PrepAway - Latest Free Exam Questions & Answers

This is termed as:

The owner of a system should have the confidence that the system will behave according to its specifications.
This is termed as:

PrepAway - Latest Free Exam Questions & Answers

A.
Integrity

B.
Accountability

C.
Assurance

D.
Availability

Explanation:
In a trusted system, all protection mechanisms work together to process sensitive data for many types of uses,
and will provide the necessary level of protection per classification level. Assurance looks at the same issues
but in more depth and detail. Systems that provide higher levels of assurance have been tested extensively and
have had their designs thoroughly inspected, their development stages reviewed, and their technical
specifications and test plans evaluated.
In the Trusted Computer System Evaluation Criteria (TCSEC), commonly known as the Orange Book, the lower
assurance level ratings look at a system’s protection mechanisms and testing results to produce an assurance
rating, but the higher assurance level ratings look more at the system design, specifications, development
procedures, supporting documentation, and testing results. The protection mechanisms in the higher assurance
level systems may not necessarily be much different from those in the lower assurance level systems, but the
way they were designed and built is under much more scrutiny. With this extra scrutiny comes higher levels of
assurance of the trust that can be put into a system.
Incorrect Answers:
A: Integrity ensures that data is unaltered. This is not what is described in the question.
B: Accountability is a security principle indicating that individuals must be identifiable and must be held
responsible for their actions. This is not what is described in the question.
D: Availability ensures reliability and timely access to data and resources to authorized individuals.

Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 390-391


Leave a Reply