The National Technical Authority for Information Assurance
 
  ABOUT US   PRODUCTS & SERVICES   PUBLICATIONS   POLICY & TECHNOLOGIES   FIND A .....
Introduction

CESG Agenda

General

ITSEC & Common Criteria

Biometrics

Mathematical

Historical

Find a Publication

 
 
ITSEC & Common Criteria

Abbreviations and References
This document lists references and abbreviations quoted in other publications.
pdf
40k
Best Practices for Biometric Testing
CESG developed "Best Practices for Biometric Testing" standards.
pdf
55k
Biometric Device
Draft Protection Profile.
pdf
587k
CCRA - Common Criteria Recognition Arrangement
The purpose of this Arrangement is to bring about a situation in which IT products and protection profiles which earn a Common Criteria certificate can be procured or used without the need for further evaluation.

pdf
435k
CLEF Requirements Part I - Start Up and Operation (UKSP02 Part I)
Covers, in detail, the appointment and operation of CLEFs for the UK ITSEC scheme. Includes the following headings: Setting up a CLEF; Appointment & Assessment for New CLEFs and CLEF operation.

pdf
293k
CLEF Requirements Part II- Conduct of an Evaluation UKSP02 Part II: version 2.0
Covers CLEF organization, preparation, conduct and conclusion phases of an evaluation.

pdf
83k
Collection of Developer Evidence
The objective of this document is to facilitate effective and flexible application of the Criteria. There is considerable flexibility in the form in which developers may supply deliverables as inputs to evaluation. This interpretation examines some of the alternatives that the developer may choose and the ways in which the evaluator may respond. Version 1.0 August 2000.

pdf
25k
Common Criteria Certification
This guide is intended as an introductory overview to Certification in the UK against Common Criteria.

pdf
1328k
Common Criteria, an Introduction
The Common Criteria represents the outcome of efforts to develop criteria for evaluation of IT security that are widely useful within the international community.

pdf
552k
Controlled Access Protection Profile Version 1.d
Certification awarded October 1999 Protection Profile NoPP006.
pdf
370k
Description of the scheme - UKSP01
Provides a complete overall description of the UK Scheme.
pdf
73k
Guidance to Sponsors on TOE Scoping
Provides guidance on questions of evaluation scope, including those of which product subset and configuration to submit for evaluation.

pdf
105k
Labeled Security Protection Profile Version 1.b
Certification awarded October 1999 Protection Profile NoPP007.
pdf
426k
Mobile Code Authentication Draft
Protection Profile for comment.
pdf
93k
Mobile Code Isolation Draft
Protection Profile for comment.
pdf
80k
Mobile Code Quarantine Draft
Protection Profile for comment.
pdf
87k
Mutual Recognition Agreement of IT Security Evaluation Certificates Version 2.0.April 1999
This document supersedes document 017/97 Finally approved by Senior Officials Group Information Systems Security of the European Commission at their meeting on 26 November 1997. This document details the agreement by which products or systems awarded an IT Security Evaluation Certificate in one country can be used by parties in other countries without the need for them to be evaluated and certified again.

pdf
108k
Oracle Database Management System
Certification awarded May 2000 Protection Profile NoPP008.
pdf
646k
PKI Secure Kernel
"version 1.1 Evaluated": Protection Profile.
pdf
673k
Privilege Directed Content Protection
Certification awarded January 2001 Protection Profile NoPP009.
pdf
161k
Requirement to perform Integrated Circuit Evaluations
This describes the minimun set of capabilities that an ITSEF must possess to carry out hardware testing. Version 1.1 July 2003.

pdf
43k

Requirement to perform Integrated Circuit EvaluationsAnnex A Examples of Smartcard Specific Attacks
This annex provides some examples of attacks that an ITSEF should be able to execute during the evaluation of an integrated circuit. Version 1.1 July 2003.

pdf
56k

Role-Based Access Control Protection Profile Version 1.0
Certification awarded September 1998 Protection Profile NoPP001.

pdf
55k
Security Evaluation and Certification of Digital Tachographs
The European Union has issued a Directive concerning the application of EEC Regulations on recording equipment used in road transport. These require the security features of the Digital Tachograph to be evaluated and certified against ITSEC. This paper provides guidance for those who wish to use Common Criteria as an alternative to ITSEC and also clarifies a number of other issues. Revised version 1.12 June 2003.

pdf
163k
Security Evaluation for IT Products
An introduction to the benefits and procedures of UK ITSEC certification.
pdf
387k

Sponsor's Guide (Role of Sponsor in IT Security Evaluation and Certification) UKSP03
Covers a broad spectrum of issues concerning the Sponsor and the UK Scheme. Subjects include: Features and Benefits of the Scheme; Concepts of Security Evaluation; Roles and Responsibilities of Sponsors; Evaluation Preparation & Timescales and Project Management Issues. Some aspects also affect Developers.

pdf
240k
TOE Scope information - Guidance to sponsors on TOE Scope Information
Guidance to sponsors on Target Of Evaluation (TOE) Scope Information.

pdf
232k
 © Crown copyright, 2008. This CESG Website is maintained for your personal use and viewing. Access and use by you of this site constitutes acceptance of our terms and conditions which take effect from the date of first use. Click here for our terms and conditions CESGweb@cesg.gsi.gov.uk