On TV.com: BATTLESTAR Galactica Maxim Photoshoot
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 38 of 54:
Next »
« Previous
Hopefully the buyers know
Apparantly, Common Criteria is the replacement for several separately developed security classification schemes, including Orange Book. If your system met Orange Book criteria, you knew that information could not leak out very quickly and there were audit trails in place. But suppliers didn't know exactly how to meet the criteria because the book was classified!! From what I understand, auditors told suppliers that they could fix deficiencies by adding or doing certain things in the system; suppliers weren't told exactly why. (Of course, the auditors represented the same folks as the customers, i.e., military or related users.)

With CC EAL1 thru 7, the criteria appear to be more in the open. From skimming the "Common Criteria User Guide," it appears that each successive level involves increasing strict testing. But since products don't conform to the same API, it is unclear how you get an objective standard. (Not a criticism; in my neophyte mind, I just don't understand.) Hopefully the buyers really know what they are buying.

In particular, EAL4 means "methodically designed, tested and reviewed."
Posted by: asky   Posted on: 10/20/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

So Bit..  Jeff Spicoli | 10/20/04
They are not using Trustworthy Computing?  theo_durcan | 10/20/04
Because Trusted Computing is untrustworthy.  Root User | 10/20/04
hit the nail on the head  V Sanders | 10/21/04
Now THAT's an oxy-moron :-))))'s  kensys | 10/21/04
Won't be long  htotten | 10/20/04
Dept of Redundancy Department  ejhonda | 10/20/04
Security depends on the threat.  Root User | 10/20/04
Redundancy IS security.  mobrien_12@... | 10/20/04
Secure Linux = Oxymoron (NT)  Loverock Davidson | 10/20/04
Loverock = straight up moron  Jeff Spicoli | 10/20/04
Translation: Loverock just escaped from the hospital. (NT)  Vily Clay | 10/20/04
secure linux  FilledOut | 10/20/04
You must be joking.  mobrien_12@... | 10/20/04
No  Linux User 147560 | 10/20/04
keep it in house  htotten | 10/20/04
Precisely  mobrien_12@... | 10/20/04
They answer to the same boss in the  Linux User 147560 | 10/20/04
RTFS  htotten | 10/20/04
Yes and that  Linux User 147560 | 10/20/04
okay, walk in and ask for it  FilledOut | 10/20/04
Source availability  Yagotta B. Kidding | 10/20/04
SELinux  Roger Ramjet | 10/21/04
We'll Special K  FilledOut | 10/22/04
Many OSs (Windows, Solaris, HP-UX) on EAL 4 list  asky | 10/20/04
... and maybe, some day Linux  Anton Philidor | 10/20/04
Are you saying  Linux User 147560 | 10/20/04
EAL4  htotten | 10/20/04
A true advantage to knowing Linux.  Anton Philidor | 10/20/04
almost the same can be said for your beloved MS  Monkey_MCSE | 10/20/04
Using imagination  Anton Philidor | 10/20/04
Not much different  Linux User 147560 | 10/20/04
not to mention that SuSe Linux is already at level 3.  Monkey_MCSE | 10/20/04
i wouldn't say employee  Monkey_MCSE | 10/20/04
Early next year  Yagotta B. Kidding | 10/20/04
With all the resources being pumped into Linux by major governments ...  George Mitchell | 10/20/04
Exactly what does it take to get this rating?  mobrien_12@... | 10/20/04
Hopefully the buyers know  asky | 10/20/04
looks like government are trying to get away from  V Sanders | 10/21/04
If you noticed...  rapson | 10/21/04
are you saying  V Sanders | 10/21/04
Nope  rapson | 10/21/04
lol  V Sanders | 10/21/04
Hmmm  rapson | 10/21/04
you are right, gee silly me  V Sanders | 10/21/04
Why not Solaris x86?  Roger Ramjet | 10/21/04
good question  geekmule | 10/21/04
The usual crowd, the usual rants.  Linux_Developer | 10/21/04
Filled?  rapson | 10/21/04
here you are defending ms again  V Sanders | 10/21/04
Defending?  rapson | 10/21/04
It?s easier to say that somebody is bad than to show your good (NT)  Vily Clay | 10/21/04
Thanks for a very ?valuable? comment. Anything else? (NT)  Vily Clay | 10/21/04
"Minds can move mountains, but not closed minds  kensys | 10/21/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement
Click Here
  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More