Common Criteria (DC) is an international standard (ISO/CEI 15408) for the Information system security. The complete name of the standard is Common Criteria for Information Technology Security Evaluation . In French, one often employs the expression common Criteria .
The common criteria are available:
Access to documentation on the site of the DCSSI: Criteria and methology of evaluation
See summarized on the site of the DCSSI: References IF
See details on the site of DCSSI: Introdution and general model (version 2.1 on French, 76 pages)
See details on the site of DCSSI: Functional requirements of safety (vesion 2.1 on French, 394 pages)
There exist 11 headings:
See details on the site of the DCSSI: Requirements of insurance of safety (version 2.1 on French, 236 pages)
There exist 10 classes:
Evaluation of a profile of protection (class APE)
See details on the site of the DCSSI: Evaluation methodology (version 3.1 in English)
TOE : object to certify
SFR : functional specifications of safety
ST: target of safety
The operating systems (" Operating Systems")
Devices dedicated to the Communication S:
Systems devoted to the Computer security
See also: Evaluation Insurance Level
Certification proposes 7 levels of insurance of the evaluation.
It is the DCSSI which applies the diagram of French certification. This organization, attached to the Prime Minister, is in load of the certification of the products evaluated by CESTI.
In Europe, the Information Technology Security Evaluation Criteria (ITSEC) is a standard for the Sécurité of the Information systems, which are interested more particularly in the Security policy of the information systems.
The ITSEC is the product of common work several countries of the European Union, in 1991.
See: Information Technology Security Evaluation Criteria (ITSEC)
In the United States, the criteria of evaluation are defined by the National Security Agency (NSA), arranges Department of Defense, on the level of the Computer materials and software.
Organization of NSA in charge of the evaluation: NIAP
The company Miter is supplier of the Department of Defense on these questions.
See: http://www.mitre.org/news/the_edge/february_01/highlights.html
Third of confidence
Certification Common Criteria
| Random links: | Phylarque | Oryzomys | Holy-Sabine (Etchemins) | Killer vacuum | Karl Sigmund von Hohenwart |