SSCP · Question #1327
The Trusted Computer Security Evaluation Criteria book (TCSEC) defines two types of assurance. What are they? (Choose two)
The correct answer is A. Life cycle assurance E. Operational assurance. The Trusted Computer Security Evaluation Criteria (TCSEC) identifies two core types of assurance: life cycle assurance and operational assurance, which cover a system's development and runtime security respectively.
Question
The Trusted Computer Security Evaluation Criteria book (TCSEC) defines two types of assurance. What are they? (Choose two)
Options
- ALife cycle assurance
- BQuality assurance
- CSystem architecture assurance
- DOS hardening methods and assurance
- EOperational assurance
How the community answered
(37 responses)- A92% (34)
- B5% (2)
- D3% (1)
Why each option
The Trusted Computer Security Evaluation Criteria (TCSEC) identifies two core types of assurance: life cycle assurance and operational assurance, which cover a system's development and runtime security respectively.
Life cycle assurance focuses on the security measures and processes implemented throughout the entire development, maintenance, and retirement phases of a system.
Quality assurance is a broader management concept and not one of the two specific assurance types defined by TCSEC.
System architecture assurance is not a formally recognized assurance category within the TCSEC framework.
OS hardening methods and assurance describes a specific security practice, rather than an overarching assurance type in TCSEC.
Operational assurance pertains to the security mechanisms and features that are active and effective during a system's normal functioning and ongoing operations.
Concept tested: TCSEC assurance types
Topics
Community Discussion
No community discussion yet for this question.