Approved System

by Bruce Brown | 0 comment

Information Assurance is based on obtaining a high level of confidence on information’s confidentiality, integrity, and availability.  Some organizations that deal with “critical information”.  Critical information included things like banking transactions, classified data, information that is evidence in an ongoing investigation.  Companies, unions and government that handle this kind of information usually have a lot of exposure because they are handling public data, share holder data, employee data and are doing a lot of translation across the un-trusted networks such as the Internet.  With critical information and high exposure these organizations MUST have “approved processes” for vetting, testing and validating “approved software” and “approved systems”.

For example, in the Department of Defense there are many lists that have approved software.  These lists are per command within larger organizations.  One over arching process/list is the Common Criteria:

Common Criteria is an international standard for validating technical security built in to security feature of information systems.  The international standard is known as ISO/IEC 15408.

This standard is used by many large organizations all over the world that serve the public:

www.commoncriteriaportal.org

http://www.commoncriteria.com

Each organization has there own specific security needs so most of the time they have many levels of application approval and process:

NSA / DOD / US Gov – www.niap-ccevs.org – National Information Assurance Partnership (NIAP) uses Common Criteria Evaluation and Validation Scheme (CCEVS) to ensure that only approved Information Assurance (IA)  and IA-Enabled Information Technology (IT) products are used

Canadian Trusted Computer Product Evaluation Criteria
UKhttp://www.cesg.gov.uk/servicecatalogue/ccitsec‎

Commercial organizations that want their products used by organization processing and storing critical information must submit to common criteria as well:

Applehttps://ssl.apple.com/support/security/commoncriteria/

Microsofthttp://www.microsoft.com/en-us/sqlserver/common-criteria.aspx‎

xeroxCommon Criteria

Citrixhttp://www.citrix.com/support/security-compliance/common-criteria.html‎

CiscoCisco Common Criteria 
Emc – EMC – Common Criteria

Organizational units also have their own criteria for approved applications and systems:

US ArmyArmy Chess

US Air ForceAF E/APL – Certified Air Force Evaluated Approved Product List

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *

Comment *