3-21.1 Flashcards
What is security evaluation?
Tto assess product functionality (security control exists and works) and assurance (degree of confidence it will act correctly/predictably) in a consistent and repeatable manner.
What is the Common Criteria?
Primary objective of the common criteria is to establish criteria for evaluating and certifying the security properties of hardware, software, and firmware. Independent labs used the Common Criteria to evaluate products as their protection profile.
What is a protection profile?
A protection profile defines sets of security requirements for specific types of products or systems. It can be written by several different groups, including vendors, customers, and accreditation agencies. Vendors can then claim compliance with the protection profile when their products meet the requirements.
What are Common Criteria EALs?
Evaluation Assurance Levels. (1-7).