600.436 High-Assurance Systems
Fall 01/System Security Realization
48
Definition
¨Demonstration that, for all adjacent abstractions of representation, the less abstract representation correctly refines the more abstract representation ¨Goal is to attain confidence that the least abstract representation of the TSF is a complete and correct realization of the ST security functional requirements