Systems Development Security | CBK#5 Cryptography | CBK#6 Security Architecture & Models | CBK#7 Operations Security | CBK#8 Business Continuity Planning & Disaster Recovery Planning | CBK#9 Law, Investigations & Ethics | CBK#10 Physical Security

Contact:

E-mail: john.wallhoff@mailbox.swipnet.se
Written by: J.Wallhoff January - April 2002
Updated by: J.Wallhoff April 2002