Orange Book
The Orange Book contains the "Trusted Computer Systems Evaluation Criteria" (TCSEC), DOD Standard 5200.28.
Red Book (for networks)
The Red Book contains the "Trusted Network Interpretation of the Trusted Computer System Evaluation Criteria" (NCSC-TG-005) and "Trusted Network Interpretation Environments Guideline: Guidance for Applying the Trusted Network Interpretation" (NCSC-TG-011).
Level D
Systems are rated on a scale starting from D, which is not secure, to A, which is the most secure.
Level D is a non-secure system.
Level C
Level C provides discretionary access control (DAC). The owner of the data can determine who has access to it.
C1: Requires user login, but allows group ID.
C2: Requires individual user login with
password and an audit mechanism.
Levels B and A
Levels B and A provide mandatory access control (MAC). Access is based on standard DOD clearances. Each data structure contains a sensitivity level, such as top secret, secret and unclassified, and is available only to users with that level of clearance.
B1: DOD clearance levels.
B2: Guarantees path between user and the
security system. Provides assurances
that system can be tested and clearances
cannot be downgraded.
B3: System is characterized by a mathematical
model that must be viable.
A1: System is characterized by a mathematical
model that can be proven. Highest
security. Used in military computers.
European Ratings
The European Information Technology Security Evaluation Criteria (ITSEC) is similar to TCSEC, but rates functionality (F) and effectiveness (E) separately.
Orange
Book
TCSEC ITSEC
D E0
C1 F-C1, E1
C2 F-C2, E2
B1 F-B1, E3
B2 F-B2, E4
B3 F-B3, E5
A1 F-B3, E6
![]() | Reproduced with permission from Computer Desktop Encyclopedia. Copyright (c) 1981-2008 The Computer Language Company Inc. All rights reserved. |
Additional Resources
- Marcus Sachs on securing the homeland
- Prior to the Churchill Club event, "Masters of Cybercrime: The Ultimate Battle of Good and Evil," I spoke with Marcus Sachs, one of the nation's top cyberwarriors. He is currently a computer scientist at SRI International and under contract with the U.S. Department of Homeland Security DHS as deputy director...
- Blog posts 2005-06-02
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Demo: Virtualization with the Intel® Xeon® Processor
-
In this Flash demo, you'll learn about virtualization performance and features ideal for consolidation, load balancing, and disaster recovery with leading enterprise reliability.
- Watch how the Intel Xeon processor can increase performance and reliability of your servers >>










