Common Criteria - Information Technology Security Evaluation

Common Criteria (CC) is a set of standards designeda hierarchical system for determining security levels.
to establish an effective way of determining the levelBased on the similarities and differences of TCSEC
of security of a Target of Evaluation (TOE). Theseand ITSEC and the global need for IT security, it was
standards were established by a multi-national boardnecessary to agree upon a standardized multi-national
of IT security groups. In coalition with many groups thatclass set to ensure assurance and compatibility across
are responsible for national standards, the CC wasmany nations, thus inspiring the design and
able to take form, some of these groups criterionimplementation of the Common Criteria.
include:The purpose of the Common Criteria is to establish a
Trusted Computer System Evaluation Criteriasingle set of IT security criteria for global use. The
(TCSEC)- These standards represent the criteriapurpose was also to resolve the conceptual and
needed, and trusted by the United States companiestechnical differences found in the different criteria and
and businesses to ensure security of a TOE. Thedeliver the results to ISO as a proposed standard.
approach in these criteria is based on a security levelCommon Criteria was the product of multinational
classification.corporation. The globalization of this standard saves
Information Technology Security Evaluation Criteriatime and money because it eliminates the need for
(TCSEC)- Like its North American Counterpart, thesemultiple evaluations when doing international business.
sets of standards were designed for classifying theCommon Criteria focuses on security objectives and
security levels of a TOE, limited to European countries.the related threats.
Unlike TCSEC, ITSEC set of standards makes use of