LWN.net Logo

The value of CC EAL[1234567] certification

The value of CC EAL[1234567] certification

Posted Sep 30, 2004 19:01 UTC (Thu) by Max.Hyre (subscriber, #1054)
In reply to: The value of CC EAL[1234567] certification by scripter
Parent article: Mandrake shoots for EAL5

There's a great article on the subject by the security researcher Jonathan S. Shapiro (Johns Hopkins University Information Security Institute). My favorite comment therein is:

As I mentioned before, EAL levels run from 1 to 7. EAL1 basically means that the vendor showed up for the meeting. EAL7 means that key parts of the system have been rigorously verified in a mathematical way. EAL4 means that the design documents were reviewed using non-challenging criteria. This is sort of like having an accounting audit where the auditor checks that all of your paperwork is there and your business practice standards are appropriate, but never actually checks that any of your numbers are correct. An EAL4 evaluation is not required to examine the software at all.

An EAL4 rating means that you did a lot of paperwork related to the software process, but says absolutely nothing about the quality of the software itself. There are no quantifiable measurements made of the software, and essentially none of the code is inspected. Buying software with an EAL4 rating is kind of like buying a home without a home inspection, only more risky.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds