Toward a Comprehensive INFOSEC Certification Methodology
Charles Payne, Judith N. Froscher, Carl E. Landwehr · 1993
Accreditors want to know what vulnerabilities will exist if they decide to turn on a system. TCSEC evaluations ad-dress products, not systems. Not only the hardware and software of a system are of concern; the accreditor needs to view these components in relation to the environment in which they operate and in relation to the system's mis-sion and the threats to it. This paper proposes an informal but comprehensive certi®cation approach that can pro-vide the accreditor with the necessary information. First, we discuss the identi®cation of assumptions and assertions that re¯ect system INFOSEC requirements. Second, we propose the de®nition of an assurance strategy to integrate security engineering and system engineering. The assur-ance strategy initally documents the set of assumptions and assertionsderived from the requirements. It is elabo-rated and re®ned throughout the development, yielding the assurance argument, delivered with the system, which provides the primary technical basis for the certi®cation decision. With the assurance strategy in place, certi®-cation of the trusted system can become an audit of the development process.