课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Security evaluation models

Security evaluation models

- [Instructor] The government is, by necessity, very serious about cybersecurity, and it's had rigorous cybersecurity programs in place for decades, long before the private sector began considering information security issues. In order to manage the complexity of securing many diverse systems, the government developed standardized evaluation models designed to help them understand the security requirements of different situations and the security capabilities of different products. In 1983, the National Security Agency issued the Trusted Computer System Evaluation Criteria, abbreviated TCSEC. Now, the security community quickly discarded that bulky name and began referring to this book by the distinctive color of its cover, calling it the Orange Book. The Orange Book described the security requirements that the Department of Defense used for computer systems and the process that the government would follow when evaluating systems under that model. The Orange Book was widely used in…

内容