Security Standards for Products

Paul J. Brusil, Noel Zakin · 2012

This chapter presents an overview of the established standards for evaluating the trustworthiness and effectiveness of security products. A particular goal of standardization in the security arena is to evolve toward an information technology (IT)-driven economy where security products, and secured products, approach plug-and-play status. They should be comparably trusted, be available for purchase from multiple competing vendors, and be able to be mixed, matched, and integrated to provide requisite secure, trusted IT infrastructures that reduce the risks of greatest concern. This chapter also provides a general introduction to standards and discusses why standards are important. It summarizes what types of security-relevant standards exist, what bodies create standards, and what security characteristics, features, or capabilities are addressed in examples of different standards. Examples of some of the many types of standards that apply specifically to enhancing trust in products are discussed. The chapter further includes several standards-based product development approaches ranging from consensus-based standards for security specifications and product development processes to formal capability-based standards and ISO (International Organization for Standardization) secure software development processes.

Read the paper · More papers on PaperTik