DI-MCCR-81349
Security Features User's Guide
Informs users on how to make effective use of security features, providing the information needed to understand and effectively use the security protection mechanism(s) that secure processed or stored information.
Approval DateJuly 2, 1993
AMSC NumberG6939
Preparing Activity—
Project Number—
OPRG/C71
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form VersionAPR 89
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Description & Purpose
The Security Features User's Guide informs users on how to make effective use of security features. It provides the necessary information to understand and effectively use the security protection mechanism(s) that secure processed or stored information.
Application & Interrelationship
7.1 This Data Item Description (DID) contains the format and content preparation instructions for the data product generated under the work task described by 2.2.4.1 and 3.2.2.1.1 of DOD-5200.28 STD, Department of Defense Trusted Computer System Evaluation Criteria.
7.2 This DID is applicable to any computer acquisition that requires user documentation for the security features as specified by DOD-5200.28 STD, Department of Defense Trusted Computer System Evaluation Criteria, Classes C1 (Discretionary Security Protection), and above, products or their equivalent systems.
7.3 The information required by 10.3 and 10.4 is required for all class products and their equivalent systems applicable to the DID as a whole. In addition, the information required in 10.4.1 and 10.4.2 is necessary for various classes of products and their equivalent systems.
Preparation Instructions
10.1Source Document.The applicable issue of the documents cited herein, including their approval date, and dates of any applicable amendments and revisions shall be reflected in the contract.
10.2Format.Document the Security Features User's Guide as follows:
10.2.1Cover SheetShall contain Title, Contract Number, Procuring Activity, Contractor Identification, Acquisition Program Name, disclaimers (as provided by the procuring activity contracting officer), date, version number, security classification, and any other appropriate descriptive data.
10.2.2Errata Sheet.Shall contain sheets delimiting cumulative page changes from previous version(s).
10.2.3Table of Contents.Shall contain paragraph numbers, paragraph names, and page numbers.
10.2.4List of illustrations, diagrams, charts and figures.
10.2.5Glossary of abbreviations, acronyms, terms, symbols, and notation used, and their definitions.
10.2.6Executive Summary, not to exceed two pages, that briefly summarizes the Security Features User's Guide.
10.2.11Bibliography.List references and all applicable documents.
10.2.12Subjective index.An exhaustive index of the key word or theme in each paragraph shall be provided.
10.2.13Specific format instructions.
10.2.13.1Abbreviations and acronyms shall be defined when first used in the text and shall be placed in the glossary.
10.2.13.2Pages shall be numbered separately and consecutively using Arabic numerals.Blank pages shall be numbered.
10.2.13.3Paragraphs shall have a short descriptive title and shall be numbered consecutively using Arabic numerals.Numbering schemes beyond the fourth level (e.g., 4.1.2.5.8) are not permitted.
10.2.13.4Chapters shall begin on an odd-numbered (right-handed) page.
10.2.13.5Column headings shall be repeated on subsequent pages if tabular material exceeds one page.
10.2.13.6Fold out pages shall be kept to a minimum.
10.2.13.7Paper shall be standard 8 1/2 x 11 inches, white, with black type.The type font shall be standard 10 inch pica or courier, 12 pitch elite, or equivalent font. Either blocked text (left and right justified) or jagged right (left justified only) shall be used.
10.2.13.8At least one inch margins shall be provided all around to allow for drilling and binding.
10.2.13.9Either single- or double-sided printing shall be used.If double-sided, the document shall be printed or typed head-to-head, front-to-back.
10.2.13.10The guide shall be provided in standard three ring notebook binders for ease of maintenance.
10.3GeneralThe level of trust enforced by the Trusted Computing Base (TCB) shall determine the depth and size of the Security Features User's Guide (SFUG). This level determines the security functions needed. The SFUG shall describe the security functions used by operational users who are not specially trained as operators, security administrators, or system administrators.
10.4Content.The SFUG shall be prepared as follows:
10.4.1A description of the prominent features of each security protection mechanism(s) (e.g., I&A, DAC, MAC, and Object Manipulation Facilities) which pertain to the operational users shall be provided.
10.4.2A description of the interface between the security protection mechanism(s) and the operational user.It shall also describe the use of the security protection features by the operational users. The SFUG shall include cautions and precautions concerning the consistent and effective use of the described protection features.
10.4.3The SFUG shall address the relationships between the operators, system administrators, or security administrators, and the operational user (e.g., the security administrator may control user password generation features).Interface(s) necessary for the user to understand his or her use of each security protection mechanism shall be completely described in the SFUG.
10.4.4The SFUG shall include a description of expected reaction to security-related events (e.g., access violations, security-related failures).Every advisory or other response from each security protection mechanism(s) shall be documented, using the exact electronic text produced. Both affirmative and negative responses shall be illustrated by example dialogue (e.g., [User] Log-In Password Verified; [User] Access Denied; (User) Discretionary Permission Exceeded for File xxxx).
10.4.5Cross-references to relevant documentation containing a more detailed description of the security protection mechanism(s) and their relationships shall be provided, where applicable, in the SFUG.All cross-references shall be to the subparagraph level in the referenced document.
10.4.6Charts, figures, and caricatures should be used in the SFUG whenever possible to illustrate complex concepts, relationships, or interfaces to operational users not specially trained in security.
10.4.7Class B2 products and their equivalent systems.The procedures for the operational user to utilize the trusted communication path between the TCB and the user for initial login and authentication shall be explicitly defined in the SFUG. The SFUG shall describe how the communications via this path is initiated exclusively by the user.
10.4.8Class B3 and above products and their equivalent systems.The procedures for the operational user to utilize the trusted communication path between the TCB and the user for use when a positive TCB-to-user connection is required (e.g., login, change subject security level) shall be explicitly defined in the SFUG. The SFUG shall describe how the communications via this trusted path is activated exclusively by the user or the TCB. The SFUG shall describe how the trusted path is logically isolated and unmistakably distinguishable by the user from other paths.
Schema v3.0Community-maintained · Verify against ASSIST