【正文】
評價和認可 В Γ 應(yīng)用系統(tǒng)案例考慮 ? 圖書館信息管理系統(tǒng) – 提供的服務(wù)和功能 – 面臨的主要安全問題 – 要求的安全服務(wù) – 建議的安全機制和方案 – 訪問控制 ? 學(xué)生宿舍網(wǎng)絡(luò)系統(tǒng) – … В Γ links В Γ Q A В Γ ? 靜夜四無鄰,荒居舊業(yè)貧。 ? // 該級系統(tǒng)得具有 EAL3/CC安全級。 ? // 該級要求最小的基于角色的認證。一個例子就是 PC機加密板。 ? 此標準可分為兩部份:首部份為準則部份,旨在協(xié)助機構(gòu)確認其運作對資料保密方面的影響,這項準則已納入 ISO品質(zhì)認證的范疇之內(nèi)( ISO 17799認證),涵蓋 10大范疇, 127控制點; ? 次部份為施行細則,是有關(guān)資料保密管理系統(tǒng) Information Security Management System 的架構(gòu)、目標以及監(jiān)控。Goto “” – Canadian System Security Centre: Canadian Trusted Computer Product Evaluation Criteria – It is a puter security standard parable to the American TCSEC (Orange Book) but somewhat more advanced. It has been superseded by the international Common Criteria standard. – 可和 TCSEC相比,但更進步 – 已被國際標準 CC替代 В Γ NIST/FIPS В Γ CC В Γ CC 3Parts ? Part 1 Introduction and General Model ? Part 2 Security Functional Requirements Annexes ? Part 3 Security Assurance Requirements ? В Γ CC / EAL Evaluation Assurance Levels ? EAL1:功能測試 ? EAL2:結(jié)構(gòu)測試 ? EAL3:系統(tǒng)測試和檢查 ? EAL4:系統(tǒng)設(shè)計、測試和復(fù)查 ? EAL5:半形式化設(shè)計和測試 ? EAL6:半形式化驗證的設(shè)計和測試 ? EAL7:形式化驗證的設(shè)計和測試 В Γ EAL1: Functional Test ? Confidence in current operation is required ? No assistance from TOE developer ? Applicable where threat to security is not serious ? Independent testing against specification and guidance documentation В Γ EAL2: Structural Test ? Requires some cooperation of the developer ? Adds requirements for configuration list, delivery, highlevel design documentation, developer functional testing, vulnerability analysis, and more extensive independent testing В Γ EAL3: Methodical Test and Check ? Requires some positive security engineering at the design stage, with minimal changes to existing practices ? Added assurance through investigation of product and development environment controls, and highlevel design documentation ? Places additional requirements on testing, development environment controls and TOE configuration management В Γ EAL4: Methodical Design, Test, and Review ? Highest level likely for retrofit of an existing product ? Additional requirements