At which of the Orange Book evaluation levels is configuration management required?
Correct Answer: D
Explanation/Reference:
Explanation:
Configuration management consists of identifying, controlling, accounting for, and auditing all changes made to a particular system or equipment during its life cycle. In particular, as related to equipment used to process classified information, equipment can be identified in categories of COMSEC, TEMPEST, or as a Trusted Computer Base (TCB).
The Trusted Computer System Evaluation Criteria (TCSEC) requires all changes to the TCB for classes B2 through A1 be controlled by configuration management.
Incorrect Answers:
A: Configuration management is not required at level C1.
B: Configuration management is not required at level C2.
C: Configuration management is not required at level B1.
References:
http://surflibrary.org/ses/TEMPBOOK/CH6CONFGMGT.pdf