Data Protection and Security

   

VI

Operating System Security and Secure Programming

   

VI.III

Security Evaluation

   

   
 

Common Criteria:

Starting in late 90’s, the Common Criteria merges ideas from its various predecessors. The ultimate goal is an internationally set of criteria in the form of an ISO standard. It separates functional and security requirements from the intensity of required testing. Evaluation assurance levels from 1 to 7.

  • EAL1: Tester reads documentation and performs some tests to confirm documented functionality.
  • EAL7: Developer provides formal functional specification and high-level design, security functions must be simple enough for formal analysis.
   

   
       
 
«previous session [1] [2] [3] [4] [5] [6] [7] [8] [9] next session »
   
       
 
«proceed to previous sectionproceed to next section »
  chapter index