#commoncriteria — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #commoncriteria, aggregated by home.social.
-
🔐 RELIANOID aligns with ISO/IEC 15408 (Common Criteria) principles.
Our load balancer follows EAL-oriented security practices: secure-by-design SSDLC, strong auth & RBAC, encrypted communications, hardened OS (Debian Bookworm), and continuous security testing.
Built for regulated and high-assurance environments.
#RELIANOID #CommonCriteria #ISO15408 #CyberSecurity #OpenSource #NetSec
https://www.relianoid.com/security-compliances/relianoid-iso-iec-15408-common-criteria-compliance/ -
VMware NSX 4.1.0.2 보안기능확인서
-
🎉 Check Point Software Technologies Receives Common Criteria EAL4+ Certification for Quantum Firewall Software R82:
#checkpoint #quantum #firewall #r82 #CommonCriteria #eal4 #cc_eal4 #certification
-
vSphere vCenter Server 8.0 한국 보안적합성 검증 - 보안기능 확인서
-
vSphere vCenter Server 8.0 한국 보안적합성 검증 - 보안기능 확인서
-
The Common Criteria #Certification certificates for #iOS 16 and #iPadOS 16 evaluations have been posted on the NIAP PCL as well as on the Common Criteria Portal.
#NIAP PCL
iOS -> https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11349
iPadOS -> https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11350#CommonCriteria Portal
iOS -> https://www.commoncriteriaportal.org/files/epfiles/st_vid11349-ci.pdf
iPadOS -> https://www.commoncriteriaportal.org/files/epfiles/st_vid11350-ci.pdf -
The Common Criteria #Certification certificates for #iOS 16 and #iPadOS 16 evaluations have been posted on the NIAP PCL as well as on the Common Criteria Portal.
#NIAP PCL
iOS -> https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11349
iPadOS -> https://www.niap-ccevs.org/Product/Compliant.cfm?PID=11350#CommonCriteria Portal
iOS -> https://www.commoncriteriaportal.org/files/epfiles/st_vid11349-ci.pdf
iPadOS -> https://www.commoncriteriaportal.org/files/epfiles/st_vid11350-ci.pdf -
In my experience Common Criteria is a double-edged sword. The NIAP Protection Profiles are often extremely detailed and describe the threats and mitigations that the product needs to take. Yet, there often is some misconception what it means that a device has the certification, and some companies seem to use the certification in kind of false marketing.
Common Criteria validation does not replace security testing. When the validated for certification, the product is rigorously tested against the specific Protection Profile, but this is the extent of this testing. In fact if you read many validation reports carefully, they actually do often go to detail in explaining that the evaluation did not look for or attempt to exploit vulnerabilities. This is what the validation laboratories are expected to do after all: Validate the target against a very specific Protection Profile.
This does leave an obvious gap however: On numerous occasions I’ve seen gaping security holes (mostly logical ones), that fall outside of the scope of the specific Protection Profile. If there is no-one actually taking a holistic view of the entire environment and use case for the product, these flaws can go unnoticed. If not careful, the CC compliance could be interpreted as something that it is not, leading to false sense of security.
Many security flaws can be prevented by adhering to the Protection Profile rules and validating the target for Common Criteria certification. The scope of the impact of the certification is limited, however. Organizations buying products need to understand what the Common Criteria compliance means and even more importantly what it does not.
-
In my experience Common Criteria is a double-edged sword. The NIAP Protection Profiles are often extremely detailed and describe the threats and mitigations that the product needs to take. Yet, there often is some misconception what it means that a device has the certification, and some companies seem to use the certification in kind of false marketing.
Common Criteria validation does not replace security testing. When the validated for certification, the product is rigorously tested against the specific Protection Profile, but this is the extent of this testing. In fact if you read many validation reports carefully, they actually do often go to detail in explaining that the evaluation did not look for or attempt to exploit vulnerabilities. This is what the validation laboratories are expected to do after all: Validate the target against a very specific Protection Profile.
This does leave an obvious gap however: On numerous occasions I’ve seen gaping security holes (mostly logical ones), that fall outside of the scope of the specific Protection Profile. If there is no-one actually taking a holistic view of the entire environment and use case for the product, these flaws can go unnoticed. If not careful, the CC compliance could be interpreted as something that it is not, leading to false sense of security.
Many security flaws can be prevented by adhering to the Protection Profile rules and validating the target for Common Criteria certification. The scope of the impact of the certification is limited, however. Organizations buying products need to understand what the Common Criteria compliance means and even more importantly what it does not.
-
Just found this brand-new overview on access control in Unix-like systems, wholly recommend to everyone who is interested in the topic. It huge though, 200 pages!
https://venam.nixers.net/blog/unix/2023/02/28/access_control.html
-
Does defining "a minimum path length" for certification validation have any security benefit?
https://security.stackexchange.com/questions/268097/does-defining-a-minimum-path-length-for-certification-validation-have-any-secu
#publickeyinfrastructure #certificateauthority #commoncriteria #certificates -
Does defining "a minimum path length" for certification validation have any security benefit?
https://security.stackexchange.com/questions/268097/does-defining-a-minimum-path-length-for-certification-validation-have-any-secu
#publickeyinfrastructure #certificateauthority #commoncriteria #certificates -
Kennt sich wer mit #CommonCriteria (https://en.wikipedia.org/wiki/Common_Criteria) aus?
Was ist besser?
- PP compliant
- EAL4+Oder dürfen/können diese nicht verglichen werden? Danke!
-
Das Bundesamt für Sicherheit in der Informationstechnik (BSI) erteilt iPhones und iPads eine Freigabe für Bundesbehörden. Warum das für Apple nützlich ist.
Bundesamt: iPhone und iPad sind sicher genug für Verschlusssachen -
In einer weitläufigen Dokumentenlandschaft verbergen sich die Spezifikationen und Sicherheitsvorgaben der TI – ein Einblick am Beispiel der Konnektoren.
eHealth: Im Irrgarten der Sicherheitsvorgaben der Telematikinfrastruktur -
@hw Über den Hinweis auf die Listen zertifizierter Produkte hinaus passt auch der Toot des #BSI vom 01. Juni 2021 gut zu dieser Thematik, der auf Hintergrundinformationen und technische Details zu exemplarischen Schwächen einiger, beispielhafter Security Tokens verlinkt.
👉 https://social.bund.de/@bsi/106335677272645761#SichereHalbleiterTechnologien #CommonCriteria #Zertifzierung #DeutschlandDigitalSicherBSI
-
@hw Von diesem und anderen Herstellern gibt es mehrere Modelle mit unterschiedlichen Sicherheitseigenschaften. Idealerweise ist sowohl die Hardware als auch die Software nach #CommonCriteria (CC) oder der Beschleunigten Sicherheitszertifizierung (BSZ) zertifiziert.
Die entsprechenden Listen zertifizierter Produkte sind hier zu finden:
• Deutschland (#BSI): https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Listen/listen_node.html
• Frankreich (ANSSI): https://www.ssi.gouv.fr/administration/produits-certifies/cspn/produits-certifies-cspn/
• Niederlande (TÜV Nederland): https://www.tuv-nederland.nl/common-criteria/certification.html -
Als erster Anbieter eines Videokonferenzsystems lässt sich Zoom nach dem internationalen Standard Common Criteria prüfen und bewerten.
Zoom-Client erhält Common-Criteria-Zertifikat -
PrimeKey hat seine Open-Souce-PKI-Software EJBCA Enterprise nach Common Criteria zertifiziert. Damit lässt sie sich auch in kritischen Umgebung einsetzen. Public-Key-Infrastruktur: EJBCA Enterprise erhält Common-Criteria-Zertifizierung -
Jdou (především) vládní standardy, certifikace, bezpečnost a open source vůbec dohromady? Odpověď zní ano, ale.. @RezzaBuh se již několik let snaží získávat razítka pro produkty firmy Red Hat a každý šedý vlas je mu toho svědkem. #fips #commoncriteria #cc