Release Dr. Aafia Siddiqui


Security Rainbow

C2 level security is an unique standard in a computer security realm that the United States Department of Defense (DoD) has developed over the past 30 years. The National Computer Security Center (NCSC), an arm of the National Security Administration, began working on security ratings for military computer systems in 1967. The center published its first report in 1970 and issued its final specifications in the mid-1980s.

There is a rainbow series marking the criteria of different kinds of security standards. Trusted Computer Standards Evaluation Criteria (TCSEC), or the Orange Book, lays out the requirements for security at various levels according to such parameters as the ability of a system to be audited, to control access, and to authenticate users. The Orange Book applies to standalone machines and operating systems.

There are more than 20 such books in this Rainbow Series which have thoroughly interpreted the criteria for other system components. For instance, the Red Book interprets the criteria for network components, the Lavender Book for databases and so on.

There also are security categories, which mark out the level of protection. They are D (minimal protection), B (mandatory protection), C (discretionary protection), and A (verified protection). C2, or controlled access protection, is the lowest that offers viable security.

For C2 certification, a system must

1- Have good documentation at both the user and administration level and have documentation on security testing 2- Authenticate all users as unique individuals 3- Not allow objects to be reused or recovered once deleted 4- Let systems administrators audit all security events and the actions of individual users 5- Protect all objects and processes from all others

Other posts by Commoner


Thank you for reading this post. You can now Leave A Comment (0) or Leave A Trackback.

Post Info

This entry was posted on Sunday, February 18th, 2007 and is filed under Technology .

Tagged with: , , , , , , , , ,

You can follow any responses to this entry through the Comments Feed . You can Leave A Comment, or A Trackback.



Previous Post: Scary Empowerment »
Next Post: Oracle Security »

Read More

Related Reading:


Subscribe without commenting


Leave a Reply

Note: Any comments are permitted only because the site owner is letting you post, and any comments could be removed for any reason at the absolute discretion of the site owner.




Say No to Electricity Bills

About Chowrangi

Chowrangi is a crossroad of lifestyles. Chowrangi cover topics related to business, entertainment, current affairs, religion, sports, technology and other aspects of our daily lives.
If you are interested in writing on Chowrangi.com, drop us a line at info@chowrangi.com


What if America attacks Pakistan?