1. Trusted Computer Systems
2. Information System Security
3. Issues with Trusted Computer Systems
4. Evaluation Concepts and Relationships
5. Evaluation Concepts and Relationships
6. Trusted Computing Base
7. Types of Secure Computing Systems
8. Dedicated (Single-Level) Systems
9. System-High
10. Compartmented
11. Multi-Level Systems
12. Evaluation Process
13. Security Evaluation Stages
14. Apprroaching Security Evaluation Tasks
15. Risk Assessment
16. Risk Assessment - Yellow Book
Risk Index = Max Info Sensitivity - Min User Clearance
17. Risk Rating Level Table
| Rating | Info Sensitivity | User Clearance |
|---|---|---|
| 0 | Unclassified | Uncleared |
| 1 | Restricted | Restricted |
| 2 | Restricted (categories) Confidential | Confidential |
| 3 | Confidential (categories) Secret | Secret |
| 4 | Secret (1+ categories) | Top Secret |
| 5 | Secret (2+ categories) Top Secret | Top Secret |
| 6 | Top Secret (1+ categories) | Top Secret - 1 category |
| 7 | Top Secret (2+ categories) | Top Secret - many categories |
18. Recommended Systems
| Risk Index | Security Mode | Min Class Open Env | Min Class Closed Env |
|---|---|---|---|
| 0 | dedicated | none | none |
| 0 | system high | C2 | C2 |
| 1 | limited access, controlled, compartmented, multi-level | B1 | B1 |
| 2 | limited access, controlled, compartmented, multi-level | B2 | B2 |
| 3 | controlled, multi-level | B3 | B3 |
| 4 | multi-level | A1 | B3 |
| 5 | multi-level | beyond A1 | A1 |
| >=6 | multi-level | beyond A1 | beyond A1 |
19. Risk Analysis - DSD Gateway Certification Guide
20. Process
21. Asset Identification
22. Threat & Threat Likelihood Estimation
23. Harm Estimation
24. Risk Assessment
risk = threat likelihood x harm
| Harm | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| T h r e a t |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Resultant Risk |
25. Required Risk & Countermeasure Rating
26. Summary
27. Exercises