Which TCSEC (Orange Book) rating or level requires the system to clearly identify functions of the security administrator to perform security-related functions?
Correct Answer: D
Explanation/Reference:
Explanation:
The Security Administrator role is defined only at level B3 (and A1). It requires the system to clearly identify functions of security administrator to perform security-related functions.
Incorrect Answers:
A: Level C2 does not require the system to clearly identify functions of the security administrator to perform security-related functions.
B: Level B1 does not require the system to clearly identify functions of the security administrator to perform security-related functions.
C: Level B2 does not require the system to clearly identify functions of the security administrator to perform security-related functions.
References:
Krutz, Ronald L. and Russell Dean Vines, The CISSP Prep Guide: Mastering the CISSP and ISSEP Exams, 2nd Edition, Wiley Publishing, Indianapolis, 2004, p. 308