The value of CC EAL[1234567] certification
Posted Sep 30, 2004 19:01 UTC (Thu) by
Max.Hyre (subscriber, #1054)
In reply to:
The value of CC EAL[1234567] certification by scripter
Parent article:
Mandrake shoots for EAL5
There's a great article on the subject by the security researcher Jonathan S. Shapiro (Johns Hopkins University Information Security Institute). My favorite comment therein is:
As I mentioned before, EAL levels run from 1 to 7. EAL1 basically means that
the vendor showed up for the meeting. EAL7 means that key parts of the
system have been rigorously verified in a mathematical way. EAL4 means that
the design documents were reviewed using non-challenging criteria. This is
sort of like having an accounting audit where the auditor checks that all of
your paperwork is there and your business practice standards are
appropriate, but never actually checks that any of your numbers are correct.
An EAL4 evaluation is not required to examine the software at all.
An EAL4 rating means that you did a lot of paperwork related to the software
process, but says absolutely nothing about the quality of the software
itself. There are no quantifiable measurements made of the software, and
essentially none of the code is inspected. Buying software with an EAL4
rating is kind of like buying a home without a home inspection, only more
risky.
(
Log in to post comments)