Experiences with the British certification scheme
David Herson · 1991
The UK Communications-Electronic Security Group (CESG) has been performing the role of national computer security certification authority for about 4½ years since being given the national remit for technical computer security, in 1984. Initially, this was solely in support of government systems processing classified information and relied mainly on the output from evaluations performed by contract evaluation facilities using CESG’s own criteria and methodology. A very small number of product evaluations were conducted at this time, where a strong government interest justified the investment of public money in seeing that IT security products, developed in the UK, received appropriate recognition.