前往小程序,Get更优阅读体验!
立即前往
首页
学习
活动
专区
工具
TVP
发布
社区首页 >专栏 >CISSP考试指南笔记:3.6 系统评估方法

CISSP考试指南笔记:3.6 系统评估方法

作者头像
血狼debugeeker
发布2020-12-29 11:16:00
4700
发布2020-12-29 11:16:00
举报
文章被收录于专栏:debugeeker的专栏debugeeker的专栏

An assurance evaluation examines the security-relevant parts of a system, meaning the TCB, access control mechanisms, reference monitor, kernel, and protection mechanisms. The relationship and interaction between these components are also evaluated in order to determine the level of protection required and provided by the system.

Common Criteria

The Common Criteria is a framework within which users specify their security requirements and vendors make claims about how they satisfy those requirements, and independent labs can verify those claims.

Under the Common Criteria model, an evaluation is carried out on a product and it is assigned an Evaluation Assurance Level (EAL). The thorough and stringent testing increases in detailed-oriented tasks as the assurance levels increase. The Common Criteria has seven assurance levels. The range is from EAL1, where functionality testing takes place, to EAL7, where thorough testing is performed and the system design is verified. The different EAL packages are

  • EAL1 Functionally tested
  • EAL2 Structurally tested
  • EAL3 Methodically tested and checked
  • EAL4 Methodically designed, tested, and reviewed
  • EAL5 Semi-formally designed and tested
  • EAL6 Semi-formally verified design and tested
  • EAL7 Formally verified design and tested‘

剩余内容请看本人公众号debugeeker, 链接为CISSP考试指南笔记:3.6 系统评估方法

本文参与 腾讯云自媒体分享计划,分享自作者个人站点/博客。
原始发表:2020-12-26 ,如有侵权请联系 cloudcommunity@tencent.com 删除

本文分享自 作者个人站点/博客 前往查看

如有侵权,请联系 cloudcommunity@tencent.com 删除。

本文参与 腾讯云自媒体分享计划  ,欢迎热爱写作的你一起参与!

评论
登录后参与评论
0 条评论
热度
最新
推荐阅读
目录
  • Common Criteria
领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档