Definition
¨ Demonstration that, for all adjacent
abstractions of representation, the less
abstract representation correctly refines the
more abstract representation
¨ Goal is to attain confidence that the least
abstract representation of the TSF is a
complete and correct realization of the ST
security functional requirements
600.436 High-
Assurance Systems
Fall 01/System Security Realization
48