Cargando…

A survey on common criteria (CC) evaluating schemes for security assessment of IT products

Over the last few years, private and public organizations have suffered an increasing number of cyber-attacks owing to excessive exploitation of technological vulnerabilities. The major objective of these attacks is to gain illegal profits by extorting organizations which adversely impact their norm...

Descripción completa

Detalles Bibliográficos
Autores principales: Fatima, Maheen, Abbas, Haider, Yaqoob, Tahreem, Shafqat, Narmeen, Ahmad, Zarmeen, Zeeshan, Raja, Muhammad, Zia, Rana, Tauseef, Mussiraliyeva, Shynar
Formato: Online Artículo Texto
Lenguaje:English
Publicado: PeerJ Inc. 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8576545/
https://www.ncbi.nlm.nih.gov/pubmed/34805499
http://dx.doi.org/10.7717/peerj-cs.701
_version_ 1784595898166149120
author Fatima, Maheen
Abbas, Haider
Yaqoob, Tahreem
Shafqat, Narmeen
Ahmad, Zarmeen
Zeeshan, Raja
Muhammad, Zia
Rana, Tauseef
Mussiraliyeva, Shynar
author_facet Fatima, Maheen
Abbas, Haider
Yaqoob, Tahreem
Shafqat, Narmeen
Ahmad, Zarmeen
Zeeshan, Raja
Muhammad, Zia
Rana, Tauseef
Mussiraliyeva, Shynar
author_sort Fatima, Maheen
collection PubMed
description Over the last few years, private and public organizations have suffered an increasing number of cyber-attacks owing to excessive exploitation of technological vulnerabilities. The major objective of these attacks is to gain illegal profits by extorting organizations which adversely impact their normal operations and reputation. To mitigate the proliferation of attacks, it is significant for manufacturers to evaluate their IT products through a set of security-related functional and assurance requirements. Common Criteria (CC) is a well-recognized international standard, focusing on ensuring security functionalities of an IT product along with the special emphasis on IS design and life-cycle. Apart from this, it provides a list of assurance classes, families, component, and elements based on which security EALs can be assigned to IT products. In this survey, we have provided a quick overview of the CC followed by the analysis of country-specific implementation of CC schemes to develop an understanding of critical factors. These factors play a significant role by providing assistance in IT products evaluation in accordance with CC. To serve this purpose, a comprehensive comparative analysis of four schemes belonging to countries including US, UK, Netherlands, and Singapore has been conducted. This comparison has aided to propose best practices for realizing an efficient and new CC scheme for the countries which have not designed it yet and for improving the existing CC schemes. Finally, we conclude the paper by providing some future directions regarding automation of the CC evaluation process.
format Online
Article
Text
id pubmed-8576545
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher PeerJ Inc.
record_format MEDLINE/PubMed
spelling pubmed-85765452021-11-19 A survey on common criteria (CC) evaluating schemes for security assessment of IT products Fatima, Maheen Abbas, Haider Yaqoob, Tahreem Shafqat, Narmeen Ahmad, Zarmeen Zeeshan, Raja Muhammad, Zia Rana, Tauseef Mussiraliyeva, Shynar PeerJ Comput Sci Computer Education Over the last few years, private and public organizations have suffered an increasing number of cyber-attacks owing to excessive exploitation of technological vulnerabilities. The major objective of these attacks is to gain illegal profits by extorting organizations which adversely impact their normal operations and reputation. To mitigate the proliferation of attacks, it is significant for manufacturers to evaluate their IT products through a set of security-related functional and assurance requirements. Common Criteria (CC) is a well-recognized international standard, focusing on ensuring security functionalities of an IT product along with the special emphasis on IS design and life-cycle. Apart from this, it provides a list of assurance classes, families, component, and elements based on which security EALs can be assigned to IT products. In this survey, we have provided a quick overview of the CC followed by the analysis of country-specific implementation of CC schemes to develop an understanding of critical factors. These factors play a significant role by providing assistance in IT products evaluation in accordance with CC. To serve this purpose, a comprehensive comparative analysis of four schemes belonging to countries including US, UK, Netherlands, and Singapore has been conducted. This comparison has aided to propose best practices for realizing an efficient and new CC scheme for the countries which have not designed it yet and for improving the existing CC schemes. Finally, we conclude the paper by providing some future directions regarding automation of the CC evaluation process. PeerJ Inc. 2021-10-26 /pmc/articles/PMC8576545/ /pubmed/34805499 http://dx.doi.org/10.7717/peerj-cs.701 Text en © 2021 Fatima et al. https://creativecommons.org/licenses/by/4.0/This is an open access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, reproduction and adaptation in any medium and for any purpose provided that it is properly attributed. For attribution, the original author(s), title, publication source (PeerJ Computer Science) and either DOI or URL of the article must be cited.
spellingShingle Computer Education
Fatima, Maheen
Abbas, Haider
Yaqoob, Tahreem
Shafqat, Narmeen
Ahmad, Zarmeen
Zeeshan, Raja
Muhammad, Zia
Rana, Tauseef
Mussiraliyeva, Shynar
A survey on common criteria (CC) evaluating schemes for security assessment of IT products
title A survey on common criteria (CC) evaluating schemes for security assessment of IT products
title_full A survey on common criteria (CC) evaluating schemes for security assessment of IT products
title_fullStr A survey on common criteria (CC) evaluating schemes for security assessment of IT products
title_full_unstemmed A survey on common criteria (CC) evaluating schemes for security assessment of IT products
title_short A survey on common criteria (CC) evaluating schemes for security assessment of IT products
title_sort survey on common criteria (cc) evaluating schemes for security assessment of it products
topic Computer Education
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8576545/
https://www.ncbi.nlm.nih.gov/pubmed/34805499
http://dx.doi.org/10.7717/peerj-cs.701
work_keys_str_mv AT fatimamaheen asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT abbashaider asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT yaqoobtahreem asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT shafqatnarmeen asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT ahmadzarmeen asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT zeeshanraja asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT muhammadzia asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT ranatauseef asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT mussiraliyevashynar asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT fatimamaheen surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT abbashaider surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT yaqoobtahreem surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT shafqatnarmeen surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT ahmadzarmeen surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT zeeshanraja surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT muhammadzia surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT ranatauseef surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts
AT mussiraliyevashynar surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts