1、1 CC CC CISSP CC CC CC CC CC CC CEM CEM 2 3 1 1 ISO ISO/IDC JTC1/SC27 I S O / T C 6 8 IEC ISO JTC1 ITU CCITT ISO X.400 X.500 Internet IETF I E T F Internet “ ”RFC“ 2 2 ECMA ISO ANSI 80 FIPS F I P S NIST FIPS NIST DES IEEE IEEE LAN/WAN SILS P1363 DODDI DOD 5200.28-STD 4 GB9387-2 ISO7498-2 GB17859 IS
2、O7498-2 GB/T9387-2,1995 1 9 8 9 ISO 2 CC ISO15408 GB/T18336,2001 1993 6 CC SSE-CMM ISO/IEC DIS 21827 NSA 1993 IATF N S A Information Assurance Technical Framework BS7799 Part1 ISO17799 B S I ISMS ISO/IEC TR 13335 IT GMITS 5 5 Trusted Computer System Evaluation Criteria TCSEC “ ” U.S. Department of D
3、efense 5200.28-STD 1985 Trusted Network Interpretation TNI “ ” 1987 Information Technology Security Evaluation Criteria ITSEC 1991 Canadian Trusted Computer Product Evaluation Criteria CTCPEC 1993 Federal Criteria FC 1993 Common Criteria CC Version 2 (Finalized 1998), ISO 15408 TCSEC TCSEC 1985 Trus
4、ted Computing Base TCB 4 4 7 D C1 C2 B1 B2 B3 A TCSEC B Bell & LaPadula NCSC 1987 6 TCSEC TCSEC D Minimal Protection DOS Windows3x Windows9x C Discretionary Access Policy Enforced C1 C2 C1 C2 Unix WindowsNT Novell3.x B Mandatory Access Policy Enforced B1 B2 TCB DAC MAC B3 TCB A Formally Proven Secur
5、ity A1 GB 17859 GB 17859- -1999 1999 TCSEC D A1 5 TCB T C B TCB TCB 7 ITSEC ITSEC 1991 ITSEC “ ” “ ” AC ITSEC Functionality F1 F10 F1 F5 C1 B3 European Assurance E0 E6 ITSEC ST ITSEC ITSEC CC CC CC CC CC CC CEM CEM 8 CC CC CC CC CC CC 1985 TCSEC 1991 ITSEC 1993 CTCPEC 1993 FC 1996 CC v1.0 1998 CC v2
6、.0 1999 CC ISO/IEC 15408 CC GB/T 18336 2001 9 CC CC IT CC ISO 15408 IT CC CC CC CC CIA CC 10 CC CC CC PP CEM CC CC CC Part 3 Assurance Classes Assurance Families Assurance Components Part 3 Assurance Classes Assurance Families Assurance Components Part 2 Functional Classes Functional Families Functi
7、onal Components Part 2 Functional Classes Functional Families Functional Components Part 1 I T PP ST Part 1 I T PP ST CC 11 CC CC CC CC CC CC CEM CEM 12 CC CC Functional Requirements Functional Requirements IT : Assurance Requirements Assurance Requirements : CC CC 1 1 Target of Evaluation TOE Prote
8、ction Profile PP Security Target ST S T TOE TOE S T TOE PP S T TOE S T ITSEC “ ” ST for Oracle v713 CC CC 2 2 TOE Security Policy TSP TOE TOE Security Functions TSF TSP TOE Component PP ST CC “ _ . ” Package PP ST C C Class Class Family Family Family Family PP/ST/ PP/ST/ TSP TOE Security Policy TSP TOE Security Policy SFP Security Function Policies SFP S