|
|
|
| ::: |
|
InfoCom Security Technology Services Common Criteria Evaluation (ISO/IEC 15408) |
InfoCom Security Technology Services Common Criteria Evaluation (ISO/IEC 15408)
|
| Copyright © 2007 Telecom Technology Center. |
|
|
|
|
|
Common Criteria is an international standard for evaluation and certification of IT security products in accordance with EAL(Evaluation Assurance Level) to justify the level of product security. EAL is divided into 7 levels, from level 1 to level 7, providing applicant/sponsor, laboratory and certification body in conformity to international standard for security and functionality of IT security products.
Common Criteria specifies the security requirements to conform with the standards for evaluation and certification of IT security products. From product development prospective, the certification procedures cover the whole product life cycle, from design, production, and delivery to operation. The certification takes place at the certification body in accordance with EAL of security products provided by vendor to justify the level of product functions based on vendor's conformance claim.
|
|
| Evaluation Procedures |
 |
|
|
- Vendor (applicant) applies for evaluation to evaluation laboratory.
- Evaluation laboratory and the certification body confirm with the vendor regarding target of evaluation and security level.
- Vendor provides products and related documents to laboratory for evaluation. Evaluation Technical Report(ETR)will be produced by laboratory upon completion of evaluation.
- Certification body certifies the evaluation results and ETR.
- A Common Criteria Certificate will be issued by certification body if all reports concerning evaluation and certification have been confirmed for accuracy and consistency. .
|
| Scope of Evaluation |
 |
|
Smart card products and systems
- IC, operation system, application, card reader, etc.
Network security devices and systems
- Firewalls, wireless adaptors, wireless access points, trusted platform modules, public key infrastructure, virtual private network, intrusion detection system/intrusion protection system, etc.
Others
- Access control systems, digital signature systems, databases, and operating systems, etc.
|
|
| Benefits |
 |
|
-
To develop IT security products that conform to the international standard and promote products competitiveness.
-
To Increase the business opportunity for international market and promote company's brand image
-
To ensure security operation of every stages in product development life cycle.
-
Products certified as conforming to Common Criteria are accepted as priority procurement by the government agency or organization in procuring IT security equipments.
|
|