Материал: Крючков Фундаменталс оф Нуцлеар Материалс Пхысицал Протецтион 2011

Внимание! Если размещение файла нарушает Ваши авторские права, то обязательно сообщите нам

8.4.3. Common Criteria for Technology Security Evaluation

The Common Criteria (the Common Criteria for Information Technology Security Evaluation) was the result of the consistent efforts undertaken to develop IT security evaluation criteria that was subsequently accepted internationally.

The Trusted Computer Systems Evaluation Criteria (TCSEC) was developed in the USA in the early 1980s. In the decade that followed, different countries initiated the development of evaluation criteria that was based on its concepts but offered more flexibility and adaptability in the context of IT evolution.

Thus, in 1991, the European Commission published the Information Technology Security Evaluation Criteria (ITSEC) developed collaboratively by France, Germany, the Netherlands and Great Britain. The Canadian Trusted Computer Product Evaluation Criteria was developed in Canada in early 1993. It was also then that a draft standard, the Federal Criteria for Information Technology Security, was published in the USA.

In 1990, the International Standardization Organization (ISO) began to develop an international standard of generic evaluation criteria. The new criteria were intended to meet the demand for the mutual acceptance of the standardized security evaluation results in the international market of information technologies. In June 1993, the consolidated efforts of the national criteria developers led to the initiation of a joint program on harmonization of varied criteria and establishment of a unified collection of security criteria.

The early version of the Common Criteria was finalized in January 1996 and approved in April 1996 for circulation as the committee’s draft criteria. A number of experimental evaluations followed with steps undertaken to have the document broadly discussed in public. Later on, the document was revised extensively, as part of the Common Criteria project, based on the experience of its experimental application. The later version was released in May 1998. Version 2.1 of this standard was approved in 1999 by the ISO as an international information security standard (ISO/IEC 15408). Some countries nowadays require their information systems, critical in terms of national security, to be certified to the CC.

On 27 March 2003, the State Technical Commission under the President of Russia unveiled a program to introduce the international information security standard. Russia began introducing the standard practically unaltered, having divided this into three State Standards (GOST) indexed

396

collectively as ISO/IEC 15408–2002. The new GOST se ries was put into operation in Russia on 1 January 2004.

Let us familiarize in brief with the new standard. The standard as such is complex and bulky. It consists of three parts with the overall volume of about 600 pages.

Part 1 of the standard contains the IT security evaluation methodology and defines the types of security requirements (both functional and confidence ones) and the basic formats (protection profile, security job) to present security requirements in the interests of three user categories: consumers, developers and appraisers of IT products and systems. The evaluation object (EO) security requirements under the Common Criteria methodology are defined depending on security objectives, which, in turn, are based on analyzing secured information resources, and the EO function and application environment (threats, statements, security policy).

Part 2 of the standard contains a versatile specifically arranged catalog of functional security requirements and enables regulated detailing and expansion thereof.

Part 3 of the standard contains a systemized catalog of confidence requirements that define the measures to be taken at all lifecycle stages of an IT product or system to make sure that these satisfy to the functional security requirements imposed thereon. This part also contains evaluation levels of confidence representing standardized collections of requirements that enable an increasingly complete and stringent evaluation of design, testing and operating documentation, and correctness of the security complex operation, as well as assessment of the IT product or system vulnerability and the stability of security features.

As its content suggests, the Common Criteria is a methodological document that contains a well arranged and structured collection of requirements, their presentation forms and the definition methodology. Using these criteria, security for different IT products is evaluated not as stringently and uniformly as Gostekhkomissiya’s effective documents require, but given the functions, types and application environments of IT products and systems with a flexible approach to generation of respective security requirements in protection profiles enabled. The CC-based security profiles may additionally include any other valid requirements needed to ensure security of a particular IT product type.

As evidenced by information security expert estimates, the Common Criteria excels other current standards in the systematization, completeness and detailing level of requirements, as well as in versatility and flexibility of applications.

397

It should be noted that the International Agreement applies only to the acceptance of evaluation results for IT products and systems intended to process confidential information (up to the confidence level of EAL 4 inclusively) and does not deal with issues of evaluating products and systems designed to handle national security information in the member countries of the International Agreement. Still, the methodology of the Common Criteria can be used by and for the sake of the parties concerned.

Since January 2001 the USA has been evaluating IT security exclusively based on the Common Criteria, while the leading European countries (Germany, Finland and others) have some 40% of their recently developed IT products evaluated also under the Common Criteria with only CC-based evaluations applied to newly emerging products.

A directive, No. 140-23, was issued in May 2000 by the US National Security Agency, which made it mandatory for the US Department of Defense and its public and private contractors to use only CC-certified IT products and systems for handling classified information.

The directive also applies to privately owned nuclear power plants in the USA where special roles are assigned to the Common Criteria in evaluating security of information technologies employed in critical systems.

All this gives evidence of the emphasis placed internationally on information security issues and of the CC approaches and methods becoming increasingly attractive as a tool to resolve these.

In the run-up to the introduction of the new standard in Russia, the Comments on the Russian Standards were developed by “Atomzashchitainform” Center, TsNIIatominform and t he Information Security Center (ISC). These had the purpose of giving Russian experts a more in-depth understanding of the objective, basic concepts, methodology and terminology of the Common Criteria as well as clarifying discrepancies between the standard’s terminology and the terminology accepted in Russia and the effective regulatory documents.

The underlying associated document issued to support the Common Criteria, which is mandatory for use in the framework of the above International Agreement, is the General Methodology for Evaluating Security of Information Technologies currently being revised by an expert team of a number of the member-countries to the International Agreement. At present time, based on an authentic translation of the relevant General Methodology version by an expert team of the ISC, “Atomzashchitainform” and TsNIIatominform, involvin g the CC international work unit, the methodology for evaluation of IT products and systems is developed.

398

The standard introduction program also stipulates:

∙development of the concept to ensure security of information technologies (the draft was prepared by the ISC and submitted to Gostekhkomissiya of Russia);

∙development of the guide to develop protection profiles and security jobs (the draft was prepared by the ISC and submitted to Gostekhkomissiya of Russia);

∙development of the guide to register protection profiles based on the ISO/IEC 15292 international standard (the draft was prepared by the ISC and submitted to Gostekhkomissya of Russia);

∙creation of a system of tools for automated development of protection profiles and security jobs (presently developed by the ISC);

∙development of protection profiles for the basic types of IT products and systems: operating systems, database management systems, fire walls, virtual private networks and others (some organizations, including the ISC, TsNIIAtominform and MEPhI, develop security profiles for IT products and systems for various applications; one example is a protection profile of security class II developed by TsNIIatominform for automated NM A&C systems);

∙development of model techniques for certification tests of IT products and systems based on the General Methodology of Evaluation;

∙certification tests of some IT products and systems, including operating systems (specifically, the Windows family).

The said activities have the purpose of not only introducing the GOST State Standard R ISO/EMC 15408–2002 “Information Te chnologies Security Evaluation Criteria”, but also taking Russ ia closer to joining the International Agreement as a country with a CC-based certification system.

As mentioned hereinabove, Rosatom of Russia is also considering evaluation and certification of software products used in NM A&C systems based on the Common Criteria requirements. This obviously requires development of a protection profile for systems of security class III and the security jobs to which the software products chosen for these functions to be certified. The solution of these issues will determine the perfection of effective and development of new NM A&C systems, as well as the operation of the Federal Nuclear Material Accounting and Control Information System.

It is a belief with Russian experts involved in implementing the Common Criteria methodology that, if put into operation, the Russian standard, the General Methodology of Evaluation and other regulatory and

399

methodological documents to support these, as well as practical use of the Common Criteria methodology will make it possible to:

∙reach the state of the art in the criteria and procedural framework for evaluation of information technologies;

∙create a new generation of interagency and departmental regulatory and procedural documents to evaluate IT security on a uniform basis;

∙provide users and developers of IT products with a highly efficient tool for formulating requirements to IT security and building information protection systems;

∙enable users to assess objectively the capability of information security IT products;

∙give users and developers of computerized systems of various levels and functions the capability to provide, accordingly, more valid formulation and implementation of information security requirements for these systems;

∙take Russia closer to joining the International Agreement, which will, in turn, enable:

–users and developers of IT systems to cut product certification costs;

–consumers to expand the market of certified produ cts;

–testing laboratories to attract extra inflows of orders for certification from abroad;

–Russian makers of high-tech products to obtain in ternational certificates in Russia, which will give them a share in the earlier inaccessible foreign markets.

For all that, Russia (as well as other parties to the mutual certificate acceptance agreement) retains the right to make allowances for its national requirements in certification of IT products and systems, primarily, those for protection of national security information.

This, however, entails a great deal of efforts to take for the Common Criteria and the General Evaluation Methodology to be put into practice of requirement formulation and IT security evaluation, as well as for Russian IT security terminology and standards to be harmonized with international standards, specifically the ISO/IEC 15408–99 standa rd, with a view to the entry of Russian testing laboratories (centers) and certification authorities, as well as of Russian products certified to the Common Criteria methodology, to the international market of products and services.

This requires the solution of the whole range of technical, organizational and financial issues relating:

400

Источник: https://studfile.net/preview/16708779/