Twenty years of evaluation criteria and commercial technology
Steven B. Lipner · 2003
The major source of progress in computer security products during the last twenty years (1980-99) has been the Internet revolution of the mid-nineties. Evaluation criteria and processes have provided users with some characterization of the security attributes of operating system products. The newly developed Common Criteria show promise of offering more timely and relevant evaluation results. However there is little sign of progress in products that can deal with hostile code or in meeting needs for high assurance.