CC:2022 is HERE!

It all started with Trusted Computer System Evaluation Criteria (TCSEC or Orange Book) in 1983; the German Security Evaluation Criteria (Green Book) in 1989; then The Information Technology Security Evaluation Criteria (ITSEC) from Europe, published in 1991 and the Canadian Trusted Computer Product Evaluation Criteria (CTCPEC) from Canada in 1993. In addition the US developed the Federal Criteria for information Technology Security in 1992, which introduced the concept of Protection Profiles (PP). All those were input for the development of the Common Criteria (CC) which started in 1993 also as an ISO standard (ISO/IEC 15408). The first version of this standard was published in 1999. After several versions and releases CC 3.1 R5 has been in place since 2017.

And now CC:2022 comes to us, courtesy of the global Common Criteria community. CC:2022 contains major changes so that it is truly a new version and not a refinement of the version 3 standard:

There are now 5 parts plus the CEM (Common Evaluation Methodology):

· Part 1: introduction and general model;

· Part 2: Security functional requirements;

· Part 3: Security assurance requirements;

· Part 4: Framework for the specification of evaluation methods and activities;

· Part 5: Pre-defined packages of security requirements and the

· CEM.

The new CC:2022 adds new SARs (Security Assurance Requirements) and instantiates Exact Conformance which was an addendum previously, thus endorsing the CPP approach. Modularization of the TOE is now also allowed. There are new functional requirements, provision for multi-assurance evaluations and the concept of composition of assurance is introduced with three levels, namely Layered composition, Network/bi-directional composition and Embedded composition. It also defines a framework for the development of evaluation methods and activities to guide the developer of Protection Profiles to tailor assurance activities to the special needs of the security functionality included in the PP.

The expiration date for new evaluations submitted under the CC 3.1 R5 is June 30, 2024.

atsec has prepared a handy overview to the new CC:2022.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值