Modeling the Security Objectives According to the Common Criteria Methodology.
Andrzej Białas · Security and Management · 2007
The paper discusses the selected issues of the IT security development process according to the Common Criteria, focusing on its security objectives elaboration stage. Meeting these objectives by the IT product or system, called there target of evaluation (TOE), decide about its assurance. The security objectives are elaborated on the basis of security problem definition and are used to specify security requirements to be satisfied by the security functions, implemented in the TOE at the claimed and evaluated assurance level (EAL). Thus the preciseness of the security objectives specification influence the design quality and the TOE assurance. The paper presents the general model of the security objectives, its elaboration processes and the defined specification means. The model is UML/OCL-based, thus it can be better understood by a wide community of UML users. The paper deals with more extensive works concerning IT security modeling and the development of computeraided tools.