22.01.2015 Views

Military Communications and Information Technology: A Trusted ...

Military Communications and Information Technology: A Trusted ...

Military Communications and Information Technology: A Trusted ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

388 <strong>Military</strong> <strong>Communications</strong> <strong>and</strong> <strong>Information</strong> <strong>Technology</strong>...<br />

Policy Reasoning <strong>and</strong> Rules Analysis Service in order to make a decision about<br />

potential granting or denial of the access.<br />

2) <strong>Trusted</strong> Platform Services<br />

Several TOE services play a role in establishing the initial secure state for<br />

the TOE Security Functionality (TSF). After secure initialization, the TSF enforces<br />

the configured security policy. The non-TSF functions playing role in establishing<br />

the initial secure state of the TSF include <strong>Trusted</strong> Delivery, <strong>Trusted</strong> Load, <strong>Trusted</strong><br />

Initialization, <strong>and</strong> <strong>Trusted</strong> Configuration.<br />

3) Content Inspection <strong>and</strong> Policy Enforcement (CIPE)<br />

Content Inspection Policy Enforcement (CIPE) is a capability that enables<br />

the inspection of structured data that is to be mediated by the HAAG. The goal<br />

is to identify <strong>and</strong> remove malicious software (such as viruses, network worms<br />

<strong>and</strong> Trojan horses) <strong>and</strong> active content, combined with a verification of file format<br />

type <strong>and</strong> a white list of allowed file formats. The CIPE capability is to be provided<br />

as a component of the HAAG in order to improve the protection for confidentiality,<br />

integrity <strong>and</strong> availability of NATO CIS against malicious software <strong>and</strong> active<br />

content that may be imported from other information systems.<br />

Figure 8. Relationship between the Content Inspection Policy Enforcement <strong>and</strong> the HAAG PP<br />

The CIPE capability is provided by the CIPE Service which is one of the components<br />

of the <strong>Information</strong> Exchange Architecture. The CIPE Service consists<br />

of the following components, which are illustrated in Figure 8:<br />

• Content Inspection Policy Enforcement Framework (CIPEF)<br />

• Content Filters for supported data format content types<br />

• Content Filter Rules for each content filter

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!