600.436 High-Assurance Systems
Fall 01/Operational Assurance
17
Vulnerability Assessment (AVA)
¨Goal of Vulnerability Assessment is to assess residual TOE security risks arising from
–intrinsic limitations of chosen security mechanisms
–misuse or misconfiguration of chosen security mechanisms
–flawed implementation of chosen security mechanisms
¨The four Families in the Class are:
–Covert Channel Analysis (AVA_CCA)
–Misuse (AVA_MSU)
–Strength of TOE Security Functions (AVA_SOF)
–Vulnerability Analysis (AVA_VLA)