Cargando…
A survey on common criteria (CC) evaluating schemes for security assessment of IT products
Over the last few years, private and public organizations have suffered an increasing number of cyber-attacks owing to excessive exploitation of technological vulnerabilities. The major objective of these attacks is to gain illegal profits by extorting organizations which adversely impact their norm...
Autores principales: | , , , , , , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
PeerJ Inc.
2021
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8576545/ https://www.ncbi.nlm.nih.gov/pubmed/34805499 http://dx.doi.org/10.7717/peerj-cs.701 |
_version_ | 1784595898166149120 |
---|---|
author | Fatima, Maheen Abbas, Haider Yaqoob, Tahreem Shafqat, Narmeen Ahmad, Zarmeen Zeeshan, Raja Muhammad, Zia Rana, Tauseef Mussiraliyeva, Shynar |
author_facet | Fatima, Maheen Abbas, Haider Yaqoob, Tahreem Shafqat, Narmeen Ahmad, Zarmeen Zeeshan, Raja Muhammad, Zia Rana, Tauseef Mussiraliyeva, Shynar |
author_sort | Fatima, Maheen |
collection | PubMed |
description | Over the last few years, private and public organizations have suffered an increasing number of cyber-attacks owing to excessive exploitation of technological vulnerabilities. The major objective of these attacks is to gain illegal profits by extorting organizations which adversely impact their normal operations and reputation. To mitigate the proliferation of attacks, it is significant for manufacturers to evaluate their IT products through a set of security-related functional and assurance requirements. Common Criteria (CC) is a well-recognized international standard, focusing on ensuring security functionalities of an IT product along with the special emphasis on IS design and life-cycle. Apart from this, it provides a list of assurance classes, families, component, and elements based on which security EALs can be assigned to IT products. In this survey, we have provided a quick overview of the CC followed by the analysis of country-specific implementation of CC schemes to develop an understanding of critical factors. These factors play a significant role by providing assistance in IT products evaluation in accordance with CC. To serve this purpose, a comprehensive comparative analysis of four schemes belonging to countries including US, UK, Netherlands, and Singapore has been conducted. This comparison has aided to propose best practices for realizing an efficient and new CC scheme for the countries which have not designed it yet and for improving the existing CC schemes. Finally, we conclude the paper by providing some future directions regarding automation of the CC evaluation process. |
format | Online Article Text |
id | pubmed-8576545 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2021 |
publisher | PeerJ Inc. |
record_format | MEDLINE/PubMed |
spelling | pubmed-85765452021-11-19 A survey on common criteria (CC) evaluating schemes for security assessment of IT products Fatima, Maheen Abbas, Haider Yaqoob, Tahreem Shafqat, Narmeen Ahmad, Zarmeen Zeeshan, Raja Muhammad, Zia Rana, Tauseef Mussiraliyeva, Shynar PeerJ Comput Sci Computer Education Over the last few years, private and public organizations have suffered an increasing number of cyber-attacks owing to excessive exploitation of technological vulnerabilities. The major objective of these attacks is to gain illegal profits by extorting organizations which adversely impact their normal operations and reputation. To mitigate the proliferation of attacks, it is significant for manufacturers to evaluate their IT products through a set of security-related functional and assurance requirements. Common Criteria (CC) is a well-recognized international standard, focusing on ensuring security functionalities of an IT product along with the special emphasis on IS design and life-cycle. Apart from this, it provides a list of assurance classes, families, component, and elements based on which security EALs can be assigned to IT products. In this survey, we have provided a quick overview of the CC followed by the analysis of country-specific implementation of CC schemes to develop an understanding of critical factors. These factors play a significant role by providing assistance in IT products evaluation in accordance with CC. To serve this purpose, a comprehensive comparative analysis of four schemes belonging to countries including US, UK, Netherlands, and Singapore has been conducted. This comparison has aided to propose best practices for realizing an efficient and new CC scheme for the countries which have not designed it yet and for improving the existing CC schemes. Finally, we conclude the paper by providing some future directions regarding automation of the CC evaluation process. PeerJ Inc. 2021-10-26 /pmc/articles/PMC8576545/ /pubmed/34805499 http://dx.doi.org/10.7717/peerj-cs.701 Text en © 2021 Fatima et al. https://creativecommons.org/licenses/by/4.0/This is an open access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, reproduction and adaptation in any medium and for any purpose provided that it is properly attributed. For attribution, the original author(s), title, publication source (PeerJ Computer Science) and either DOI or URL of the article must be cited. |
spellingShingle | Computer Education Fatima, Maheen Abbas, Haider Yaqoob, Tahreem Shafqat, Narmeen Ahmad, Zarmeen Zeeshan, Raja Muhammad, Zia Rana, Tauseef Mussiraliyeva, Shynar A survey on common criteria (CC) evaluating schemes for security assessment of IT products |
title | A survey on common criteria (CC) evaluating schemes for security assessment of IT products |
title_full | A survey on common criteria (CC) evaluating schemes for security assessment of IT products |
title_fullStr | A survey on common criteria (CC) evaluating schemes for security assessment of IT products |
title_full_unstemmed | A survey on common criteria (CC) evaluating schemes for security assessment of IT products |
title_short | A survey on common criteria (CC) evaluating schemes for security assessment of IT products |
title_sort | survey on common criteria (cc) evaluating schemes for security assessment of it products |
topic | Computer Education |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8576545/ https://www.ncbi.nlm.nih.gov/pubmed/34805499 http://dx.doi.org/10.7717/peerj-cs.701 |
work_keys_str_mv | AT fatimamaheen asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT abbashaider asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT yaqoobtahreem asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT shafqatnarmeen asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT ahmadzarmeen asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT zeeshanraja asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT muhammadzia asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT ranatauseef asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT mussiraliyevashynar asurveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT fatimamaheen surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT abbashaider surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT yaqoobtahreem surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT shafqatnarmeen surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT ahmadzarmeen surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT zeeshanraja surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT muhammadzia surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT ranatauseef surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts AT mussiraliyevashynar surveyoncommoncriteriaccevaluatingschemesforsecurityassessmentofitproducts |