stason.org logo lotus


previous page: 44  What does it mean for a product to be "in evaluation"? (Computer Security Evaluation)page up: Computer Security Evaluation FAQnext page: 46  What and where is the Evaluated Products List (EPL)? (Computer Security Evaluation)

45 What does it mean for a product to be "compliant" with the TCSEC? (Computer Security Evaluation)

 Books
 TULARC
















Description

This article is from the Computer Security Evaluation FAQ, by Trusted Product Evaluation Program TPEP@dockmaster.ncsc.mil.

45 What does it mean for a product to be "compliant" with the TCSEC? (Computer Security Evaluation)

If a product has been evaluated by the Trusted Product
Evaluation Program (TPEP) to comply with the requirements of a
rated class, then it means that an independent assessment
showed the product to have the features and assurances of that
class. It does not mean that the product is impenetrable. It
is even possible that the independent assessment overlooked
some failure to meet the criteria, although we expend a lot of
energy attempting to prevent that. A vendor claim to be
"compliant" without an evaluation often doesn't mean very much
since the vendor's interpretation of the requirement may not be
the same as an independent assessor's would be.

 

Continue to:


Share and Enjoy

Bookmark this story so others can enjoy it:
  • digg
  • Reddit
  • del.icio.us
  • Furl
  • Wists

Tags

computer security, evaluation, TREP, Trusted Product Evaluation Program, Federal Criteria, hacker-proof







TOP
previous page: 44  What does it mean for a product to be "in evaluation"? (Computer Security Evaluation)page up: Computer Security Evaluation FAQnext page: 46  What and where is the Evaluated Products List (EPL)? (Computer Security Evaluation)