Navy IS Quality Assurance Controls
IS configuration management consists of identifying,
controlling,
accounting for, and auditing all changes made to a particular
system or equipment during its life cycle. The Navy IS Security
Manual states that:
-
- "While life-cycle assurance is concerned with
procedures for managing system design, development, and
maintenance; operational assurance focuses on features and system
architecture used to ensure that the security policy is
uncircumventably enforced during system operation. That is, the
security policy must be integrated into the hardware and software
protection features of the system."
- "Systems that are used to process or handle classified or
other
sensitive information must be designed to guarantee correct and
accurate interpretation of the security policy and must not
distort
the intent of that policy. Assurance must be provided that
correct
implementation and operation of the policy exists throughout the
system's life-cycle."