Information Technology Security Evaluation Criteria (ITSEC)
Richard Sizer · ITNOW · 1993
Abstract The insecurity of IT systems (typified by unauthorised access) is a complex and increasingly aggravating social problem. All sectors of society - commerce, industry, government (local and national) and domestic are at risk. People who have the responsibility for choosing, installing or using IT systems have faced considerable difficulty in choosing IT security products purporting to provide a ‘secure environment’ employing technical security mechanisms in hardware and software. The problem has, in the main, been the highly subjective claims for, and interpretation of, those security mechanisms.