<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Certification Process Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://sitdev.corsec.com/tag/certification-process-zh-hans/feed/" rel="self" type="application/rss+xml" />
	<link>https://sitdev.corsec.com/tag/certification-process-zh-hans/?lang=zh-hans</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL / UC APL.</description>
	<lastBuildDate>Mon, 07 Feb 2022 19:52:46 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>

<image>
	<url>https://sitdev.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Certification Process Archives - Corsec Security, Inc.®</title>
	<link>https://sitdev.corsec.com/tag/certification-process-zh-hans/?lang=zh-hans</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Further Automation Within The CMVP</title>
		<link>https://sitdev.corsec.com/cmvp-automation/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 29 Apr 2021 15:03:39 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=18854</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>The Cryptographic Module Validation Program (CMVP) is a part of the National Institute of Standards and Technology (NIST) which operates under the Department of Commerce.  The CMVP&#8217;s role is to promote the use of validated cryptographic modules and provide Federal agencies with a security metric to use in procuring equipment containing validated cryptographic modules, this primarily occurs through management and oversight of the testing required as part of the <a href="https://sitdev.corsec.com/fips-140-2/"><span style="color: #339966;">FIPS 140-2</span></a> / <a href="https://sitdev.corsec.com/fips-140-3/"><span style="color: #339966;">FIPS 140-3</span></a> validation standards.</p>
<p>The CMVP is currently experiencing longer than usual evaluation periods within the <a href="https://sitdev.corsec.com/fips-140-3/"><span style="color: #339966;">FIPS 140</span></a> programs. To rectify and hopefully assist in shortening those wait times, the CMVP is looking to automate processes and procedures related to the evaluation and testing of these cryptographic modules.</p>
<p>To support this newly identified objective, the CMVP has developed a <span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.nccoe.nist.gov/sites/default/files/library/project-descriptions/cmvp-project-description-draft.pdf">draft document</a></span> which outlines assumptions, challenges, current architectures, requirements, and guidance.  The ultimate goal is to identify ideas and recommendations on how to automate some of the more tedious and manual elements of the <a href="https://sitdev.corsec.com/fips-140-3/"><span style="color: #339966;">FIPS 140</span></a> evaluation process.  Specifically stating they hope to improve efficiencies and timelines within CMVP operations.</p>
<p>Some of the current challenges outlined include:</p>
<ul>
<li>An increase in complex modules being evaluated</li>
<li>A lack of human resources to address the influx in evaluations</li>
<li>Insufficient information/documentation submissions</li>
<li>Operating Environment Updates</li>
</ul>
<p>This is not the first time the CMVP has turned to automation, as they recently implemented a change to the methods for testing algorithms within the Cryptographic Algorithm Validation Program (CAVP). Read more about that transition <span style="color: #3366ff;"><a style="color: #3366ff;" href="https://sitdev.corsec.com/algorithm-automation/">here</a></span>.</p>
<p>Although the effects of such an effort are not expected to make an impact in the near term, it is a positive sign that the CMVP is actively trying to improve things in the long run.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5><span style="color: #000000;"><strong>Need Support?</strong></span></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://sitdev.corsec.com/contact-us/">Contact Corsec</a></span> to ask questions, discuss a project, or gain more insight on this post.</p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;">Press Contact:</strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FED ROUNDUP: JULY 2019</title>
		<link>https://sitdev.corsec.com/fed-july19/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 31 Jul 2019 18:07:31 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/fed-july19/</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.disa.mil/NewsandEvents/2019/DISA-awards-SETI">DISA Awards SETI IDIQ to 23 Small Businesses</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.disa.mil/NewsandEvents/2019/DISA-new-strategic-plan">DISA Releases 4 Year Strategic Plan</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><span style="color: #3366ff;">None</span></li>
</ul>
<h5 style="padding-left: 30px;">Releases &amp; Special Publications:</h5>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/1800-17/final">SP 1800-17, Multifactor Authentication for E-Commerce: Risk-Based, FIDO Universal Second Factor Implementations for Purchasers</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/nist-publishes-sp-800-133-revision-1" data-csrc-pub-link="true" data-pub-guid="ef6e6155-b91a-4790-9dc8-ad5e44d1c3ce">SP 800-133 Revision 1, Recommendation for Cryptographic Key Generation</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/NIST-Releases-Draft-SP-1800-21-for-Comment">Draft SP 1800-21, Mobile Device Security: Corporate-Owned Personally-Enabled (COPE)</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/NCCoE-Releases-Draft-SP-1800-16-for-Comment" data-csrc-pub-link="true" data-pub-guid="dcda17a4-1b55-471c-9aea-dc6d1177187e">Draft SP 1800-16, <em>Securing Web Transactions: Transport Layer Security (TLS) Server Certificate Management</em></a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/draft-white-paper-emerging-blockchain-idms">Draft Cybersecurity White Paper, </a><em><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/white-paper/2019/07/09/a-taxonomic-approach-to-understanding-emerging-blockchain-idms/draft">A Taxonomic Approach to Understanding Emerging Blockchain Identity Management Systems (IDMS)</a></em></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/nist-releases-draft-sp-800-175B-rev-1-for-comment" data-csrc-pub-link="true" data-pub-guid="c793169f-7918-4ba8-9545-70d826cf0068">Draft SP 800-175B Revision 1, <em>Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms</em></a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/NIST-Releases-Draft-SP-800-77-Rev-1-for-Comment" data-csrc-pub-link="true" data-pub-guid="fc004568-b730-473b-9d71-69d672e34095">SP 800-77 Revision 1, <em>Guide to IPsec VPNs</em></a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates:</h5>
<ul>
<li><span style="color: #3366ff;">None</span></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li>Peripheral Sharing Device (PSD) Protection Profile (PP), Version 4.0 and its five associated PP-Modules:<br />
1.) PP-Module for Audio Input Devices, Version 1.0<br />
2.) PP-Module for Analog Audio Output Devices, Version 1.0<br />
3.) PP-Module for Keyboard/Mouse Devices, Version 1.0<br />
4.) PP-Module for User Authentication Devices, Version 1.0<br />
5.) PP-Module for Video/Display Devices, Version 1.0</li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FED ROUNDUP: JUNE 2019</title>
		<link>https://sitdev.corsec.com/fed-june19/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Fri, 28 Jun 2019 13:11:36 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=17919</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA’s June News</a></strong></h5>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.disa.mil/NewsandEvents/2019/reduces-DITCO-contracting-fee">DITCO, DISA&#8217;s contracting arm, reduces its enterprise acquisition services fee</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST’s June News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/Open-Security-Controls-Assessment-Language-Milesto">NIST announces Open Security Controls Assessment Language (OSCAL), Version 1.0.0 &#8211; Milestone 1 has been released</a></span></li>
</ul>
<h5 style="padding-left: 30px;">Releases &amp; Special Publications:</h5>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/nist-publishes-nistir-8228">NIST Interagency/Internal Report 8228, &#8220;Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks.&#8221;</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/NCCoE-Releases-Data-Confidentiality-Draft-Project">NCCoE has posted two draft data confidentiality project descriptions</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/draft-sp-800-171-rev-2-and-sp-800-171b">Draft SP 800-171 Rev. 2 and SP 800-171B</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/nist-publishes-sp-800-205">SP 800-205, &#8220;Attribute Considerations for Access Control Systems.&#8221;</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/NCCoE-Draft-Project-Descriptions-for-SMBs-and-Manu">NCCoE drafts two Project Descriptions for SMBs and Manufactures</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/draft-white-paper-on-ssdf">Draft White Paper &#8220;Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF)&#8221;</a></span></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/News/2019/nist-publishes-nistir-8221">NISTIR 8221, &#8220;A Methodology for Enabling Forensic Analysis Using Hypervisor Vulnerabilities Data.&#8221;</a></span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP’s June News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates:</h5>
<ul>
<li><span style="color: #3366ff;">None</span></li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li><span style="color: #3366ff;">None</span></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <span style="color: #0000ff;"><a style="color: #0000ff;" href="http://marketing.corsec.com/Subscribe-Email.html">Subscribe</a></span></p>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FIPS 140-3 APPROVED</title>
		<link>https://sitdev.corsec.com/fips-140-3-approved/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 01 May 2019 15:52:00 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[federal regulation]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/fips-140-3-approved/</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>A <a id="" href="https://www.federalregister.gov/documents/2019/05/01/2019-08817/announcing-issuance-of-federal-information-processing-standard-fips-140-3-security-requirements-for" target="_blank" rel="noopener noreferrer">Federal Register Notice</a> has been issued for the &#8220;Federal Information Processing Standard (<span style="color: #008000;"><a id="" style="color: #008000;" title="FIPS 140" href="https://csrc.nist.gov/publications/detail/fips/140/3/final" target="_blank" rel="noopener noreferrer">FIPS</a></span>) 140-3, Security Requirements for Cryptographic Modules&#8221;.</p>
<p>Having now been signed by the U.S. Commerce Secretary, it is official, FIPS 140-3 has been approved!</p>
<p style="padding-left: 40px;"><em>&#8220;This notice announces the Secretary of Commerce&#8217;s issuance of Federal Information Processing Standard (FIPS) 140-3, Security Requirements for Cryptographic Modules. <span style="color: #008000;">FIPS 140-3</span> includes references to two existing international standards: International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 19790:2012(E) Information technology — Security techniques — Security requirements for cryptographic modules, and ISO/IEC 24759:2017(E) Information technology — Security techniques — Test requirements for cryptographic modules. As permitted by those standards, NIST Special Publication (SP) series 800-140 will specify updates, replacements, or additions to the currently-cited ISO/IEC standard, as necessary. Those new SP 800-140 documents (currently under development) will consolidate implementation guidance and administrative guidance, and will be made available for public review and comment.&#8221;</em></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>Key Dates:</strong></p>
<p>Companies actively working on or planning a FIPS validation will inevitably face decisions around which standard to work towards. The following dates will be critical for those projects:</p>
<ul>
<li><span style="color: #339966;">Draft For Comments: Complete</span></li>
<li><span style="color: #339966;">Effective Date: Complete</span></li>
<li><span style="color: #339966;">Publication of the Standard: Complete</span></li>
<li><span style="color: #339966;">Supporting Documents for FIPS 140-2 &amp; the CMVP Released: Complete</span></li>
<li>New Testing Begins: 9/22/20</li>
<li>140-3 Mandated &amp; The Last Day for 140-2 Submissions: 9/22/21 (This means Labs must submit their Lab reports to CMVP by this date)</li>
</ul>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><b>Documentation:</b></p>
<p>CMVP wants to minimize the content in the series of NIST SP 800-140 documents because they hope to be as close to the international standard as possible. These are the documents that we believe will replace the existing FIPS 140-2 DTR, Appendices, and Annexes:</p>
<ul>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140/final">NIST SP 800-140</a></span> – <em>FIPS 140-3 Derived Test Requirements</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140a/final">NIST SP 800-140A</a></span> – <em>CMVP Documentation Requirements</em></li>
<li><a href="https://csrc.nist.gov/publications/detail/sp/800-140b/final"><span style="color: #3366ff;">NIST SP 800-140B</span></a> – <em>CMVP Security Policy Requirements</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140c/final">NIST SP 800-140C</a> </span>– <em>CMVP Approved Security Functions</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140d/final">NIST SP 800-140D</a> </span>– <em>CMVP Approved Sensitive Security Parameter Generation and Establishment Methods</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140e/final">NIST SP 800-140E</a></span> – <em>CMVP Approved Authentication Mechanisms</em></li>
<li><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://csrc.nist.gov/publications/detail/sp/800-140f/final">NIST SP 800-140F</a></span> – <em>CMVP Approved Non-Invasive Attack Mitigation Test Metrics</em></li>
</ul>
<p>A notable omission from the new SP 800-140 series is any reference document for Approved Protection Profiles from Common Criteria (a CC-certified operating system was required for software validations at level 2 and above).</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><b>Early Review and Analysis:</b></p>
<p>This release has been a long time coming. We still expect additional updates and changes to come, but Corsec has reviewed the public documents and found the following areas to be of interest:</p>
<ul>
<li>Rather than encompassing the module requirements directly, FIPS 140-3 references ISO/IEC 19790:2012. The testing for these requirements will be in accordance with ISO/IEC 24759:2017</li>
<li>This version of FIPS 140-3 retains the 4 levels of validation</li>
<li>The sections in FIPS 140-3 are now as follows:
<ol>
<li>Cryptographic Module Specification</li>
<li>Cryptographic Module Interfaces</li>
<li>Roles, Services, And Authentication</li>
<li>Software/Firmware Security</li>
<li>Operating Environment</li>
<li>Physical Security</li>
<li>Non-Invasive Security</li>
<li>Sensitive Security Parameter Management*</li>
<li>Self-Tests</li>
<li>Life-Cycle Assurance</li>
<li>Mitigation of Other Attacks</li>
</ol>
</li>
</ul>
<p style="padding-left: 80px;"><strong>*</strong>Sensitive Security Parameters is a new category &#8211; SSPs include both CSPs and PSPs (Public Security Parameters)</p>
<p style="padding-left: 80px;"><strong>**</strong>Finite State Model was removed but may have been absorbed into section 11</p>
<p style="padding-left: 80px;"><strong>***</strong>EMI/EMC was removed. There was no mention of EMI/EMC in the draft ISO 24759 either</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p><strong>Moving Forward:</strong></p>
<ol>
<li>Get Ahead: Be the first to complete the new standard (<span style="color: #008000;"><a style="color: #008000;" href="https://csrc.nist.gov/publications/detail/fips/140/3/final">FIPS 140-3</a></span>)</li>
<li>Revalidate Early: Avoid the new requirements prior to the mandated transition date and add 5 years to your current <span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> validation</li>
<li>Plan Accordingly &#8211; Products being evaluated against FIPS 140-2 during testing transition may face problems completing their certification under old requirements.</li>
</ol>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>Corsec participates in numerous committees, technical working groups, certification leadership positions, and industry events. As more information develops, we will deliver updates. Stay informed on all the program details, requirements, and timelines associated with FIPS 140-3 – <a href="https://ww3.corsec.com/subscribe">Subscribe</a></p>
<p>For more information on the current <span style="color: #008000;"><a style="color: #008000;" href="https://sitdev.corsec.com/fips-140-2/">FIPS 140-2</a></span> program, requirements, and process &#8211; <a href="https://sitdev.corsec.com/fips-140-2/">visit here</a>.</p>
<p>For any questions on how this will affect current or future FIPS projects, <a href="https://sitdev.corsec.com/contact-us/">contact Corsec</a>!</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p style="text-align: center;">###</p>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p><strong>Jake Nelson</strong><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>
</div>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5 class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img loading="lazy" decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="auto, (max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></h5>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Security Certification Maintenance</title>
		<link>https://sitdev.corsec.com/security-certification-maintenance/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 07 Dec 2016 20:16:07 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[reevaluation]]></category>
		<category><![CDATA[Revalidation]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/security-certification-maintenance/</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>As you release new versions of previously certified and validated products, it is crucial that you develop a security certification maintenance plan to keep up with the evolution of your technology. Corsec’s Maintenance and Compliance Service helps you determine whether a full re-evaluation is necessary, or if you can pursue other measures to continue generating revenue from your initial certification or validation.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><strong>Security Certification Maintenance:</strong></h5>
<p>Each security certification has its own unique requirements for maintenance and renewal. Corsec’s engineering team helps you understand the specific actions you will need to take for each of their products and certifications.</p>
<p><a href="https://sitdev.corsec.com/fips-140-2/?lang=zh-hans"><span style="color: #008000;">FIPS 140-2</span></a><br />
The FIPS 140-2 validation process lists five change scenarios that are used to determine if a product requires revalidation, or if documentation alone can address the changes at issue. Corsec will help determine which scenario mostly closely aligns to the latest version of your product.</p>
<p><a href="https://sitdev.corsec.com/c%e6%b1%87mm%e6%b1%87n-cr%e8%af%8d%e7%9a%84%e5%8c%85r%e8%af%8d%e8%af%b7/?lang=zh-hans"><span style="color: #ff6600;">Common Criteria</span></a><br />
Common Criteria determines re-evaluation through a process called Assurance Continuity (AC). If major changes have occurred in the security environment, evidence needs to be submitted to a laboratory and the product needs to be re-evaluated. If minor changes have occurred, a vendor can perform “Assurance Maintenance,” a report that is attached as an addendum to the original product certification, as long as it is within two years of the initial issuance date.</p>
<p><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://sitdev.corsec.com/dodin-apl/?lang=zh-hans">DoDIN APL</a></span><br />
In order to maintain a listing on the DoDIN APL, you must complete a Desktop Review (DR) for each major product version. In such a review, a high-level assessment determines whether the product listing will simply be updated with the new version identifier, whether minimal testing must be performed on the new version prior to receiving an updated listing, or whether the product must undergo a new evaluation in its entirety.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<h5><strong>Keep Products Market-Ready</strong></h5>
<p>Corsec helps ensure that our partners continue to benefit from the efforts they put in initially to get their products certified or validated. If you have questions on the requirements around your products’ recertification or revalidation, we can help determine the best path forward with little to no disruption of your revenue stream.</p>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Common Criteria Schemes: Tips for Making the Right Choice</title>
		<link>https://sitdev.corsec.com/common-criteria-schemes-tips-for-making-the-right-choice/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 29 Aug 2013 13:25:37 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/common-criteria-schemes-tips-for-making-the-right-choice/</guid>

					<description><![CDATA[So many decisions, so little time. You’ve heard—and likely experienced—this mantra. And if you read this blog regularly, you’ve probably picked up on the fact that security validations involve making a whole host of decisions. When pursuing Common Criteria certification, one often perplexing, yet critical decision I hear people lament...]]></description>
										<content:encoded><![CDATA[<p>So many decisions, so little time. You’ve heard—and likely experienced—this mantra. And if you read this blog regularly, you’ve probably picked up on the fact that security validations involve making a whole host of decisions. When <a href="/?p=6496" target="_blank" rel="noopener noreferrer">pursuing Common Criteria certification</a>, one often perplexing, yet critical decision I hear people lament about is how to choose the best scheme for your product or system.</p>
<p>As you start out on the path to Common Criteria certification, the decisions that factor into your journey affect not only how long it takes to achieve certified status but also <a href="/?p=6500" target="_blank" rel="noopener noreferrer">how much it costs</a>—and how many times you reach for an aspirin throughout the process.<span id="more-1943"></span></p>
<p>So let’s start first with the basics to get us all on the same page. Why <a href="https://sitdev.corsec.com/c%e6%b1%87mm%e6%b1%87n-cr%e8%af%8d%e7%9a%84%e5%8c%85r%e8%af%8d%e8%af%b7/?lang=zh-hans" target="_blank" rel="noopener noreferrer">Common Criteria</a>? First and foremost, national government agencies are required to purchase security products that have obtained Common Criteria certification, if and when they exist. Second, we need to define the meaning of a certification scheme. Put simply, it’s an official government entity charged with ensuring the security of all government and military acquisitions. And in terms of Common Criteria, the scheme is responsible for making sure that all commercial off-the-shelf (COTS) products evaluated in that particular country have been evaluated consistently and independently according to Common Criteria requirements. Testing labs perform the actual product evaluations, and must be certified through a scheme. The scheme oversees and performs accreditations of testing labs, and is responsible for the issuance of certificates in that country.</p>
<p>Sixteen recognized government schemes for Common Criteria exist in the world today and include the following countries: the United States, Canada, Australia, France, Germany, Italy, Japan, Malaysia, Netherlands, New Zealand, Norway, the Republic of Korea, Spain, Sweden, Turkey, and the United Kingdom.</p>
<p>It stands to reason that if you’re a security product vendor in the United States, you would opt for the U.S. scheme. And if you’re a company in the United Kingdom, you’d go with the UK scheme. It’s important to realize, however, that choosing a scheme outside your home country sometimes makes the most sense. So let’s take a closer look at the variables you need to consider.</p>
<p><strong>Important Considerations</strong></p>
<p><i>Inclusion in NIAP PCL</i><br />
If you are looking to be included in the National Information Assurance Product Compliant List (NIAP PCL) in the United States, then work with the U.S., Canadian, UK, or Australian scheme. These schemes have the most experience with the criteria it takes to gain NIAP PCL approval. However, keep in mind that if an evaluation is done outside of the U.S., NIAP imposes partial technical oversight for a portion of the evaluation.</p>
<p>And keep in mind that while NIAP states that you must use NIAP-approved PPs in order to be placed on the PCL, there are not PPs for all products so you are not actually <i>required</i> to conform to a PP. At some point this will, however, likely become a requirement.</p>
<p>Before you make a decision about the NIAP PCL and an associated PP, make sure you know the facts. And if you’re working with an outside consultant on your Common Criteria certification, talk to them about PCL.</p>
<p><i>Protection Profiles<br />
</i>Does your product conform to a protection profile (PP) for a particular country? All schemes can handle PPs, but the U.S. and Canadian schemes have the most experience with U.S.-approved PPs. In the case of PPs released by other countries, the scheme in the country that publishes a particular PP typically has the most experience.</p>
<p><i>Evaluation Assurance Levels<br />
</i>If you require an assurance level higher than EAL2, either for competitive reasons or because the agency that wants to acquire your product has dictated a higher level, then consider a scheme in Spain, Sweden, or Germany. The U.S., Canada, Australia, New Zealand and UK do not handle anything higher than EAL2.</p>
<p><i>Agency preference<br />
</i>If you’re working with an agency that requires or prefers evaluations to be performed in the same country, then start there—in that country.</p>
<p><i>CAPS certification<br />
</i>CAPS (CESG Assisted Products Service) is a certification exclusive to the UK government market, so if you also require CAPS certification, you must also use the UK scheme for your Common Criteria certification.</p>
<p><i>Assurance Continuity<br />
</i>Assurance Continuity, a reevaluation that takes place after changes to a certified Target of Evaluation or its environment, must be performed through the scheme that originally certified the product for Common Criteria. This makes the scheme you choose even more important because you’re establishing an on-going relationship.</p>
<p><i>Your Customer Base<br />
</i>Most schemes require that you prove that you have customers in their country. Canada, for instance, requires a letter from a Canadian customer as proof, while other countries may just ask for a statement from your company. Keep this in mind when taking schemes into consideration.</p>
<p>When you consider not only the time and cost involved but also the reason you want to pursue certification in the first place, Common Criteria is an important undertaking that can affect your revenue substantially. The decision you make regarding the scheme you select will no doubt impact next year’s bottom line.</p>
<p>For help sifting through the options and choosing the right Common Criteria scheme for your objectives and product, <a href="http://sitdev.corsec.com/contact-us/" target="_blank" rel="noopener noreferrer">contact us today</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why You Need Common Criteria Certification and How to Get There</title>
		<link>https://sitdev.corsec.com/why-you-need-common-criteria-certification-and-how-to-get-there/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 20 Jun 2013 14:38:53 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/why-you-need-common-criteria-certification-and-how-to-get-there/</guid>

					<description><![CDATA[In the IT security industry, research and development teams continually race to introduce new products, while at the same time, project teams improve upon existing offerings—all scrambling to ensure that the latest versions meet security functional and assurance requirements. The goal is to bring the strongest and most secure...]]></description>
										<content:encoded><![CDATA[<p>In the IT security industry, research and development teams continually race to introduce new products, while at the same time, project teams improve upon existing offerings—all scrambling to ensure that the latest versions meet security functional and assurance requirements. The goal is to bring the strongest and most secure products to market.</p>
<p>If you’re in the business of producing IT security products, you should know that attaining <a href="https://sitdev.corsec.com/c%e6%b1%87mm%e6%b1%87n-cr%e8%af%8d%e7%9a%84%e5%8c%85r%e8%af%8d%e8%af%b7/?lang=zh-hans">Common Criteria</a> certification is critical to your business for some very good reasons, for example:</p>
<p><strong>It opens the door to the government market</strong>.<i> </i>All IT security products purchased by the U.S. government for national security systems are required to have <a href="https://sitdev.corsec.com/c%e6%b1%87mm%e6%b1%87n-cr%e8%af%8d%e7%9a%84%e5%8c%85r%e8%af%8d%e8%af%b7/?lang=zh-hans">Common Criteria</a> certification. Many government agencies, especially the DoD, write <a href="https://sitdev.corsec.com/c%e6%b1%87mm%e6%b1%87n-cr%e8%af%8d%e7%9a%84%e5%8c%85r%e8%af%8d%e8%af%b7/?lang=zh-hans">Common Criteria</a> certification into their RFPs.<span id="more-1729"></span></p>
<p><strong>Certification helps you stay competitive</strong>.<i> </i>You must have <a href="https://sitdev.corsec.com/c%e6%b1%87mm%e6%b1%87n-cr%e8%af%8d%e7%9a%84%e5%8c%85r%e8%af%8d%e8%af%b7/?lang=zh-hans">Common Criteria</a> certification if you want to compete against established players who have already been evaluated. This is true not only when selling into the government sector, but also for commercial clients like banks and financial institutions.</p>
<p><strong>Common Criteria helps you improve on the security of your product</strong>. Think of the <a href="https://sitdev.corsec.com/c%e6%b1%87mm%e6%b1%87n-cr%e8%af%8d%e7%9a%84%e5%8c%85r%e8%af%8d%e8%af%b7/?lang=zh-hans">Common Criteria</a> evaluation as the litmus test of your team’s success in developing the product’s security against the appropriate Protection Profile. The Common Criteria certification process may uncover hidden vulnerabilities before you go to market, saving you from having to make costly corrections in the field.</p>
<p><strong>The road to Common Criteria success</strong></p>
<p>When you’re ready to pursue certification, an IT security consultant can make the entire process easier and more cost effective. Make sure your partner has a process that they can describe in detail to guide you through certification to ensure that everything goes smoothly—setbacks can cost not only time but also money. Adhering to this plan can help you ramp up and get underway quickly, and will ensure that you <a href="http://sitdev.corsec.com/2013/05/budgeting-for-common-criteria-avoid-cost-creep/">stick to your budget</a> and shorten your evaluation time. Corsec’s process includes these steps:</p>
<p>Begin with an <strong>education about the Common Criteria</strong> process and an understanding of the sequence of events so that you can schedule time and resources accordingly. Corsec provides customers with a custom compliance report including a blueprint for successful certification—make sure that your partner offers documentation that gives you an understanding of what the process will entail and cost before you actually get started.</p>
<p>With a certification plan in place, you’ll then determine which <strong>Protection Profiles</strong> you will be validated against, so you can make certain your product meets the requirements specified in the appropriate Protection Profile or Profiles.</p>
<p>Preparation of documentation is a big part of certification. First, you’ll <strong>develop a Security Target </strong>that provides information about how your product or system meets requirements. A Security Target contains a statement of the requirements to which a specific product or system under evaluation must conform, written to be implementation dependent. A Security Target can be authored to conform to a specific Protection Profile or it can simply state the security functional requirements that your product offers and the assurance levels for the evaluation.</p>
<p>Once that’s done, your team must produce all <strong>assurance documentation</strong> necessary for submission to the testing lab. It is vital that you have clear, complete documentation, as this is one area where many Common Criteria certifications grind to a halt. Having someone on your team who’s experienced in this type of documentation prep will save you time and costly delays.</p>
<p>The next step is to submit your product and associated documentation to an <strong>accredited testing laboratory</strong>. The choice you make regarding the lab you’ll work with is really important because different testing labs have different experience levels with particular standards and schemes, different styles of communicating with customers, and different pricing models. Your consulting partner’s relationships will be critical here. Assuming you’ve chosen a good partner to work with, the last step in the process should be “<strong>receive certification!</strong>”</p>
<p>While Common Criteria certification isn’t a simple process, it’s much easier with an experienced consultant to guide you. Corsec has completed hundreds of certifications for clients. <a href="http://corsec.com/company/contact-us/" target="_blank" rel="noopener noreferrer">Find out</a> how we can help you.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Content Delivery Network via cdn.corsec.com

Served from: sitdev.corsec.com @ 2026-05-30 22:26:47 by W3 Total Cache
-->