DI-MISC-81341
Informal Security Policy Model
Provides format and content instructions for an Informal Security Policy Model documenting the abstract representation of a trusted computing base (TCB) and the security policy it enforces.
Approval DateJuly 2, 1993
AMSC NumberG6931
Preparing Activity—
Project Number—
OPRG/C71
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form VersionAPR 89
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Description & Purpose
An informal security policy model provides an abstract representation of a trusted computing base (TCB) and the security policy enforced by the TCB.
Application & Interrelationship
This Data Item Description (DID) contains the format and content preparation instructions for the data product generated under the work task described by 3.1.4.4 and 3.1.3.2.2 of DOD-5200.28 STD, Department of Defense Trusted Computer System Evaluation Criteria. This DID is applicable to any computer acquisition that calls for an informal security policy model as specified by DoD 5200.28-STD Department of Defense Trusted Computer System Evaluation Criteria (TCSEC) for TCB Class B1 (Labeled Security Protection) products or their equivalent systems. The TCSEC Class B1 requirement is for either an Informal Security Policy Model or a Formal Security Policy Model. If a Formal Security Policy Model is required and is available, then the Informal Security Policy Model is redundant and not necessary. Then Informal Security Model is based upon the Philosophy of Protection Report.
Preparation Instructions
10.1Source Document.The applicable issue of the documents cited herein, including their approval date, and dates of any applicable amendments and revisions shall be reflected in the contract.
10.2Format.Document an Informal Security Policy Model as follows:
10.2.1Cover Sheet.Shall contain Title, Contract Number, Procuring Activity, Contractor Identification, Acquisition Program Name, disclaimers (as provided by the procuring activity contracting officer), date, version number, and any other appropriate descriptive data.
10.2.2Errata Sheet.Shall contain cumulative page changes from previous versions.
10.2.3Table of Contents.Shall contain paragraph numbers, paragraph names, and page numbers.
10.2.4List of illustrations, diagrams, charts, and figures.
10.2.5Glossary of abbreviations, acronyms, terms, symbols, and notation used, and their definitions.
10.2.6Executive Summary,not to exceed two pages, that briefly describes the security model, including its assumptions and limitations.
10.2.8Body of the Report.
10.2.9.1Subjective index.
10.2.11Bibliography.List of reference sources and applicable documents.
10.2.12Specific format instructions
10.2.12.1Abbreviations and acronyms shall be defined when first used in the text and shall be placed in the glossary.
10.2.12.2Pages shall be numbered separately and consecutively using Arabic numerals.Blank pages shall be numbered.
10.2.12.3Paragraphs shall have a short descriptive title and shall be numbered consecutively using Arabic numerals.Numbering schemes beyond the fourth level (e.g., 4.1.2.5.8) are not permitted.
10.2.12.4Chapters shall begin on an odd-numbered (right hand) page.
10.2.12.5Column headings shall be repeated on subsequent pages if tabular material exceeds one page.
10.2.12.6Fold out pages shall be kept to a minimum.
10.2.12.7Paper shall be standard 8 1/2 x 11 inches, white, with black type.The type font shall be standard 10 pitch pica or courier, 12 pitch elite, or equivalent font. Either blocked text (left and right justified) or ragged right (left justified only) shall be used.
10.2.12.8At least one inch margins shall be provided all around each page to allow for drilling and binding.
10.2.12.9Either single- or double-sided printing shall be used.If double-sided, the document shall be printed or typed head-to-head, front-to-back.
10.2.12.10The report shall be provided in standard three-ring notebook binders for ease of maintenance.
10.3Content.The Informal Security Policy Model document shall contain the informal security policy model, its associated convincing assurance arguments, and supporting explanations and documentation for both the model and assurance arguments. The model consists of two segments: 1) an informal description of the policy which is to be enforced by the TCB, and 2) an informal description of the abstract protection mechanism(s) within the TCB which enforce the described policy. The model shall include the representation of subjects objects, modes of access, and security labels; the set of security properties enforced by the TCB; the representation of the initial state of the TCB; and the representations of the operations performed.
10.3.1General.The Informal Security Policy Model document shall provide background information supporting the modeling effort. All of this background information is informal in nature and may be presented in English text, and graphic representations where appropriate. The following information shall be included as part of this information:
10.3.1.1Summarization of the security policy to be modeled, how this policy relates to the overall security policy (if the policy modeled is some subset of the overall policy), and the source of the policy.This discussion shall be in enough detail to form the background for the model.
10.3.1.2Discussion of the model chosen, and the rationale for why this model was chosen.
10.3.1.3Discussion of the modeling technique/methodology chosen, and the rationale for why this technique/methodology was selected over other possible techniques.
10.3.1.4Expansion of the security policy into security policy statements.These security policy statements may be brief, but they must explicitly and thoroughly describe the security policy. Each policy statement shall be mapped to the Philosophy of Protection Report.
10.3.1.5Introduction to the kinds of assurance arguments that are provided, along with a rationale that explains why these arguments are sufficient to demonstrate that the TCB is secure with respect to the security properties modeled.
10.3.2Policy segment.The Informal Security Policy Model document shall provide an informally stated mathematical description of the policy enforced by the TCB. Also, an English language description of the policy model and each of its segments shall be provided. Supporting material shall be provided in the following sequence:
10.3.2.1All assumptions used in the model, using an English language description.The Informal Security Policy Model document shall state the assumptions derived from the Philosophy of Protection Report, and explain why the assumptions are necessary to the model. It shall also explain why all identified assumptions are required, and the consequences of violating the assumptions.
10.3.2.2All axioms used in the model, using an English language description.The Informal Security Policy Model document shall provide supporting rationale for including each axiom.
10.3.2.3The actual model of the policy.Graphic representations of the model's segments may be included (e.g., diagrams and tables). These graphics shall be annotated with brief English language descriptions. Supporting material shall be provided to describe each of the following:
10.3.2.3.1The classes of subjects and objects controlled by the TCB.Examples of subjects are people, processes, or devices; and objects are records, blocks, pages, components, files, directories, directory trees, and programs, as well as bits, bytes, words, fields, processors, video displays, keyboards, clocks, printers, network nodes, etc.
10.3.2.3.2How subjects are related to users.
10.3.2.3.3How subjects are assigned privileged conditions (trusted subjects).
10.3.2.3.4How users identify themselves to the TCB.
10.3.2.3.5How the TCB records events.
10.3.3Abstract mechanisms segment.The Informal Security Policy Model document shall describe the abstract TCB protection mechanism(s). The following supporting material shall be provided:
10.3.3.1The actual model of the abstract TCB protection mechanism(s).Graphic representations of the model's segments may be included (e.g., diagrams and tables). These graphics shall be augmented with brief English language descriptions. The model shall include the following abstract mechanism(s), for example:
10.3.3.1.1All the rules which permit, as well as constrain, how a subject is allowed access to an object.
10.3.3.1.2All privileged conditions under which certain kinds of subjects are allowed to bypass the identified mandatory and discretionary access control rules.
10.3.3.1.3All controls on assigning subjects privileged conditions.
10.3.3.1.4All the controls on identifying users to the TCB.
10.3.3.1.5All the rules that generate an audit event.
10.3.3.2The explanation of how the abstract protection mechanism(s) satisfy the security policy model.Each mechanism shall be discussed separately. The explanation shall include a description of how each element within a mechanism supports other elements of the mechanism.
10.3.4Segment integration.The integration of the policy and abstract protection mechanism segments of the model shall provide the assurance arguments of the Informal Security Policy Model document. It shall include the following:
10.3.4.1An explanation to show that the model is consistent with its axioms.The explanation shall provide rationale sufficient to demonstrate consistency.
10.3.4.2A description of the relationship of each axiom to the model's segments and specific security-enforcement abstract mechanism(s) in the model.
10.3.4.3An explanation which shows that the TCB is sufficient to enforce the security policy.The explanation shall provide rationale sufficient to demonstrate consistency.
Schema v3.0Community-maintained · Verify against ASSIST