A Case Study in Applying Common Criteria to Development Process to Improve Security of Software Products
暂无分享,去创建一个
IT Security evaluation based on Common Criteria (CC, ISO/ IEC 15408), international standard for evaluation of security properties of IT products and systems, requires evaluation deliverables such as development and operational documents of TOE (Target of Evaluation) according to EAL (Evaluation Assurance Level). As most developers commonly prepare evaluation deliverables after their products have been developed, additional costs and time have been invested to be ready for evaluation evidences in reverse-engineering. But CC does not provide any methodological support to prepare evaluation deliverables, and furthermore, related work is not sufficient. In this paper, we present how CC applies to development process to improve security of their products and reduce the time and costs to make IT security evaluation. We demonstrate our idea by means of case study – developing MTOS 7.5, security enhanced UNIX-like operating system based on BSD 4.4 according to EAL3 in CC.
[1] Tai-Hoon Kim,et al. SSE-CMM BPs to Meet the Requirements of ALC_DVS.1 Component in CC , 2003, ISCIS.
[2] Sea Ling,et al. Describing Web Service Architectures through Design-by-Contract , 2003, ISCIS.
[3] Ross J. Anderson. Security engineering - a guide to building dependable distributed systems (2. ed.) , 2001 .
[4] Choon Seong Leem,et al. Supplement of Security-Related Parts of ISO/IEC TR 15504 , 2003, ISCIS.