TCSEC Comprehensive Questions
(Frequently Tested) with Verified
Answers Graded A+
EXAM ESSENTIALS: Be able to list the classes of TCSEC, ITSEC, and the Common Criteria. -
Answer: 1). The classes of TCSEC include verified protection, mandatory protection,
discretionary protection, and minimal protection.
2). Table 8.4 covers and compares equivalent and applicable rankings for TCSEC, ITSEC, and the
CC (remember that functionality ratings from F7 to F10 in ITSEC have no corresponding ratings
in TCSEC).
TCSEC Classes and Required Functionality: - Answer: TCSEC combines the functionality and
assurance rating of the confidentiality protection offered by a system into four major categories.
These categories are then subdivided into additional subcategories identified with numbers,
such as C1 and C2. Furthermore, TCSEC's categories are assigned through the evaluation of a
target system. Applicable systems are stand-alone systems that are not networked.
TCSEC defines the following major categories:
>. Category A Verified protection. The highest level of security.
>. Category B Mandatory protection.
>. Category C Discretionary protection.
, >. Category D Minimal protection. Reserved for systems that have been evaluated but do not
meet requirements to belong to any other category.
The list that follows includes brief discussions of categories A through C, along with numeric
suffixes that represent any applicable subcategories (Figure 8.6).
A). Verified Protection (Category A1) - Answer: Verified Protection (Category A1)
Verified protection systems are similar to B3 systems in the structure and controls they employ.
The difference is in the development cycle. Each phase of the development cycle is controlled
using formal methods. Each phase of the design is documented, evaluated, and verified before
the next step is taken. This forces extreme security consciousness during all steps of
development and deployment and is the only way to formally guarantee strong system security.
A1). Verified Protection:
"document, verify every step, from design, delivery & install" - Answer: A1). Verified Protection:
1). A verified design system starts with a design document that states how the resulting system
will satisfy the security policy. From there, each development step is evaluated in the context of
the security policy.
2). Functionality is crucial, but assurance becomes more important than in lower security
categories.
3). A1 systems represent the top level of security and are designed to handle top-secret data.
(Frequently Tested) with Verified
Answers Graded A+
EXAM ESSENTIALS: Be able to list the classes of TCSEC, ITSEC, and the Common Criteria. -
Answer: 1). The classes of TCSEC include verified protection, mandatory protection,
discretionary protection, and minimal protection.
2). Table 8.4 covers and compares equivalent and applicable rankings for TCSEC, ITSEC, and the
CC (remember that functionality ratings from F7 to F10 in ITSEC have no corresponding ratings
in TCSEC).
TCSEC Classes and Required Functionality: - Answer: TCSEC combines the functionality and
assurance rating of the confidentiality protection offered by a system into four major categories.
These categories are then subdivided into additional subcategories identified with numbers,
such as C1 and C2. Furthermore, TCSEC's categories are assigned through the evaluation of a
target system. Applicable systems are stand-alone systems that are not networked.
TCSEC defines the following major categories:
>. Category A Verified protection. The highest level of security.
>. Category B Mandatory protection.
>. Category C Discretionary protection.
, >. Category D Minimal protection. Reserved for systems that have been evaluated but do not
meet requirements to belong to any other category.
The list that follows includes brief discussions of categories A through C, along with numeric
suffixes that represent any applicable subcategories (Figure 8.6).
A). Verified Protection (Category A1) - Answer: Verified Protection (Category A1)
Verified protection systems are similar to B3 systems in the structure and controls they employ.
The difference is in the development cycle. Each phase of the development cycle is controlled
using formal methods. Each phase of the design is documented, evaluated, and verified before
the next step is taken. This forces extreme security consciousness during all steps of
development and deployment and is the only way to formally guarantee strong system security.
A1). Verified Protection:
"document, verify every step, from design, delivery & install" - Answer: A1). Verified Protection:
1). A verified design system starts with a design document that states how the resulting system
will satisfy the security policy. From there, each development step is evaluated in the context of
the security policy.
2). Functionality is crucial, but assurance becomes more important than in lower security
categories.
3). A1 systems represent the top level of security and are designed to handle top-secret data.