Trend in security evaluation and accreditation
達明 武部 · 2008
This paper discusses series of security evaluation criteria which provide the methods to verify whether the product can protect the information assets. Having advanced along with the progress of the information technology and the growing threats of the adversaries, the security evaluation has been offering non-biased references to the market. TCSEC, ITSEC, Common Criteria, and FIPS PUB 140-2 are criteria established for the governments’ procurements, and have contributed to the products’ security improvement. A light-weight security evaluation criteria has been proposed for the DCS/SCADA products by the ISA Security Compliance Institute, and has posed practical possibilities.