2 cissp ® Official Study Guide Eighth Edition


Structure of the Common Criteria



Download 19,3 Mb.
Pdf ko'rish
bet288/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   284   285   286   287   288   289   290   291   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Structure of the Common Criteria
The CC guidelines are divided into three areas, as follows:
Part 1 
Introduction and General Model describes the general concepts and underlying model 
used to evaluate IT security and what’s involved in specifying targets of evaluation. It contains 
useful introductory and explanatory material for those unfamiliar with the workings of the 
security evaluation process or who need help reading and interpreting evaluation results.
Part 2 
Security Functional Requirements describes various functional requirements in 
terms of security audits, communications security, cryptographic support for security, user 
data protection, identification and authentication, security management, TOE security 
functions (TSFs), resource utilization, system access, and trusted paths. Covers the com-
plete range of security functions as envisioned in the CC evaluation process, with addi-
tional appendices (called 
annexes
) to explain each functional area.
Part 3 
Security Assurance covers assurance requirements for TOEs in the areas of 
configuration management, delivery and operation, development, guidance documents, and 
lifecycle support plus assurance tests and vulnerability assessments. Covers the complete 
range of security assurance checks and protects profiles as envisioned in the CC evaluation 
process, with information on evaluation assurance levels that describe how systems are 
designed, checked, and tested.
Most important of all, the information that appears in these various CC documents (worth 
at least a cursory read-through) are the evaluation assurance levels commonly referred as EALs. 
Table 8.3 summarizes EALs 1 through 7. For a complete description of EALs, consult the CC 
documents hosted at 
https://www.niap-ccevs.org/
 and view Part 3 of the latest revision.



Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   284   285   286   287   288   289   290   291   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish