Re: C2 security standards

From: Gian Fabio Palmerini (gianfabio.palmerini@epiclink.it)
Date: 05/22/02


From: Gian Fabio Palmerini <gianfabio.palmerini@epiclink.it>
To: Juan Ignacio Trentalance <TRENTALANCE@crm.com.ar>, "'focus-sun@securityfocus.com'" <focus-sun@securityfocus.com>
Date: Wed, 22 May 2002 09:47:09 +0200


Hi
also HP refers to C1 / C2 security standards after some questions to HP
security personnel working with me i discovereed they refer to Orange Book

here u can find a check list in accordance with that standard
http://www.dynamoo.com/orange/orangechart.htm

i personally think and i said this to HP that Orange Book is a too old
security model to refer with
i really think it is better to check with common criteria requirements

see ya

Gian Fabio Palmerini

-- 
Gian Fabio Palmerini

Security Specialist

EPICLink S.p.A.

Tel. +39 02 7030 621 FAX +39 0362 185 5160

http://www.epiclink.it E-mail: gianfabio.palmerini@epiclink.it



Relevant Pages

  • Re: Chrome processes vs. threads
    ... I would refer to early days as after the release of a 1.0. ... so now somehow Google produced Windows did they? ... versions of windows prior to XP SP2, ... but the basic architecture of Windoze was totally without security ...
    (uk.comp.sys.mac)
  • RE: [Full-Disclosure] Antigen Path Disclosure
    ... me unrelated to the aspects of security... ... The .jpg you refer ... Do you Yahoo!? ... Calendar - Free online calendar with sync to Outlook. ...
    (Full-Disclosure)
  • RE: Enabling HTTP Post to invoke web services
    ... it is recommended to disable httpget and httppost for security issues. ... You may refer to this article for details: ... Soap Toolkit can work with windows authenticated ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: variable length strings
    ... >> Unauthorized access is just a tiny part of Confidentiality. ... I believe it is "Trusted Computer Security ... But I did not promise those exact words are in the Orange Book, ...
    (comp.lang.ada)
  • Re: Comparison of operating systems on wikipedia - Security
    ... The Orange book was rendered obsolete by the Common Criteria ca. 1995. ... OpenVMS is in fact used in the ... I have also read discussions indicating that the security ... > certification status: ...
    (comp.os.vms)