SECB451: Policy Criteria and Evaluation

Description:This course is organized around the following major themes: Assurance: overview of assurance, assurance versus trust, and functionality versus assurance. Evaluating Systems: goal of formal evaluation and historical perspective of evaluation methodologies, knowledge of the formal evaluation methodologies used for evaluating IT systems. Trusted Computer System Evaluation Criteria (TCSEC). Common Criteria: understanding the major processes, steps, activities, concepts, terminologies, and how the methodology is used throughout the life of the system, Functionality requirements, Assurance requirement, etc.
Credit Hours.:3
Text Book: Using the Common Criteria for IT security Evaluation, CRC Press., Dec 2002, by Debra S Herrmann. 1.
Coordinator: Ezedin Barka
Topics Outline:
  1. Course Introduction and Syllabus review.
  2. Introduction to Assurance
  3. Evaluating systems-Goals, decisions, and historical perspectives
  4. What are the Common Criteria?
  5. Specifying Security Requirements: The protection Profile
  6. Designing a Security Architecture: The Security Target
  7. Verifying a Security Solution: Security Assurance Activities
  8. CC case studies
  9. Group presentations and discussions
  1. Define the common criteria system evaluation concepts and terms.
  2. Describe security evaluations for IT systems
  3. Demonstrate the Common Criteria major processes
  4. Explain how the Common Criteria methodology is used throughout the life of the system.
  5. Demonstrate authentication technologies and systems
  6. Evaluate functional and assurance requirements and levels of trust provided by systems evaluation methodologies
Pre-requisiteITBP301: Security Principles and Practice
