President and COO of Sun Federal Bill Vass' Weblog

Friday Jul 25, 2008

I want to be sure to recognize the Solaris & TX engineering team and some key members of the field organization
(especially Steve Gaul, John Totah, John Weeks + others) for their tireless efforts, in guiding Solaris TX through this certification process. Special thanks to Kathy Jenks' team and Jane Medefesser for all their hard work on TX and support in moving this forward...this is just the beginning for TX!

Also, thanks to Matt Hatley, who correctly pointed out to me that my statement: "Evaluation Assurance Level (EAL) 4+, the highest recognized global security certification." is not correct. See the table and information he provided below:

Common Criteria and EAL - Terms, CC Evaluation Assurance Levels (EAL)

EAL1 Functionally Tested
EAL2 Structurally Tested
EAL3 Methodically Tested and Verified
EAL4 Methodically Designed, Tested and Verified
EAL5 Semi-formally Designed and Tested
EAL6 Semi-formally Verified Design and Tested
EAL7 Formally Verified Design and Tested

More info on Common Criteria is available here...
http://www.niap-ccevs.org/cc-scheme http://www.commoncriteriaportal.org

However, I believe that the protection profile used to get this level of certification was the strongest and most aggressive of any other operating system achieving this level of certification.

It's always important to look at the protection profile that was used to achieve a level of certification, and not just the number of the level. For example, some operating systems say they have achieved (EAL) 4+, but when you look at the detail of the protection profile, they achieved it WITHOUT being connected to a network. It's pretty simple to have an OS be secure when it's not connected to a network :-)

So what I should have said was "Achieved (EAL) 4+ with the strongest protection profile of any operating system given a rating of level 4.

Tags

Bill Vass' blog

Sun Blogs

Technorati

Del.icio.us



Comments:

As a note, anything above EAL 4 is actually NOT mutually recognized by all the member countries of the Common Criteria. That is, tests conducted at EAL 5 and above ARE recognized as such in the county in which the test was done, but are essentially only recognized as an EAL 4 by all other countries that are a part of the Common Criteria agreement. So, yes, EAL 4 is the highest mutually recognized Assurance Level.
And, my congratulations to the Trusted Extensions (TX) team for pursuing the most complete evaluation of a modern OS against Common Criteria evaluation since the original Trusted Solaris product line !

Posted by Mark Thacker on July 31, 2008 at 10:10 PM EDT #

Post a Comment:
Comments are closed for this entry.