Upcoming Events

Executive conference

Cloud Connect March 16-18

Comprehensive thought leadership for executives, IT professionals and developers. Topics include: the ROI, cost and economics of on-demand computing; Migration strategies to move from on-premise to cloud-based IT; Vertical cloud specialization, tailoring features and architectures to specific applications, industries, and customer ecosystems

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Security
W O R K S H O P  
Certification Security Blanket

  July 24, 2003
  By Mike Fratto


>> continued from previous page

CC Glossary

TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
Something in Common
arrow
CC Glossary
arrow
CC EALs
arrow
Sites to See

Certification Report: Summary of the Common Criteria testing results

EAL (Evaluation Assurance Level): A rating given to products that meet a minimum set of CC requirements defined for a specific level

PP (Protection Profile): This document defines the required security functions for a set of security needs. CC-certified PPs are evaluated just as thoroughly as STs and TOEs. You can define your own PP using the Common Criteria Part 2 document.

ST (Security Target): This document provides the environmental context and protection expectations that a TOE supports for an EAL. The ST is written by the vendor and reviewed by the CC evaluator. The ST helps you understand the vendor's claims of what the product features should do and how they should be used. It also gives you some context when you read the Certification Report.

TOE (Target of Evaluation): The product or subsystem being tested, such as a firewall or encryption processor. The TOE is described in the ST.


start top  Something in Common CC EALs 

Best of the Web

Data deduplication: Declawing the clones

Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.

Quick Read

Compression, Encryption, Deduplication, and Replication: Strange Bedfellows

One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.

Quick Read

WAN Optimization Whitelists and Blacklists

Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.

Quick Read

WAN Optimization as a Managed Service: It's Not About the Cost

This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.

Quick Read

  Sponsored Links

Premium Content

Data Centers Gone Wild
February 22, 2010

NWC


Salary

Video