Share to: share facebook share twitter share wa share telegram print page

Evaluation Assurance Level

The Evaluation Assurance Level (EAL1 through EAL7) of an IT product or system is a numerical grade assigned following the completion of a Common Criteria security evaluation, an international standard in effect since 1999. The increasing assurance levels reflect added assurance requirements that must be met to achieve Common Criteria certification. The intent of the higher levels is to provide higher confidence that the system's principle security features are reliably implemented. The EAL level does not measure the security of the system itself, it simply states at what level the system was tested.

To achieve a particular EAL, the computer system must meet specific assurance requirements. Most of these requirements involve design documentation, design analysis, functional testing, or penetration testing. The higher EALs involve more detailed documentation, analysis, and testing than the lower ones. Achieving a higher EAL certification generally costs more money and takes more time than achieving a lower one. The EAL number assigned to a certified system indicates that the system completed all requirements for that level.

Although every product and system must fulfill the same assurance requirements to achieve a particular level, they do not have to fulfill the same functional requirements. The functional features for each certified product are established in the Security Target document tailored for that product's evaluation. Therefore, a product with a higher EAL is not necessarily "more secure" in a particular application than one with a lower EAL, since they may have very different lists of functional features in their Security Targets. A product's fitness for a particular security application depends on how well the features listed in the product's Security Target fulfill the application's security requirements. If the Security Targets for two products both contain the necessary security features, then the higher EAL should indicate the more trustworthy product for that application.

Assurance levels

EAL1: Functionally Tested

EAL1 is applicable where some confidence in correct operation is required, but the threats to security are not viewed as serious. It will be of value where independent assurance is required support the contention that due care has been exercised with respect to the protection of personal or similar information. EAL1 provides an evaluation of the TOE (Target of Evaluation) as made available to the customer, including independent testing against a specification, and an examination of the guidance documentation provided. It is intended that an EAL1 evaluation could be successfully conducted without assistance from the developer of the TOE, and for minimal cost. An evaluation at this level should provide evidence that the TOE functions in a manner consistent with its documentation, and that it provides useful protection against identified threats.

EAL2: Structurally Tested

EAL2 requires the cooperation of the developer in terms of the delivery of design information and test results, but should not demand more effort on the part of the developer than is consistent with good commercial practice. As such it should not require a substantially increased investment of cost or time. EAL2 is therefore applicable in those circumstances where developers or users require a low to moderate level of independently assured security in the absence of ready availability of the complete development record. Such a situation may arise when securing legacy systems.

EAL3: Methodically Tested and Checked

EAL3 permits a conscientious developer to gain maximum assurance from positive security engineering at the design stage without substantial alteration of existing sound development practices. EAL3 is applicable in those circumstances where developers or users require a moderate level of independently assured security, and require a thorough investigation of the TOE and its development without substantial re-engineering.

EAL4: Methodically Designed, Tested and Reviewed

EAL4 permits a developer to gain maximum assurance from positive security engineering based on good commercial development practices which, though rigorous, do not require substantial specialist knowledge, skills, and other resources. EAL4 is the highest level at which it is likely to be economically feasible to retrofit to an existing product line. EAL4 is therefore applicable in those circumstances where developers or users require a moderate to high level of independently assured security in conventional commodity TOEs and are prepared to incur additional security-specific engineering costs.

Commercial operating systems that provide conventional, user-based security features are typically evaluated at EAL4. Examples with expired Certificate are AIX,[1] HP-UX,[1] Oracle Linux, NetWare, Solaris,[1] SUSE Linux Enterprise Server 9,[1][2] SUSE Linux Enterprise Server 10,[3] Red Hat Enterprise Linux 5,[4][5] Windows 2000 Service Pack 3, Windows 2003,[1][6] Windows XP,[1][6] Windows Vista,[7][8] Windows 7,[1][9] Windows Server 2008 R2,[1][9] z/OS version 2.1 and z/VM version 6.3.[1]

Operating systems that provide multilevel security are evaluated at a minimum of EAL4. Examples with active Certificate include SUSE Linux Enterprise Server 15 (EAL 4+).[10] Examples with expired Certificate are Trusted Solaris, Solaris 10 Release 11/06 Trusted Extensions,[11] an early version of the XTS-400, VMware ESXi version 4.1,[12] 3.5, 4.0, AIX 4.3, AIX 5L, AIX 6, AIX7, Red Hat 6.2 & SUSE Linux Enterprise Server 11 (EAL 4+). vSphere 5.5 Update 2 did not achieve EAL4+ level it was an EAL2+ and certified on June 30, 2015.

EAL5: Semiformally Designed and Tested

EAL5 permits a developer to gain maximum assurance from security engineering based upon rigorous commercial development practices supported by moderate application of specialist security engineering techniques. Such a TOE will probably be designed and developed with the intent of achieving EAL5 assurance. It is likely that the additional costs attributable to the EAL5 requirements, relative to rigorous development without the application of specialized techniques, will not be large. EAL5 is therefore applicable in those circumstances where developers or users require a high level of independently assured security in a planned development and require a rigorous development approach without incurring unreasonable costs attributable to specialist security engineering techniques.

Numerous smart card devices have been evaluated at EAL5, as have multilevel secure devices such as the Tenix Interactive Link. XTS-400 (STOP 6) is a general-purpose operating system which has been evaluated at EAL5 augmented.

LPAR on IBM System z is EAL5 Certified.[13]

EAL6: Semiformally Verified Design and Tested

EAL6 permits developers to gain high assurance from application of security engineering techniques to a rigorous development environment in order to produce a premium TOE for protecting high-value assets against significant risks. EAL6 is therefore applicable to the development of security TOEs for application in high risk situations where the value of the protected assets justifies the additional costs.

Green Hills Software's INTEGRITY-178B RTOS has been certified to EAL6 augmented.[1]

EAL7: Formally Verified Design and Tested

EAL7 is applicable to the development of security TOEs for application in extremely high risk situations and/or where the high value of the assets justifies the higher costs.

Practical application of EAL7 is currently limited to TOEs with tightly focused security functionality that is amenable to extensive formal analysis. The ProvenCore OS, developped by ProvenRun, has been certified to EAL7 in 2019 by the ANSSI.[14] The Tenix Interactive Link Data Diode Device and the Fox-IT Fox Data Diode (one-way data communications device) claimed to have been evaluated at EAL7 augmented (EAL7+).[15]

Implications of assurance levels

Technically speaking, a higher EAL means nothing more, or less, than that the evaluation completed a more stringent set of quality assurance requirements. It is often assumed that a system that achieves a higher EAL will provide its security features more reliably (and the required third-party analysis and testing performed by security experts is reasonable evidence in this direction), but there is little or no published evidence to support that assumption.

Impact on cost and schedule

In 2006, the US Government Accountability Office published a report on Common Criteria evaluations that summarized a range of costs and schedules reported for evaluations performed at levels EAL2 through EAL4.

Range of completion times and costs for Common Criteria evaluations at EAL2 through EAL4.

In the mid to late 1990s, vendors reported spending US$1 million and even US$2.5 million on evaluations comparable to EAL4. There have been no published reports of the cost of the various Microsoft Windows security evaluations.

Augmentation of EAL requirements

In some cases, the evaluation may be augmented to include assurance requirements beyond the minimum required for a particular EAL. Officially this is indicated by following the EAL number with the word augmented and usually with a list of codes to indicate the additional requirements. As shorthand, vendors will often simply add a "plus" sign (as in EAL4+) to indicate the augmented requirements.

EAL notation

The Common Criteria standards denote EALs as shown in this article: the prefix "EAL" concatenated with a digit 1 through 7 (Examples: EAL1, EAL3, EAL5). In practice, some countries place a space between the prefix and the digit (EAL 1, EAL 3, EAL 5). The use of a plus sign to indicate augmentation is an informal shorthand used by product vendors (EAL4+ or EAL 4+).

References

  1. ^ a b c d e f g h i j "Common Criteria certified product list". Archived from the original on 2013-12-31. Retrieved 2008-04-28.
  2. ^ "Certification Report for SUSE Linux Enterprise Server 9" (PDF). Archived from the original (PDF) on 2015-09-23. Retrieved 2008-04-28.
  3. ^ "SUSE Linux Enterprise Server 10 EAL4 Certificate". Archived from the original on 2008-05-22. Retrieved 2008-04-28.
  4. ^ "Red Hat Enterprise Linux Version 5 EAL4 Certificate". Archived from the original on 2007-06-19. Retrieved 2007-06-16.
  5. ^ "Red Hat Customer Portal".
  6. ^ a b Windows Platform Products Awarded Common Criteria EAL 4 Certification Archived 2006-04-20 at the Wayback Machine
  7. ^ Myers, Tim. "Windows Vista and Windows Server 2008 are Common Criteria Certified at EAL4+". Microsoft. Retrieved May 15, 2013.
  8. ^ "National Information Assurance Partnership Common Criteria Evaluation and Validation Scheme" (PDF). Archived from the original (PDF) on March 27, 2014. Retrieved May 15, 2013.
  9. ^ a b Microsoft Windows 7, Windows Server 2008 R2 and SQL Server 2008 SP2 Now Certified as Common Criteria Validated Products
  10. ^ "SUSE Linux Enterprise Server 15 SP2" (PDF). Common Criteria Portal. Retrieved 9 September 2022.
  11. ^ Solaris 10 Release 11/06 Trusted Extensions EAL 4+ Certification Report
  12. ^ "VMware Common Criteria Evaluation & Validation (CCEVS)". Retrieved 2019-01-27.
  13. ^ IBM System z Security; IBM System z partitioning achieves highest certification
  14. ^ "Certifications ANSSI - ProvenCore" (PDF). Archived from the original (PDF) on 2022-12-04.
  15. ^ "Certifications - Fox-IT". Archived from the original on 2020-09-23.

Read other articles:

Lourdes Osuna Lourdes Osuna en el Europeo de Viena (1984).Datos personalesNombre completo Lourdes Osuna AlcalayaApodo(s) Luli OsunaNacimiento España España, Madrid18 de febrero de 1969(54 años)Nacionalidad(es) EspañolaCarrera deportivaDeporte Gimnasia rítmicaClub RetiradaSelección España EspañaTrayectoria Club Gimnasio Moscardó Selección nacional de España[editar datos en Wikidata] Lourdes Osuna Alcalaya (Madrid, 18 de febrero de 1969) es una ex gimnasta …

NumbersPoster promosiHangul넘버스: 빌딩숲의 감시자들 Arti harfiahNumbers: Building Forest's SurveillantAlih AksaraNeombeoseu: Bildingsup-ui Gamsijadeul GenreTempat kerja[1]Ditulis olehJung An[2]Oh Hye-seok[2]SutradaraKim Chil-bong[2]PemeranKim Myung-sooChoi Jin-hyukChoi Min-sooYeonwooNegara asalKorea SelatanBahasa asliKoreaProduksiRumah produksiTiger Studio[2]A2Z Entertainment[2]RilisJaringan asliMBC TVPranala luarSitus web Numbers (Hang…

Raúl Eduardo Baglini Diputado de la Nación Argentinapor la provincia de Mendoza 10 de diciembre de 1983-10 de diciembre de 1993 Senador de la Nación Argentinapor la provincia de Mendoza 10 de diciembre de 2001-10 de diciembre de 2003Predecesor José GenoudSucesor Ernesto Sanz Información personalNacimiento 23 de diciembre de 1949Mendoza, ArgentinaFallecimiento 3 de enero de 2021 (71 años)Mendoza, ArgentinaNacionalidad ArgentinaEducaciónEducado en Universidad Nacional de CórdobaInform…

معين نابة (محلة) تقسيم إداري البلد  اليمن المحافظة محافظة إب المديرية مديرية حبيش العزلة عزلة صائر القرية قرية صائر السكان التعداد السكاني 2004 السكان 111   • الذكور 39   • الإناث 72   • عدد الأسر 18   • عدد المساكن 18 معلومات أخرى التوقيت توقيت اليمن (+3 غرينيتش) تعديل مصد…

Pour les articles homonymes, voir Dimension. Si ce bandeau n'est plus pertinent, retirez-le. Cliquez ici pour en savoir plus. Cet article a besoin d’être illustré (en discuter) (septembre 2023). Pour améliorer cet article, des animations sous licence libre ou du domaine public sont les bienvenus. Si vous êtes l’auteur d’un média que vous souhaitez partager, importez-le. Si vous n’êtes pas l’auteur, vous pouvez néanmoins faire une demande de libération d’image à son auteur. E…

  لمعانٍ أخرى، طالع جورج ويت (توضيح). هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (يوليو 2019) جورج ويت معلومات شخصية الميلاد 9 نوفمبر 1933  لونغ بيتش، كاليفورنيا  الوفاة 30 يناير 2013 (79 سنة)   لاغونا بيتش، أورا

Rufino Martínez Intendente de Brandsen 1913-1913Predecesor Ezequiel Llera AchavalSucesor José María Berazategui 1907-1911Predecesor Pastor BanegasSucesor José Maril 1904-1905Predecesor Pastor BanegasSucesor Pastor Banegas 1901-1903Predecesor Modesto VeraSucesor Pastor Banegas 1896-1899Predecesor Silverio IzetaSucesor Modesto Vera Comisionado de Brandsen 1885-1886Predecesor Agustín BerutiSucesor Raymundo Borda Información personalNombre de nacimiento Rufino Modesto MartínezNacimiento 1859B…

Kardinalswappen von Joseph Schröffer Joseph Martin Kardinal Schröffer (* 20. Februar 1903 in Ingolstadt; † 7. September 1983 in Nürnberg) war Bischof von Eichstätt, später Kurienerzbischof der römisch-katholischen Kirche und Kardinaldiakon mit der Titeldiakonie San Saba. Leben Schröffer wurde 1903 in Ingolstadt geboren, wo er zusammen mit seinen vier jüngeren Schwestern aufwuchs und 1917 an das Bischöfliche Knabenseminar in Eichstätt wechselte. Bereits 1921, im Jahr vor seinem Abitur…

كاتشوكافالو   بلد المنشأ إيطاليا  المكونات الرئيسية حليب بقر،  وحليب الغنم  تعديل مصدري - تعديل   كَجيُكَفلَّة أو كَجيُكَفلَّو أو كاتشوكافالو (بالإيطالية: Caciocavallo)‏ هي نوع من الأجبان ممدودة التخثر تصنع من حليب الأغنام أو البقر.[1][2][3] يتم إنتاجها في جم

Disambiguazione – Se stai cercando il videogioco, vedi X-Men le origini - Wolverine (videogioco). X-Men le origini - WolverineWolverine (Hugh Jackman) in una scena del filmTitolo originaleX-Men Origins: Wolverine Lingua originaleinglese Paese di produzioneStati Uniti d'America, Nuova Zelanda, Australia Anno2009 Durata107 min Rapporto2,35:1 Genereazione, fantascienza, fantastico, avventura RegiaGavin Hood SceneggiaturaDavid Benioff, Skip Woods ProduttoreHugh Jackman, John Pa…

U.S. House districts in the state of Hawaii Hawaii's congressional districts since 2023 The U.S. state of Hawaii is divided into two congressional districts for representation in the United States House of Representatives. Before statehood, the Territory of Hawaii was represented by a non-voting delegate. From statehood until 1963, Hawaii had one representative. From 1963 to the creation of the two districts in 1971, Hawaii was represented in the House with two representatives elected at-large s…

Dalam artikel ini, nama keluarganya adalah Ahn. Ahn Sol-binLahirAhn Sol-bin19 Agustus 1997 (umur 26)Seongnam, Provinsi Gyeonggi, Korea SelatanNama lainAn Sol-binSolbinPendidikanSeoul Institute of the ArtsPekerjaanPenyanyiaktrismodelAgenGlobal HKeluargaAhn Sang-mun (ayah)Karier musikGenreK-popInstrumenVokalTahun aktif2014–sekarangArtis terkaitLaboumNama KoreaHangul안솔빈 Hanja安率濱 Alih AksaraAn Sol-binMcCune–ReischauerAn Solpin Ahn Sol-bin (bahasa Korea: 안솔빈), lebi…

Tren de Ferrosur en Veracruz, México. La Bestia (también conocido como El tren de la muerte) es el nombre de una red de trenes de carga que transportan combustibles, materiales y otros insumos por las vías férreas de México, también usado como medio de transporte por migrantes, principalmente de El Salvador, Honduras, Guatemala, Venezuela, Cuba y Haití, entre otros, que buscan llegar a Estados Unidos. Los puntos de acceso a la ruta de La Bestia desde la frontera sur de México eran Tenosi…

Billy Duffy Información personalNacimiento 12 de mayo de 1961 (62 años)Mánchester (Reino Unido) Nacionalidad InglesaInformación profesionalOcupación Guitarrista, compositorAños activo desde 1979Género Hard rock Instrumento Guitarra Discográfica Virgin Music Sitio web www.billyduffy.comPerfil de jugadorEquipos Hollywood United F.C. [editar datos en Wikidata] William Henry Billy Duffy (nacido el 12 de mayo de 1961, Hulme, Mánchester[1]​) es un guitarrista y compositor…

2013 filmPrison Terminal: The Last Days of Private Jack HallDirected byEdgar BarensProduced byEdgar BarensEdited byGeof Bartz and Gladys Mae MurphyMusic byMax RichterDistributed byThe Cinema GuildRelease date 2013 (2013) Running time40 minutes Prison Terminal: The Last Days of Private Jack Hall is a 2013 documentary film by Edgar Barens. Synopsis This film tells the story of Jack Hall, a terminally ill octogenarian lifer at Iowa State Penitentiary. The film looks at the last six months of J…

Bundesamt für Umwelt BAFU Hauptsitz Ittigen Vorsteherin Katrin Schneeberger Aufsicht Eidgenössisches Departement für Umwelt, Verkehr, Energie und Kommunikation UVEK Webpräsenz bafu.admin.ch Hauptsitz an der Worblentalstrasse 68 in Ittigen Gebäude an der Monbijoustrasse 40 in Bern (seit 2022) Gebäude an der Papiermühlestrasse 172 (bis Frühjahr 2022) Das Bundesamt für Umwelt (BAFU, französisch Office fédéral de l’environnement OFEV, italienisch Ufficio federale dell’ambiente UFAM, …

Chinese microblogging website Tencent WeiboType of sitemicrobloggingAvailable inChinese, EnglishDissolvedSeptember 28, 2020; 3 years ago (2020-09-28)OwnerTencent Holdings LtdURLt.qq.comCommercialYesLaunchedApril 1, 2010; 13 years ago (2010-04-01)Current statusDefunct Tencent WeiboSimplified Chinese腾讯微博Traditional Chinese騰訊微博TranscriptionsStandard MandarinHanyu PinyinTéngxùn WēibóBopomofoㄊㄥ˙ㄒㄩㄣ˙ㄨㄟ˙ㄅㄛ˙Wade…

Academic journalMichigan Law ReviewDisciplineLawLanguageEnglishEdited byDashaya ForemanPublication detailsHistory1902–presentPublisherUniversity of Michigan Law School (United States)FrequencyMonthlyImpact factor2.56 (2016)Standard abbreviationsISO 4 (alt) · Bluebook (alt1 · alt2)NLM (alt) · MathSciNet (alt )BluebookMich. L. Rev.ISO 4Mich. Law Rev.IndexingCODEN (alt · alt2) · JSTOR (alt) · LCCN (alt)M…

Adherents of the Chaldean Catholic Church This article is about adherents of the Chaldean Catholic Church. For the church (seperatist) itself, see Chaldean Catholic Church. For all other Christian groups that have at times been called Chaldean, see Church of the East. This article contains too many or overly lengthy quotations. Please help summarize the quotations. Consider transferring direct quotations to Wikiquote or excerpts to Wikisource. (April 2022) Chaldean Catholicsܟܲܠܕܵܝܹ̈ܐ ܩ…

Peninsula in the northwest of Russia Kola PeninsulaRussian: Кольский полуостровKildin Sami: Куэлнэгк нёа̄рркKola Peninsula as a part of Murmansk OblastLocation of Murmansk Oblast within RussiaGeographyLocationNorthwest RussiaCoordinates67°41′18″N 35°56′38″E / 67.68833°N 35.94389°E / 67.68833; 35.94389Adjacent to Barents Sea White Sea Area100,000 km2 (39,000 sq mi)Length370 km (230 mi)Width244 km (1…

Kembali kehalaman sebelumnya

Lokasi Pengunjung: 3.138.113.68