Trust and Assumptions
•Underlie all aspects of security
•Policies
–Unambiguously partition system states
–Correctly capture security requirements
•Mechanisms
–Assumed to enforce policy
–Support mechanisms work correctly
Assurance
•Specification
–Requirements analysis
–Statement of desired functionality
•Design
–How system will meet specification
•Implementation
–Programs/systems that carry out design