free web tracker Part 3: Security assurance requirements

Part 3 Contents

(Part 1Introduction and general model)
(Part 2
 
Security functional requirements)
1Scope
1.1Organisation of CC Part 3
1.2CC assurance paradigm
1.2.1CC philosophy
1.2.2Assurance approach
1.2.3The CC evaluation assurance scale
2Security assurance requirements
2.1Structures
2.1.1Class structure
2.1.2Assurance family structure
2.1.3Assurance component structure
2.1.4Assurance elements
2.1.5EAL structure
2.1.6Relationship between assurances and assurance levels
2.2Component taxonomy
2.3Protection Profile and Security Target evaluation criteria class structure
2.4Usage of terms in Part 3
2.5Assurance categorisation
2.6Assurance class and family overview
2.6.1Class ACM: Configuration management
2.6.2Class ADO: Delivery and operation
2.6.3Class ADV: Development
2.6.4Class AGD: Guidance documents
2.6.5Class ALC: Life cycle support
2.6.6Class ATE: Tests
2.6.7Class AVA: Vulnerability assessment
2.7Maintenance categorisation
2.8Maintenance of assurance class and family overview
2.8.1Class AMA: Maintenance of assurance
3Protection Profile and Security Target evaluation criteria
3.1Overview
3.2Protection Profile criteria overview
3.2.1Protection Profile evaluation
3.2.2Relation to the Security Target evaluation criteria
3.2.3Evaluator tasks
3.3Security Target criteria overview
3.3.1Security Target evaluation
3.3.2Relation to the other evaluation criteria in this Part 3
3.3.3Evaluator tasks
4Class APE: Protection Profile evaluation
4.1TOE description (APE_DES)
4.2Security environment (APE_ENV)
4.3PP introduction (APE_INT)
4.4Security objectives (APE_OBJ)
4.5IT security requirements (APE_REQ)
4.6Explicitly stated IT security requirements (APE_SRE)
5Class ASE: Security Target evaluation
5.1TOE description (ASE_DES)
5.2Security environment (ASE_ENV)
5.3ST introduction (ASE_INT)
5.4Security objectives (ASE_OBJ)
5.5PP claims (ASE_PPC)
5.6IT security requirements (ASE_REQ)
5.7Explicitly stated IT security requirements (ASE_SRE)
5.8TOE summary specification (ASE_TSS)
6Evaluation assurance levels
6.1Evaluation assurance level (EAL) overview
6.2Evaluation assurance level details
6.2.1EAL1 - functionally tested
6.2.2EAL2 - structurally tested
6.2.3EAL3 - methodically tested and checked
6.2.4EAL4 - methodically designed, tested, and reviewed
6.2.5EAL5 - semiformally designed and tested
6.2.6EAL6 - semiformally verified design and tested
6.2.7EAL7 - formally verified design and tested
7Assurance classes, families, and components
8Class ACM: Configuration management
8.1CM automation (ACM_AUT)
8.2CM capabilities (ACM_CAP)
8.3CM scope (ACM_SCP)
9Class ADO: Delivery and operation
9.1Delivery (ADO_DEL)
9.2Installation, generation and start-up (ADO_IGS)
10Class ADV: Development
10.1Functional specification (ADV_FSP)
10.2High-level design (ADV_HLD)
10.3Implementation representation (ADV_IMP)
10.4TSF internals (ADV_INT)
10.5Low-level design (ADV_LLD)
10.6Representation correspondence (ADV_RCR)
10.7Security policy modeling (ADV_SPM)
11Class AGD: Guidance documents
11.1Administrator guidance (AGD_ADM)
11.2User guidance (AGD_USR)
12Class ALC: Life cycle support
12.1Development security (ALC_DVS)
12.2Flaw remediation (ALC_FLR)
12.3Life cycle definition(ALC_LCD)
12.4Tools and techniques (ALC_TAT)
13Class ATE: Tests
13.1Coverage (ATE_COV)
13.2Depth (ATE_DPT)
13.3Functional tests (ATE_FUN)
13.4Independent testing (ATE_IND)
14Class AVA: Vulnerability assessment
14.1Covert channel analysis (AVA_CCA)
14.2Misuse (AVA_MSU)
14.3Strength of TOE security functions (AVA_SOF)
14.4Vulnerability analysis (AVA_VLA)
15Assurance maintenance paradigm
15.1Introduction
15.2Assurance maintenance cycle
15.2.1TOE acceptance
15.2.2TOE monitoring
15.2.3Re-evaluation
15.3Assurance maintenance class and families
15.3.1Assurance maintenance plan
15.3.2TOE component categorisation report
15.3.3Evidence of assurance maintenance
15.3.4Security impact analysis
16Class AMA: Maintenance of assurance
16.1Assurance maintenance plan (AMA_AMP)
16.2TOE component categorisation report (AMA_CAT)
16.3Evidence of assurance maintenance (AMA_EVD)
16.4Security impact analysis (AMA_SIA)
AnnexACross reference of assurance component dependencies
AnnexBCross reference of EALs and assurance components