Common Criteria Ravi Sandhu.

Slides:



Advertisements
Similar presentations
Supporting further and higher education Quality Planning Richard McKenna JISC.
Advertisements

NRL Security Architecture: A Web Services-Based Solution
Sony Smart Cards and International Evaluation 2 nd Common Criteria Conference London, UK July 2001 i-Card System Solutions Division Broadband Network.
Computer Science CSC 474Dr. Peng Ning1 CSC 474 Information Systems Security Topic 5.2: Evaluation of Secure Information Systems.
Main issues: • Why is reuse so difficult • How to realize reuse
PKE PP Mike Henry Jean Petty Entrust CygnaCom Santosh Chokhani.
1 Common Criteria Ravi Sandhu. 2 Common Criteria International unification CC v2.1 is ISO Flexibility Separation of Functional requirements Assurance.
The Common Criteria for Information Technology Security Evaluation
IT Security Evaluation By Sandeep Joshi
The Common Criteria Cs5493(7493). CC: Background The need for independently evaluated IT security products and systems led to the TCSEC Rainbow series.
Midwest Real Estate Data LLC
Lesson 1-3 Example Example 2 A drawer of socks contains 6 pairs of white socks, 6 pairs of blue socks, and 3 pairs of black socks. What is the probability.
Business Case Exercise May 1, Evaluate an idea Divide into groups responsible for considering: – The availability and size of the market – The likely.
Chapter 9 Testing the System, part 2. Testing  Unit testing White (glass) box Code walkthroughs and inspections  Integration testing Bottom-up Top-down.
1 Plenary Panel on Cloud Security and Privacy: What is new and What needs to be done? Ravi Sandhu Executive Director and Endowed Professor December 2010.
Evaluation Arguments X Is (Is Not) a Good Y. Overview n Criteria-Match Structure n Problem of Standards.
Updates on Korean Scheme IT Security Certification Center, National Intelligence Service The 8 th ICCC in Rome, Italy.
1 Omissions and errors in the CC Who got it right? 8ICCC Denise Cater.
1 Common Criteria Ravi Sandhu Edited by Duminda Wijesekera.
Borders Business Programme IT and Marketing Functions of Web-based Systems Russell Taylor Lecturer in Computing Borders Business Programme.
The Value of Common Criteria Evaluations Stuart Katzke, Ph.D. Senior Research Scientist National Institute of Standards & Technology 100 Bureau Drive;
Common Criteria V3 Overview Presented to P2600 October Brian Smithson.
CMSC : Common Criteria for Computer/IT Systems
1 Cloud Computing and Security Prof. Ravi Sandhu Executive Director and Endowed Chair April 19, © Ravi Sandhu.
What is Testing? Testing is the process of exercising or evaluating a system or system component by manual or automated means to verify that it satisfies.
TM8104 IT Security EvaluationAutumn CC – Common Criteria (for IT Security Evaluation) The CC permits comparability between the results of independent.
Security consulting What about the ITSEC?. security consulting What about the ITSEC? Where it came from Where it is going How it relates to CC and other.
1 Using Common Criteria Protection Profiles. 2 o A statement of user need –What the user wants to accomplish –A primary audience: mission/business owner.
HOLE 1 – Par 4 TEE BOXBlack - 400M Blue - 385M White - 350M Red - 310M.
Software Testing and Quality Assurance 1. What is the objectives of Software Testing?
Strawman operating environment proposal Presented to P2600 Meeting #16, Las Vegas NV January 16-17, 2006 Brian Smithson.
Software Testing. System/Software Testing Error detection and removal determine level of reliability well-planned procedure - Test Cases done by independent.
High Assurance Products in IT Security Rayford B. Vaughn, Mississippi State University Presented by: Nithin Premachandran.
Next level solutions 1 Security: It’s Just Good Systems Engineering Ronda R. Henning Harris Corporation
Guideline for Developer Documentation Christian Krause 8th ICCC / September 26th, 2007 Federal Office for Information Security.
1 MIS 444 Information Resource Management Ahituv, Neumann, & Riley Ch. 4: The Systems Approach.
1 Open Discussion PSOSM 2012 Prof. Ravi Sandhu Executive Director and Endowed Chair © Ravi Sandhu.
Guess the colour Mix the colours Evaluation Group with work.
And you call me coloured..?
And you call me coloured..?. When I was born, I was black When I grow up, I’m black When I go in sun, I’m black When I’m scared, I’m black And when I.
The Common Criteria for Information Technology Security Evaluation
Software Development and Safety Critical Decisions
Colours Презентацию выполнила Преподаватель МБУДО ДШИ им.Л.И.Ошанина
Median Per Capita Home Equity of Medicare Homeowners, by Federal Poverty Level and Race/Ethnicity, 2012 Median per capita home equity, among beneficiaries.
Institute for Cyber Security
Quality Management Perfectqaservices.
Costume Design Character _______________________________
ALTERNATIVES Santa Clara County Parks & Recreation Department and California State Parks.
الوحدة 20 مهارات التواصل مع الآخرين
SENIOR YEAR APPAREL SALES!!
Basics of Modeling اصول مدلسازی
Social Security Income Social Security Income Social Security Income
The Control Process.
Intersection of Data, Policy and Privacy
Share of Medicare beneficiaries Median savings () Mean savings
Instructions: Look at the question in the central square.
Executive Director and Endowed Chair
Lesson Quizzes Standard Lesson Quiz
Median Per Capita Savings of the Medicare Population, by Federal Poverty Level and Race/Ethnicity, 2012 Median per capita savings, among all beneficiaries.
Software Testing.
Give your answer as a mixed number in its simplest form
Common Criteria Ravi Sandhu.
The Grand Goal: One Evaluation Per Planet
World-Leading Research with Real-World Impact!
IT SECURITY EVALUATION ACCORDING TO HARMONIZED AND APPROVED CRITERIA
World-Leading Research with Real-World Impact!
Principles of Object Oriented Programming
Share of Medicare beneficiaries Median (50th percentile)
Kraft Box Custom Packaging Pro. Being familiar with the Kraft boxes and packaging concept is not all that you need to know. There’s more to it that you.
Presentation transcript:

Common Criteria Ravi Sandhu

Common Criteria International unification Flexibility Separation of CC v2.1 is ISO 15408 Flexibility Separation of Functional requirements Assurance requirements Marginally successful so far v1 1996, v2 1998, widespread use ???

Common Criteria

Class, Family, Component, Package

Security Functional Requirements

Security Assurance Requirements

Evaluation Assurance Levels (EALs) Security can be retrofitted Security must be designed in Impractical except for simplest systems

Evaluation Assurance Levels (EALs) Black box evaluation Grey box evaluation White box evaluation

Evaluation Assurance Levels (EALs)