CA Community






This Blog

Common Criteria – a good concept in transformation

Published: March 25 2010, 08:03 AM
by Joshua Brickman

In my first blog, I pointed out that although it’s a good idea, Common Criteria is expensive, not widely adopted beyond government, and could be improved by transforming to Protection Profiles for enterprise security management. Today the industry is on its way to doing just that – transforming Common Criteria.

The core of the problem with Common Criteria when it comes to enterprise security management (ESM) is there is nothing “common” about it. Each time we or any other vendor wants our products evaluated, we must rewrite a custom security target or requirements document.

Protection Profiles are what the industry is moving toward to simplify and reduce the cost of the Common Criteria  process.  Protection Profiles establish a set of standard features one would expect to find in a certain product. Call it a requirements document, if you want. These would allow government agencies to compare apples to apples and make better informed decisions when acquiring products. Today under Common Criteria, comparisons in the ESM space are not as straightforward because each product has its own security target document.

If Protection Profiles existed for ESM now, at least 64 products from CA, IBM, EMC, Oracle, Symantec, and Microsoft would be compliant.  At the 10th International Common Criteria conference in Tromso, Norway, I gave a talk with Booz Allen Hamilton that laid out the plan to develop this new family of “Protection Profiles” for Enterprise Security Management.     The plan was lauded by the Common Criteria Development Board (CCDB) as the community-based approach they wanted other technology types to follow to update and build out these new standards.   Since this project started, a similar team was formed to update the Firewall Protection Profile. 

This month I participated in the Common Criteria Vendor Forum meeting with the Common Criteria Development Board at the 2010 RSA Conference.    I presented how we are leading a team of ESM Vendors in an effort to build out Protection Profiles to close the gap for Enterprise Security Management products.  

We just kicked off the Global Threat Analysis portion of the project.  A survey will be distributed world-wide to determine the priorities for this new standard.   Participants are the government agencies that buy our software.   The primary goal of the survey is to get our customers to set the priority among the six technology types in the ESM space:  Access Control, Centralized Policy Management and Distributed Enforcement, Identity Management,  Data Loss Prevention and Log Collection.  

In my next blog I’ll present the results of the survey and announce which technology the team will focus on for the first ESM Protection Profile which we hope to publish by the end of the year.

 

Share this post:  

 

By: Joshua Brickman
Joshua Brickman, project management professional, runs CA’s Federal Certifications Program. He has led CA through the successful evaluation of sixteen products through the Common Criteria over the last five years (in both the U.S. and Canada). Brickman has given talks at the last four International...
Read More..

3 people have left comments:

In my last blog I referenced a global threat survey that CA was administrating. I plan on presenting

Posted by: CA on Security Management | September 15, 2010 12:09 PM

Nice Reading. Thanks. LRQA helps bring integrity, independence and world-renowned recognition to your assurance claims. Quality-ISO 9001 Training Environmental-ISO 14001 Training Information Security Management Training Food & Beverage Industry Management Training Occupational Health And Safety Management Training

Posted by: Anna Ashmore | September 27, 2010 10:05 AM

I had the pleasure of recently presenting at the International Common Criteria Conference (ICCC) in Kuala

Posted by: CA on Security Management | October 18, 2011 2:51 PM

Leave a Comment

* An asterisk indicates a required field

* :  

:

* :  

 Submit