Outline for May 22, 2013
Reading
: §18, 19
Due
: Homework #4, due May 24, 2013
Assurance
Assurance and software life cycle
Basics
Threats
Reference monitor, validation mechanism
Design security in or layer it on?
Policy and requirements
Security specifications
Problems with precision
Example: System X and Bell-LaPadula
Justifying requirements
Techniques to support design assurance
Subsystem, subcomponent, module
Design documents
Security functions summary specification
External functional specification
Internal design description
Justifying design meets requirements
You can also obtain a PDF version of this.
Version of May 21, 2013 at 10:39PM