【正文】
В Γ TNI ? TNI – Trusted Network Interpretation of the TCSEC – Goto “” “” ? Content – Part I – Part II – APPENDIX A, B, C В Γ TNI / I ? Part I of this document provides interpretations of the Department of Defense Trusted Computer System Evaluation Criteria (TCSEC) (), for trusted puter/munications work systems. The specific security feature, the assurance requirements, and the rating structure of the TCSEC are extended to works of puters ranging from isolated local area works to widearea interwork systems. В Γ TNI / II ? Part II of this document describes a number of additional security services (., munications integrity, denial of service, transmission security) that arise in conjunction with works. Those services available in specific work offerings, while inappropriate for the rigorous evaluation applied to TCSEC related feature and assurance requirements, may receive qualitative ratings. В Γ ITSEC ? ITSEC by European Union – Information Technology Security Evaluation Criteria ? Goto “” – Ex遞增 ? E0 – 無安全保證 ? E1 – 有安全目標和關(guān)于體系結(jié)構(gòu)設(shè)計的非形式化描述 ? E2 – 對詳細設(shè)計有非形式化的描述 В Γ ? E3 – 評估源代碼或硬件設(shè)計圖 ? E4 – 有對安全目標 /策略的基本形式模型 ? E5 – 設(shè)計和源代碼 /硬件有緊密的對應(yīng)關(guān)系 ? E6 – 安全功能 /體系結(jié)構(gòu)設(shè)計與安全目標 /策略模型一致 В Γ CSSC’CTCPEC ? CSSC: CTCPEC 187。 В Γ Parts 1, 2 ? Part 1: ISO/IEC 17799:2023 – the standard code of practice and can be regarded as a prehensive catalogue of good security things to do. ? Part 2: BS77992:2023 Specify for security management – a standard specification for an Information Security Management Systems (ISMS). – An ISMS is the means by which Senior Management monitor and control their security, minimising the residual business risk and ensuring that security continues to fulfil corporate, customer and legal requirements. В Γ ToC of P1 ? Information security policy ? Security anization ? Assets classification and control ? Personal security ? Physical and environmental security ? Computer and work management ? System access control ? System development and maintenance ? Business contin