CBK#6 Security Architecture & Models - Page 8

CBK#6 Security Architecture & Models - Page 1 2 3 4 5 6 7 8 9

ITSEC:
ITSEC - Information Technology Security Evaluation Criteria.
Only used in Europe
Two main attributes - Functionality and Assurance.
Is a criteria for both security products and security systems and refers to both as the target of evaluation (TOE).

Common Criteria:
Is an international evaluation standard.
EAL - Evaluation assurance level.
Protection profile - The set of security requirements, their meaning and reasoning and the corresponding EAL rating.
Two main attributes - Functionality and Assurance.
Five sections of the protection profile -
- Descriptive elements
- Rationale
- Functional requirements
- Development assurance requirements
- Evaluation assurance requirements

Certification <-> Accreditation
Certification:
Is the technical evaluation of the security components and their compliance for the purpose of accreditation.
Is the process of assessing the security mechanisms and controls and evaluating their effectiveness.

Accreditation:
Is the formal acceptance of the adequacy of a system's overall security by the management.
Is management's official acceptance of the information in the certification process findings.

Open Systems <-> Closed Systems
Open Systems:
Have an architecture that has published specifications, which enables third-party vendors to develop add-on components and devices.
Provides interoperability between products by different vendors of different operating systems, applications and hardware devices.

Closed Systems
:
Use an architecture that does not follow industry's standards.
Interoperability and standard interfaces are not employed to enable easy communication between different types of systems and add-on features.
Are proprietary, meaning that the system can only communicate with like systems.


CBK#6 Security Architecture & Models - Page 1 2 3 4 5 6 7 8 9

CISSP Summary 2002Related links | References

CBK#1 Access Control Systems & Methodology | CBK#2 Telecommunications & Network Security | CBK#3 Security Management Practices | CBK#4 Applications & Systems Development Security | CBK#5 Cryptography | CBK#6 Security Architecture & Models | CBK#7 Operations Security | CBK#8 Business Continuity Planning & Disaster Recovery Planning | CBK#9 Law, Investigations & Ethics | CBK#10 Physical Security

Contact:

E-mail: john.wallhoff@mailbox.swipnet.se
Written by: J.Wallhoff January - April 2002
Updated by: J.Wallhoff April 2002