Skip to content

DN-Systems

Sections
Personal tools
You are here: Home » Policy » Common Criteria » Common Criteria » Common Criteria » Common Criteria

Common Criteria

“Common Criteria for Information Technology Security Evaluation (CC), Version 2.0" have been released in its final version end of May 1998 with contributions by Germany, France, Great Britain, Canada, the Netherlands and the US.

These common criteria are applicable to evaluating the security features of practically any information technology product or system.

In Germany, the CC are represented by the Bundesamt für Sicherheit in der Informationstechnik (BSI)

CC 2.1 has been standardized by the International Organization for Standardization (ISO) as ISO 15408.

The few non-technical changes introduced by the ISO standardization process have been incorporated into the CC in its version 2.1.

Contents:

Part 1: Introduction and generic Model

Definition of the basics of IT security evaluation and scope of the CC. The appendices detail protection profiles and security targets for the evaluation.

Part 2: Functional Security Requirements

This part contains an elaborate catalogue of functional requirements. The catalogue is meant as a recommendation for how to describe a product’s or system’s functionality but in any given case it might be more appropriate to choose a different approach and diverge from the catalogue. The appendix covers background information and the connection between threats, security targets and functional requirements.

Part 3: Evaluation Assurance

This part lists requirements regarding trustworthiness. It is crucial that every evaluation result is based on a certain level of trust possibly amended by further requirements. The CC defines seven evaluation assurance levels:
  • EAL1 - functionally tested
  • EAL2 - structurally tested
  • EAL3 - methodically tested and checked
  • EAL4 - methodically designed, tested, and reviewed
  • EAL5 - semiformally designed and tested
  • EAL6 - semiformally verified design and tested
  • EAL7 - formally verified design and tested

References:

Common portal for all countries contributing to the CC
National Institute of Standards and Technology CC Publications
Created by lukas
Last modified 2005-10-09 08:01 PM
« November 2008 »
Su Mo Tu We Th Fr Sa
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30            
 
 

Powered by Plone

This site conforms to the following standards: