Common Criteria (CC) for Information Technology Security Evaluation

Part of the TechTarget Network of Enterprise IT Web Sites

Search our IT-specific encyclopedia for:
 
Browse alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #
All Categories Government IT

Common Criteria (CC) for Information Technology Security Evaluation

Common Criteria (CC) is an international set of guidelines and specifications developed for evaluating information security products, specifically to ensure they meet an agreed-upon security standard for government deployments. Common Criteria is more formally called "Common Criteria for Information Technology Security Evaluation." 

Common Criteria has two key components: Protection Profiles and Evaluation Assurance Levels. A Protection Profile (PPro) defines a standard set of security requirements for a specific type of product, such as a firewall. The Evaluation Assurance Level  (EAL) defines how thoroughly the product is tested.  Evaluation Assurance Levels are scaled from 1-7,  with one being the lowest-level evaluation and seven being the highest-level of evaluation. A higher-level evaluation does not mean the product has a higher level of security, only that the product went through more tests. 

To submit a product for evaluation, the vendor must first complete a Security Target (ST) description, which includes an overview of the product and product's security features, an evaluation of potential security threats and the vendor's self-assessment detailing how the product conforms to the relevant Protection Profile at the Evaluation Assurance Level the vendor chooses to test against. The laboratory then tests the product to verify the product's security features and evaluates how well it meets the specifications defined in the Protection Profile. The results of a successful evaluation form the basis for an official certification of the product. The goal of CC certification is to assure customers that the products they are buying have been evaluated and that the vendor's claims have been verified by a vendor-neutral third party. 

 

Learn more:

The Common Criteria Portal makes the guidelines and specifications available for downloading

The Trusted Computer System Evaluation Criteria was superseded by the Common Criteria for Information Technology Security Evaluation in 2005.

Last updated on: Mar 22, 2011
Editorial Director: Margaret Rouse

>  Enterprise Software related Research & News
>  White Papers for the Retail Industry

Are you a Know-IT-All?
This is the certification of a product or specification to indicate that it meets regulatory standards.
a. homologation
b. collocation

word of the day Sign up for the Word of the Day
twitter Follow us on Twitter
Editorial director:


WORD OF THE DAY...
data center infrastructure management (DCIM)
LEARN MORE ABOUT...
Windows 8
AccessChk
AccessEnum
Microsoft Windows Server 2008
Windows Server 2008 R2
icacls
mechanical refrigeration
mobile middleware
PCI DSS 2.0
PCI DSS User Group
Raspberry Pi ($35 computer)
HTML 5 client
persistent desktop
nonpersistent desktop
Microsoft System Center Virtual Machine Manager 2012
RemoteFX
Windows Thin PC
polyfill
computer room air handler (CRAH
arc flash
electric arc
WhatIs.com RSS Feeds
About Us   |   Contact Us   |   For Advertisers   |   For Business Partners   |   Reprints   |   RSS   |   Awards
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts