home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!usc!news.aero.org!faigin
- From: faigin@aero.org (Daniel P. Faigin)
- Newsgroups: comp.security.misc
- Subject: Re: Security Levels
- Date: 15 Dec 92 07:51:48
- Organization: The Aerospace Corporation, El Segundo, CA
- Lines: 58
- Distribution: usa
- Message-ID: <FAIGIN.92Dec15075148@soldan.aero.org>
- References: <1992Dec14.232220.8343@cbis.ece.drexel.edu>
- NNTP-Posting-Host: soldan.aero.org
- In-reply-to: jpw@lorelei.ece.drexel.edu's message of 14 Dec 92 23:22:20 GMT
-
- On 14 Dec 92 23:22:20 GMT, jpw@lorelei.ece.drexel.edu (Joseph Wetstein) said:
-
- > Could somebody be kind enough to post (or mail) the definitions (with
- > examples, in clear english) of the NSCS security levels/criteria,
- > i.e. D, C1, C2, B1, ... etc.
-
- Unfortunately, if we had clear English, our job of evaluating to those levels
- would be much easier!
-
- In any case, let me try a summary. These funny digraphs (C2, etc.) are ratings
- of commercial products that are evaluated by an *unclassified* branch of the
- NSA, the Trusted Product Evaluation Program, with help from some Federal
- Contract Research Centers: Mitre, IDA, and Aerospace. The digraphs specify a
- particular level of security functionality and assurance in a product.
-
- D is for products that have no security functionality
-
- The C division is for products with discretionary protection (like Unix access
- control ONLY) C1 really isn't used: it has minimal functionality. C2 provides
- audit, discrationary controls, object reuse, and identification and
- authentication. Assurance is primarily through testing.
-
- The B division adds mandatory labels (UNCLASSIFIED, etc.) to the DAC
- protection. B1 is basically C2 with training wheels. B2 increases assurance by
- requiring the code to be highly modular; B3 increases the assurance by
- requiring minimal kernels, and formal models.
-
- The A division adds formal verification to the mix
-
- > If there are any gov't publications available, how would I get them?
-
- A good synopsis of the digraphs can be found in Debby Russell's book "Computer
- Security Basics" from O'Reilly Press. You can also obtain the relevant NSA
- publications:
-
- To order them, call
- 301.766.8729 or 301.688.8742 or write:
-
- Department of Defense
- National Security Agency
- ATTN: S332
- 9800 Savage Road
- Ft George G. Meade, MD 20755-6000
-
- Daniel Faigin
- Chair, ACM/SIGSAC
-
-
-
- > --
- > Joseph P. Wetstein __|__ "I may be Captain by
- > jpw@coe.drexel.edu ---o-(_)-o--- rank, but I never wanted
- > to be anything else but
- > KA3VJY an engineer" - Scotty
- --
- [W]:The Aerospace Corp. M1/055 * POB 92957 * LA, CA 90009-2957 * 310/336-8228
- [Email]:faigin@aerospace.aero.org [Vmail]:310/336-5454 Box#13149
- "And as they say, the rest is compost"
-