Mandatory Access Control - Evaluation of MAC System Strength

Evaluation of MAC System Strength

The Common Criteria is based on this science and it intended to preserve the Assurance Level as EAL levels and the functionality specifications as Protection Profiles. Of these two essential components of objective robustness benchmarks, only EAL levels were faithfully preserved. In one case, TCSEC level C2 (not a MAC capable category) was fairly faithfully preserved in the Common Criteria, as the Controlled Access Protection Profile (CAPP). Multilevel security (MLS) Protection Profiles (such as MLSOSPP similar to B2) is more general than B2. They are pursuant to MLS, but lack the detailed implementation requirements of their Orange Book predecessors, focusing more on objectives. This gives certifiers more subjective flexibility in deciding whether the evaluated product’s technical features adequately achieve the objective, potentially eroding consistency of evaluated products and making it easier to attain certification for less trustworthy products. For these reasons, the importance of the technical details of the Protection Profile is critical to determining the suitability of a product.

Such an architecture prevents an authenticated user or process at a specific classification or trust-level from accessing information, processes, or devices in a different level. This provides a containment mechanism of users and processes, both known and unknown (an unknown program (for example) might comprise an untrusted application where the system should monitor and/or control accesses to devices and files).

Read more about this topic:  Mandatory Access Control

Famous quotes containing the words evaluation of, evaluation, system and/or strength:

    Good critical writing is measured by the perception and evaluation of the subject; bad critical writing by the necessity of maintaining the professional standing of the critic.
    Raymond Chandler (1888–1959)

    Good critical writing is measured by the perception and evaluation of the subject; bad critical writing by the necessity of maintaining the professional standing of the critic.
    Raymond Chandler (1888–1959)

    A religion so cheerless, a philosophy so sorrowful, could never have succeeded with the masses of mankind if presented only as a system of metaphysics. Buddhism owed its success to its catholic spirit and its beautiful morality.
    W. Winwood Reade (1838–1875)

    The most successful career must show a waste of strength that might have removed mountains, and the most unsuccessful is not that of the man who is taken unprepared, but of him who has prepared and is never taken. On a tragedy of that kind our national morality is duly silent.
    —E.M. (Edward Morgan)