A system must satisfy srict assurance requirements for successful evaluation at the B3 class of the Trusted Computer System Evaluation Criteria (TCSEC). Many of these requirements are essentially requirements on process or on documentation. Unlike many other areas, TCSEC requirements are a job of selling to an uncertain buyer: TCSEC evaluation is a matter of convincing a responsible team of evaluators that the system can be trusted to manage sensitive data in an appropriate fashion.
Click Here to download this article