- published: 16 Feb 2016
- views: 849
The Common Criteria for Information Technology Security Evaluation (abbreviated as Common Criteria or CC) is an international standard (ISO/IEC 15408) for computer security certification. It is currently in version 3.1 revision 4.
Common Criteria is a framework in which computer system users can specify their security functional and assurance requirements (SFRs and SARs respectively) through the use of Protection Profiles (PPs), vendors can then implement and/or make claims about the security attributes of their products, and testing laboratories can evaluate the products to determine if they actually meet the claims. In other words, Common Criteria provides assurance that the process of specification, implementation and evaluation of a computer security product has been conducted in a rigorous and standard and repeatable manner at a level that is commensurate with the target environment for use.
Common Criteria is used as the basis for a Government driven certification scheme and typically evaluations are conducted for the use of Federal Government agencies and critical infrastructure.
Common Criteria in 5 minutes, What is Common Criteria?
Daniel Faigin, Overview of Common Criteria (September 10, 2003)
System Security Evaluation Models on Common Criteria (CISSP Free by Skillset.com)
Common Criteria from a Global Perspective
How to Get the Common Criteria Certificate in Germany and Live to Tell the Tale
CISSP - Sample practice question (Common Criteria Model) #163
Free CISSP Training Video | CISSP Tutorial Online Part 3
Glossary: Dr. Peter Laackmann, Common Criteria
fosdem2012 tomas gustavsson cesecore common criteria
Security Evaluations: Common Criteria