ICT Security Evaluation
Svein J. Knapskog · 2011
Bibliography . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 240 Security is increasingly seen as one of the basic qualities for ICT services. Without adequate security, a number of potential service users will decline the use of net-based services that they otherwise would have found to be effective and useful. Service providers must be able to convince users of the fact that information that is exchanged as a part of the service related procedures and that may be seen as sensitive, for example for economical or personal reasons, is not going astray or falling victim of any kind of abuse or misuse. However, it is not at all easy to describe and characterize ICT security in quantitative and absolute terms-the answer to this challenge may perhaps be sought with other means. It may be that adequate assurance that an ICT product, also often referred to as a system, best can be obtained by a thorough scrutiny by specialist personnel. This form of quality control will frequently be referred to as a security evaluation by which a technical process is performed in a security evaluation laboratory by experts. The result of the evaluation will be a technical report describing security-relevant findings. The evaluation steps will be described in detail in the current security evaluation standards described in the following sections, and the final verdict will be passed or failed. The laboratory itself must be organized and run by an administratively and economically independent third party and be accredited for the task by a national (governmental) overseeing body. The overseeing body will also be responsible for national certifications schemes build on the results of the security evaluations. A successful evaluation and certification framework aims at providing developers, manufacturers, vendors, and end users alike a common understanding and description of the security challenges they all are facing, and to use this framework to their advantage to describe technical and organizational measures necessary to meet the security challenges.