A Study on Secure SDLC Specialized in Common Criteria
Min-Gyu Lee, Hyo-jung Sohn, Baek MinSeong, Jong-Bae Kim · Advanced science and technology letters · 2015
Common Criteria (CC) is a globally standardized process for information technology security evaluation criteria for IT products manufactured around the world. IT products used in governmental organizations and public institutions must acquire a certain level of or higher than the Evaluation Assurance Level (EAL) of CC. Meanwhile, the general Software Development Life Cycle (SDLC) does not suggest guidelines to eliminate weakness in the development process; therefore, a possible critical situation may occur. Furthermore, CC currently performs security certification for Target of Evaluation (TOE) only, and it does not suggest a guideline related to Secure Software Development Life Cycle (SSDLC) that considers weakness in the development process. If the relevant TOE is developed by SSDLC specializing in CC, all of the evaluators and developers can engage in CC certification with an objective perspective. This thesis suggests that SSDLC can develop TOE suitable for CC by identifying vulnerabilities and weaknesses, making a reference to MS-SDL, OWASP Comprehensive Lightweight Application Security Process (CLASP), and McGraw's Touchpoints based on the weaknesses provided at the CWE.