Advances of emerging Information and Communications Technology (ICT) technologies push the boundaries of what is possible and open up new markets for innovative ICT products and services. The adoption of ICT products and systems with security properties depends on consumers' confidence and markets' trust in the security functionalities and whether the assurance measures applied to these products meet the inherent security requirements. Such confidence and trust are primarily gained through the rigorous development of security requirements, validation criteria, evaluation, and certification. Common Criteria for Information Technology Security Evaluation (often referred to as Common Criteria or CC) is an international standard (ISO/IEC 15408) for cyber security certification. In this paper, we conduct a systematic review of the CC standards and its adoptions. Adoption barriers of the CC are also investigated based on the analysis of current trends in security evaluation. Specifically, we share the experiences and lessons gained through the recent Development of Australian Cyber Criteria Assessment (DACCA) project that promotes the CC among stakeholders in ICT security products related to specification, development, evaluation, certification and approval, procurement, and deployment. Best practices on developing Protection Profiles, recommendations, and future directions for trusted cybersecurity advancement are presented.
翻译:采用具有安全特性的信通技术产品和系统取决于消费者对安全功能的信心和市场对安全功能的信任,以及对这些产品采用的保证措施是否符合固有的安全要求。这种信心和信任主要通过严格制定安全要求、验证标准、评估和认证而获得。信息技术安全评价共同标准(通常称为共同标准或CC)是网络安全认证的国际标准(ISO/IEC 15408)。我们在本文件中对CC标准及其采用进行了系统审查。根据对当前安全评价趋势的分析,还调查CC的采用障碍。具体地说,我们分享最近澳大利亚网络标准评估开发项目的经验教训,该项目在信息和通信技术安全产品规格、开发、评价、认证和核准、采购和部署方面促进利益攸关方之间对CCC的开发、评价、认证和核准、采购和部署。关于制定保护概况、建议和未来方向以促进可靠网络安全的最佳做法介绍。