Security Case and Design Good Practice

Framework Core Functions
Identify - Protect - Detect - Respond - Recover
Framework Implementation Tiers
1 - Partial 2 - Risk Informed 3 - Repeatable 4 - Adaptive
Control Set of TL0
Control Set of TL1
TS Essentials
Control Set of TL2
Baseline TS Controls
Control Set of TL3
TS Framework
Control Set of TL4
Comprehensive TS Controls
Trustworthiness Facets
Safety Reliability Availability Resilience Security
TS Essentials (Subset Of TS Framework)
Scope for Use Coding Practices Use Tools Effectively Defect Management Artifact Management
Common Criteria
The International Standard for computer security verification. Standardised as ISO 15408. It is the framework in which the security claims about a product can be independently verified.
Target of Evaluation (TOE)
System or Product that is the subject of evaluation
Protection Profile
A document identifying security requirements relevant to those users.
Security Target
Document Identifying security properties of TOE
Security Functional Requirements (SFRs)
Individual security functions provided by a product
Security Assurance Requirements (SARs)
Descriptions of the measures taken during development and evaluation of the product to assure compliance with the claimed security functionality.
Evaluation Assurance Level (EAL)
Numerical rating describing the depth and rigor of an evaluation
