摘要
探讨了一种基于保障范围的CC安全保障要求类层次结构,并阐述了各层次下CC安全保障要求在软件工程活动中的确立方法。在此基础上,以一个面向CC EAL3评估级的安全数据采集系统的开发活动为背景,阐述了一种结合实际软件工程活动的、基于CC安全保障类的安全工程方法。
This paper presents a layered framework of CC security assurance requirements based on the assurance scope, and the concrete corresponding assurance methods integrated with the activities in software engineering. Based on this framework, this paper explains a security engineering method based on the CC security assurance requirements, by means of case study developing secure data acquisition system according to EAL3 in CC.
出处
《计算机应用研究》
CSCD
北大核心
2006年第10期137-139,143,共4页
Application Research of Computers
基金
西安市科技攻关计划资助项目(GG05023)
关键词
数据采集系统
安全工程
通用评估准则
Data Acquisition System(DAS)
Security Engineering
Common Criteria(CC)