Outline for December 1, 2005
Reading: Kenneth Olthoff, "Sysadmin Admonishments" (2002).
-
Assurance
-
Trustworthy entities
-
Security assurance
-
Trusted system
-
Why assurance is needed
-
Requirements
-
Assurance and software life cycle
-
Life cycle: Waterfall Model
-
Requirements definition and analysis
-
System and software design (system design, program design)
-
Implementation and unit testing
-
Integration and system testing
-
Operation and maintenance
-
Evaluation Criteria
-
Trusted Computer System Evaluation Criteria (Orange Book)
-
Common Criteria
-
Best practices
-
Example of Best Practices
-
CIS FreeBSD Benchmark
-
Environment and assumptions
Here is a PDF version of this document.