These are not Cliff Notes

Quoting the Common Criteria (CC) introduction, as it explains the nature of assessment, "the project has tremendous fit with technology audit needs."

An evaluation is an assessment of an IT product or system against defined criteria.  A CC evaluation is one using the CC as the basis for evaluating the IT security properties.  Evaluations against a common standard facilitate comparability of evaluation outcomes.  In order to enhance comparability between evaluations results even further, evaluations should be performed within the framework of an authoritative evaluation scheme, which sets standards and monitors the quality of evaluations.  Such schemes currently exist in several nations[118].

Models used to compare security best practices are astoundingly comprehensive.  Unfortunately, I began by reading items pulled back by Google searches, which provided out of date (1999) text of CCV.1 and CCV.2, then finding out just today that CC had already released Version 3 of the Common Criteria and the Common Evaluation Methodology, CC V3.0.

As explained at the organization portal, “The Common Criteria (CC) was published as Version 2.1 in 1999.  Some updates were subsequently incorporated in version 2.2, which was published in 2004.  The CC and the associated evaluation methodology (CEM) are used by the nations involved in the Common Criteria Recognition Arrangement (CCRA) to gain assurance in products, protection profiles, etc. evaluated under the various schemes.”

As explained at the organization portal, “The Common Criteria (CC) was published as Version 2.1 in 1999.  Some updates were subsequently incorporated in version 2.2, which was published in 2004.  The CC and the associated evaluation methodology (CEM) are used by the nations involved in the Common Criteria Recognition Arrangement (CCRA) to gain assurance in products, protection profiles, etc. evaluated under the various schemes.”

The Common Criteria Project summary explaining the reason to update and change their standard is a model of why we continue to optimize all of our standards.  Taking some liberty, here is my summation of their points.

Cause for update to an existing release is to provide by new release:

  • Simplicity, Clarity and Consistency, (in all cases reducing length)
  • Rationalization and removal of duplication, (especially those created by other standards), Improved ease of use, (as in leveraging organizations dedicated to the training of professional such as the ISPI)
  • Provide for Additional support

Full text of the series is available under limited copyright.  I recommend reading the introduction and evaluation methodology.  Based in assessment needs, this may be useful, in particular for industries supporting or releasing security and IT control management products.

CC Part 1: Introduction and general model ccpart1 V3.0.pdf

CC Part 2: Security functional components ccpart2 V3.0.pdf

CC Part 3: Security assurance components ccpart3 V3.0.pdf

CEM: Evaluation Methodology cem V3.0.pdf

Any company needing product based security compliance certification, as means to advance in international markets, should own and adopt the Common Criteria standard released by ISO.

This is not the answer to my quest, but it offers a lot of insight in the process.  The Common Criteria, ISO/IEC 1528 standard provides a method that includes uniform comparisons, response to changes in current application and security conformance to best practice.  The approach aligns all known best inputs from literally dozens of organizations.

Here are two more snippets from the introduction.  I liked the simple idea that any standard might be aligned to a protection profile, so here is just one taste from the CC.

"Protection Profile (PP) A protection profile defines an implementation-independent set of security requirements and objectives for a category of products or systems which meet similar consumer needs for IT security.  A PP is intended to be usable and to define requirements which are known to be useful and effective in meeting the identified objectives.  The PP concept has been developed to support the definition of functional standards, and as an aid to formulating procurement specifications.  PPs have been developed for firewalls, relational databases, etc, and to enable backwards compatibility with TCSEC B1 and C2 ratings.

Security Target (ST)

A security target contains the IT security objectives and requirements of a specific identified TOE and defines the functional and assurance measures offered by that TOE to meet stated requirements.  The ST may claim conformance to one or more PPs, and forms the basis for an evaluation[119]."

Common Criteria for Information Technology Security Evaluation, Part 3: Security assurance components, 2005 release, I found a design model that offered some insight into a standard for all standards approach.  Classes of information used to evaluate products against their relative claim in providing technology controls are presented as class and family, across the following domains:

  • ACO: Composition
  • ADV: Development
  • AGD: Guidance documents
  • ALC: Life-cycle support
  • ASE: Security Target evaluation
  • ATE: Tests
  • AVA: Vulnerability assessment
Table 1: Assurance family breakdown and mapping

Assurance Class

Assurance Family

Composition

Composition Rationale

Development Evidence

Reliance of Dependent Component

Base TOE Testing

Composition Vulnerability Analysis

Development

Architecture Design

Functional Specification

Implementation Representation

TSF Internals

Security Policy Modeling

TOE Design

Guidance Document

Operational User Guidance

Preparative User Guidance

Life-Cycle Support

CM Capabilities

CM Scope

Delivery

Development Security

Flaw Remediation

Life-Cycle Definition

Tools and Techniques

Security Target Evaluation

Conformance Claims

Extended Components Definition

ST Introduction

Security Objectives

Security Requirements

Security Problem Definition

TOE Summary Specification

Tests

Coverage

Depth

Functional Test

Independent Testing

Vulnerability Assessment

Vulnerability Analysis

Main Menu