CISSP Domain 3: Common Criteria Flashcards
1
Q
What does Common Criteria (CC) define?
A
various levels of testing and confirmation of system’s security capabilities
2
Q
What does the number of the level of CC define?
A
indicates what kind of testing and confirmation has been performed
3
Q
What are the objectives of the CC guidelines?
A
- add to buyers’ confidence in the security of evaluated, rated IT products
- eliminate duplicate evaluations (if one country follows CC, same evaluations don’t need to be performed elsewhere)
- to keep making security evaluations more cost-effective and efficient
- to make sure evaluation of IT products adhere to high and consistent standards
- to promote evaluation and increse availability of evaluated IT products
- evaluate the functionality and assurance of the target of evaluation
4
Q
Name each level and assurance level
A
- EAL 1, Functionality Tested
- EAL 2, Structually Tested
- EAL 3, Methodically Tested and Checked
- EAL 4, Methodically Designed, Tested, and Reviewed
- EAL 5, Semi-formally Designed and Tested
- EAL 6, Semi-formally Verified, Designed and Tested
- EAL 7, Formally Verified, Designed, and Tested