词条 | Common Criteria Evaluation and Validation Scheme |
释义 |
Common Criteria Evaluation and Validation Scheme (CCEVS) is a United States Government program administered by the National Information Assurance Partnership (NIAP) to evaluate security functionality of an information technology with conformance to the Common Criteria international standard. The new standard uses Protection Profiles and the Common Criteria Standards to certify the product. This change happened in 2009. The change was implemented to bring credibility back to the CC brand. Their stated goal in making the change was to ensure achievable, repeatable and testable evaluations. ObjectivesThe CCEVS program is a partnership between the U.S. Government and industry to assist themselves and the consumers:
The scheme is intended to serve many communities of interest with very diverse roles and responsibilities. This community includes IT product developers, product vendors, value-added resellers, systems integrators, IT security researchers, acquisition/procurement authorities, consumers of IT products, auditors, and accreditors (individuals deciding the fitness for operation of those products within their respective organizations). Close cooperation between government and industry is paramount to the success of the scheme and the realization of its objectives.[1] Validation BodyThe Validation Body has the ultimate responsibility for the operation of the CCEVS in accordance with NIAP policies and procedures. Where appropriate it will interpret and amend those policies and procedures. The NIST and NSA are responsible for providing sufficient resources to the NIAP so that the Validation Body may carry out its responsibilities. However as of 2009 the NIAP has reached out to other vendors, labs, academia and customers to help in the evaluation of products therefore diminishing the reliance on the NSA. The Validation Body is led by a Director and Deputy Director selected by NIST and NSA management and other personnel include validators and technical experts in various technology areas. The Validation Body ensures that appropriate mechanisms are in place to protect the interests of all parties within the CCEVS participating in the process of IT security evaluation. Disputes brought forth by any participating party, i.e. the sponsor of an evaluation, product or Protection Profile developer or CCTL concerning the operation of the CCEVS or any of its associated activities shall be referred to the Validation Body for resolution. Once the product has been certified it is listed as PP Compliant in the NIAP Product Compliant List (PCL). External links
References1. ^{{Cite web|url=http://www.niap-ccevs.org/Big_Picture/objectives.cfm|title=NIAP: CCEVS Objectives|website=National Information Assurance Partnership|language=en|access-date=2017-11-07}} {{Commons category}} 5 : Computer security|Crime prevention|Data security|Information technology in the United States|National Security Agency |
随便看 |
|
开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。