Evaluation Methods, Certification and Accreditation Flashcards
Target Of Evaluation (TOE)
The product or system that is the subject
of the evaluation.
Protection Profile (PP)
– A document which identifies security requirements for a class of security devices. Products can comply with more than one PP. Customers looking for particular types of products can focus on those products certified against the PP that meet their requirements.
Security Target (ST)
The document that identifies the security properties of the target of evaluation. The ST may have one or more
PP’s.
Evaluation Assurance Level (EAL) – How did the system or product score on the testing?
EAL Level 1-7:
EAL1: Functionally Tested.
EAL2: Structurally Tested.
EAL3: Methodically Tested and Checked.
EAL4: Methodically Designed, Tested and Reviewed
EAL5: Semi-formally Designed and Tested.
EAL6: Semi-formally Verified Design and Tested.
EAL7: Formally Verified Design and Tested.