DI-MISC-81348
Philosophy of Protection Report
The Philosophy of Protection Report provides an informal description of a security policy and the overall high-level design of a Trusted Computing Base, detailing each protection mechanism used to enforce that policy.
Approval DateJuly 2, 1993
AMSC NumberG6938
Preparing Activity—
Project Number—
OPRG/C71
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form VersionAPR 89
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Description & Purpose
This report details an informal description of a security policy and the overall high level design of a Trusted Computing Base (TCB) delineating each of the protection mechanisms (both TCB and non-TCB) employed to enforce the policy.
Application & Interrelationship
This Data Item Description (DID) contains the format and content preparation instructions for the data product generated under the work task described by 2.1.4.4 of DOD-5200.28 STD, Department of Defense Trusted Computer System Evaluation Criteria.
This DID is applicable to any computer acquisition that calls for a Philosophy of Protection Report as specified by DOD-5200.28 STD, Department of Defense Trusted Computer System Evaluation Criteria for a TCB Class C1 (Discretionary Security Protection), or above, products or their equivalent systems. The Philosophy of Protection Report is based on the security policy enforced by the TCB derived from U.S. Government laws, regulations, standards, and practices.
Preparation Instructions
10.1Source Document.The applicable issue of the documents cited herein, including their approval date, and dates of any applicable amendments and revisions shall be reflected in the contract.
10.2Format.Document the Philosophy of Protection Report as follows:
10.2.1Cover Sheet.Shall contain Title, Contract Number, Procuring Activity, Contractor Identification, Acquisition Program Name, disclaimers (as provided by the procuring activity contracting officer), date, version, number, security classification, and any other appropriate descriptive data.
10.2.2Errata Sheet.Shall contain sheets delimiting cumulative page changes from previous versions.
10.2.3Table of Contents.Shall contain paragraph numbers, paragraph names, and page numbers.
10.2.4List of illustrations, diagrams, charts, and figures.
10.2.5Glossary of abbreviations, acronyms, terms, symbols, and notation used, and their definitions.
10.2.6Executive Summary.Not to exceed two pages, that briefly describes the TCB's security-related capabilities.
10.2.8Body of the Report.
10.2.11Bibliography.List reference sources and applicable documents.
10.2.13Specific format instructions.
10.2.13.1Abbreviations and acronyms shall be definedAbbreviations and acronyms shall be defined when first used in the text and shall be placed in the glossary.
10.2.13.2Pages shall be numbered separately and consecutivelyPages shall be numbered separately and consecutively using Arabic numerals. Blank pages shall be numbered.
10.2.13.3Paragraphs shall have a short descriptive titleParagraphs shall have a short descriptive title and shall be numbered consecutively using Arabic numerals. Numbering schemes beyond the fourth level (e.g., 4.1.2.5.8) are not permitted.
10.2.13.4Chapters shall begin on an odd-numbered (right hand) page.
10.2.13.5Column headings shall be repeated on subsequent pages if tabular material exceeds one page.
10.2.13.6Fold out pages shall be kept to a minimum.
10.2.13.7Paper shall be standard 8 1/2 x 11 inches, white, with black type.The type font shall be standard 10 pitch pica or courier, 12 pitch elite, or equivalent font. Either blocked text (left and right justified) or ragged right (left justified only) shall be used.
10.2.13.8At least one inch margins shall be providedAt least one inch margins shall be provided all around to allow for drilling and binding.
10.2.13.9Either single- or double-sided printing shall be used.If double-sided, the document shall be printed or typed head-to-head, front-to-back.
10.2.13.10The report shall be provided in standard three-ring notebook bindersThe report shall be provided in standard three-ring notebook binders for ease of maintenance.
10.3Content.The following shall be included in the Philosophy of Protection Report:
10.3.1The Philosophy of Protection Report shall provide a description of the explicit and well-defined security policyThe Philosophy of Protection Report shall provide a description of the explicit and well-defined security policy enforced by the TCB and the environment, as appropriate. The discussion shall include the applicable laws, rules, and regulations. This description shall be in enough detail to form the background for the philosophy of protection discussions.
10.3.2The Philosophy of Protection Report shall describe the high-level TCB protection mechanisms derived from the policy.It shall describe the philosophy of protection for the TCB. This encompasses the enumeration of any assumptions and constraints, with the rationale and justification for using each. These assumptions and constraints may be applicable for justifying distribution of the security requirements through the TCB.
10.3.3The Philosophy of Protection Report shall describe the environmental mechanisms supporting the policy.It shall provide an explanation of how the security policy is translated into environmental constraints, connectivity constraints, and the specific TCB protection mechanism(s). This discussion shall include any entity that enforces the security policy, either external or internal to the computer itself (e.g., physical access control, TCB access control).
10.3.4The Philosophy of Protection Report shall describe the TCB mechanisms supporting the policy.It shall show how the philosophy of protection is translated into the TCB hardware, software, and firmware; as appropriate. The Philosophy of Protection Report shall relate the security requirements to the architecture.
Schema v3.0Community-maintained · Verify against ASSIST