login

Information Technology Security Evaluation Criteria (ITSEC) - a Contribution to Vulnerability?

Published 7 September 1992
Michael Gehrke, Andreas Pfitzmann, Kai Rannenberg
Citations15

TL;DR

Criticism focusses on the intended scope, the functionality aspects, the assessment of effectiveness and correctness, and problems arising after the evaluation of IT systems.

Abstract

On initiative of the Commission of the European Communities, the Information Technology Security Evaluation Criteria (ITSEC) are designed to provide a yardstick for the evaluation and certification of the security of IT systems. To improve the usefulness of resulting evaluations and certificates for procurers, users, and manufacturers the ITSEC are intended to undergo further extensive review. We discuss weaknesses, remaining questions, and possible improvements concerning the current version 1.2 of ITSEC. Our criticism focusses on the intended scope, the functionality aspects, the assessment of effectiveness and correctness, and problems arising after the evaluation of IT systems. Additionally, the ITSEC development and the accompanying discussion are criticized and improvements are proposed. Keyword Codes: K.7.3; K.6.5; D.4.6 Keywords: The Computing Profession, Certification, and Licensing; Management of Computing and Information Systems, Security and Protection; Operating Systems, ...

Keywords

Computer Science