Data Protection and Security

   

VI

Operating System Security and Secure Programming

   

VI.III

Security Evaluation

   

   
 

Users of secure systems need some kind of assurance that the products they use provide adequate security. They could:

  1. Rely on the word of the manufacturer/service provider.
  2. Test the system themselves.
  3. Rely on an impartial assessment by an independent body (evaluation).

The Trusted Computer Security Evaluation Criteria (TCSEC, Orange Book) were the first evaluation criteria to gain wide acceptance. A number of other criteria have since been developed to improve on the Orange Book and to unify different criteria which have arisen. These are:

  • Information Technology Security Evaluation (ITSEC)
  • Canadian Trusted Computer Product Evaluation Criteria
  • Federal Criteria
  • Common Criteria
   

   
       
 
«previous session [1] [2] [3] [4] [5] [6] [7] [8] [9] next session »
   
       
 
«proceed to previous sectionproceed to next section »
  chapter index