Download presentation
Presentation is loading. Please wait.
Published byElla Regan Modified over 11 years ago
1
© Crown Copyright (2000) Module 3.2 Evaluation Management
2
You Are Here M3.1 Evaluation Process M3.2 Evaluation Management MODULE 3 - SCHEME RULES AND PROCEDURES
3
Evaluation Management Preparation Phase Conduct Phase Conclusion Phase
4
Evaluation Management Preparation Phase Conduct Phase Conclusion Phase
5
Preparation Phase - Inputs Definition of Target of Evaluation –Scope, boundaries, interfaces, composites, etc. What evaluation level is required ? Technical expertise required ? Evaluation Planning TOE
6
Preparation Phase - Suitability CLEF/CB may review ST for suitability Check Sponsor and Developer have full understanding of: –the evaluation process –the role of the CLEF –their responsibilities throughout evaluation
7
Preparation Phase - TIN May be combined with EWP Task Identification Sponsor and Developer Details Description of TOE Summary of Security Requirements Timescales Staffing Contacts
8
Preparation Phase - EWP May be combined with TIN Evaluation methodology –CEM/ITSEC –Interpretations Evaluation effort for each activity Constraints Limitations
9
Preparation Phase - UKSP06 Entry & CB Questionnaire UKSP06
10
Task Start-up Meeting Objective Attendees Timing Agenda
11
Preparation Phase - Outputs Evaluation Planning EWP TIN UKSP 06 Entry Security Target CB Questionnaire
12
Evaluation Management Preparation Phase Conduct Phase Conclusion Phase
13
Conduct Phase - Inputs Task Conduct TIN / EWP TOE Deliverables Security Target Deliverables Schedule
14
Conduct Phase - Reporting Progress Evaluation Progress Meeting (EPM) ETR Production –Draft annexes (activity reports, glossary, list of deliverables etc.) Observation Report Status Register
15
Evaluation Progress Meetings Objective Attendees Timing Agenda
16
Observation Report Status - 1 AGR - Corrective Action Agreed CAP - Certifier Action Pending CLR - Cleared FIX - Fix to be evaluated by CLEF ISS - Issued to the Certifier
17
Observation Report Status - 2 PRO - Corrective Action Proposed REJ - Corrective Action Rejected REL - Released to the Sponsor / Developer WDN - Problem Report Withdrawn
18
Conduct Phase - Observation Reports Content (Level 1 and Level 2) –Identifier –Severity Level –Evaluation Activity where raised –Observation –Organisation responsible for resolution –Timescale for resolution
19
Conduct Phase - Issues Maintain Independence Comply with UKAS Requirements Comply with Methodology Requirements
20
Conduct Phase - Outputs Task Conduct Work Package Reports Observation Reports Scheme Observation Reports
21
Evaluation Management Preparation Phase Conduct Phase Conclusion Phase
22
Conclusion Phase Evaluation Technical Report (ETR) Certificate and Certification Report Task Closedown
23
Assurance Maintenance (CMS) Additional Evaluation Task See Module 2.8 for more details
24
ITSEC v. CC Main difference is work breakdown ITSEM/UK SP 05 specify mandatory requirements CEM defines Work Units
25
Summary Three Phases to evaluation Management –Preparation Phase –Conduct Phase –Conclusion Phase Covers whole evaluation Terminology difference between ITSEC & CC
26
Further Reading UKSP 01 UKSP 04 Part 1 UKSP 05 Part 1 CEM Part 2, Chapter 2
27
Exercise - Planning Given the ITT on the handouts, please prepare a TIN and EWP for the task
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.