Common Criteria Security Evaluation: A Time and Cost Effective Approach

Mohammadreza Razzazi, M. Jafari, S. Moradi, H. Sharifipanah, Morteza Damanafshan, Kaveh Fayazbakhsh, A. Nickabadi · 2006

Security is one of the most important concerns for both developers and consumers in the Information Technology (IT) world. Developing secure IT products demands some standards to assure the security level of the products. Common Criteria (CC) standard is formed to achieve this goal. But like other standards, CC has its own problems. In this paper, we address two of these problems: abstraction and time problems. Abstraction in the context of Common Criteria evaluation methodology is one of the most significant problems in the IT product evaluation process. Furthermore, the other problem of evaluation process based on Common Criteria is that it is a time consuming process, so it eventually makes the process a costly one. To solve these two problems, we decompose the tasks mentioned in the CC standard into finer ones. Moreover, we propose various expertises and task parallelism for performing aforementioned finer tasks.

Read the paper · More papers on PaperTik