From [the Security Enhanced Linux] page:
The traditional definition for a TrustedSystem comes from the [Orange Book], which is [available here]. (The CommonCriteria? is now the standard to judge trusted systems.)
Another definition is one of need, rather than capability. "A Trusted computer is one which can break the security model", says the [TCPA/Palladium FAQ]. The elements of a TrustedSystem are there to make it more difficult to break the security policy.