© crown copyright (2000) module 3.2 evaluation management

27
© Crown Copyright (2000) Module 3.2 Evaluation Management

Upload: ella-regan

Post on 28-Mar-2015

221 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: © Crown Copyright (2000) Module 3.2 Evaluation Management

© Crown Copyright (2000)

Module 3.2

Evaluation Management

Page 2: © Crown Copyright (2000) Module 3.2 Evaluation Management

“You Are Here”

M3.1 Evaluation Process

M3.2 Evaluation Management

MODULE 3 - SCHEME RULES AND PROCEDURES

Page 3: © Crown Copyright (2000) Module 3.2 Evaluation Management

Evaluation Management

PreparationPhase

Conduct Phase

ConclusionPhase

Page 4: © Crown Copyright (2000) Module 3.2 Evaluation Management

Evaluation Management

PreparationPhase

Conduct Phase

ConclusionPhase

Page 5: © Crown Copyright (2000) Module 3.2 Evaluation Management

Preparation Phase - Inputs

• Definition of Target of Evaluation– Scope, boundaries, interfaces, composites, etc.

• What evaluation level is required ?

• Technical expertise required ?

Evaluation

PlanningTOE

Page 6: © Crown Copyright (2000) Module 3.2 Evaluation Management

Preparation Phase - Suitability

• CLEF/CB may review ST for suitability

• Check Sponsor and Developer have full understanding of:– the evaluation process– the role of the CLEF– their responsibilities throughout evaluation

Page 7: © Crown Copyright (2000) Module 3.2 Evaluation Management

Preparation Phase - TIN

• May be combined with EWP• Task Identification• Sponsor and Developer Details• Description of TOE• Summary of Security Requirements• Timescales• Staffing• Contacts

Page 8: © Crown Copyright (2000) Module 3.2 Evaluation Management

Preparation Phase - EWP

• May be combined with TIN

• Evaluation methodology– CEM/ITSEC– Interpretations

• Evaluation effort for each activity

• Constraints

• Limitations

Page 9: © Crown Copyright (2000) Module 3.2 Evaluation Management

Preparation Phase - UKSP06 Entry & CB Questionnaire

UKSP06

Page 10: © Crown Copyright (2000) Module 3.2 Evaluation Management

Task Start-up Meeting

• Objective

• Attendees

• Timing

• Agenda

Page 11: © Crown Copyright (2000) Module 3.2 Evaluation Management

Preparation Phase - Outputs

Evaluation

Planning

EWP

TIN

UKSP 06 Entry

Security Target

CB Questionnaire

Page 12: © Crown Copyright (2000) Module 3.2 Evaluation Management

Evaluation Management

PreparationPhase

Conduct Phase

ConclusionPhase

Page 13: © Crown Copyright (2000) Module 3.2 Evaluation Management

Conduct Phase - Inputs

Task Conduct

TIN / EWP

TOE Deliverables

Security Target

Deliverables Schedule

Page 14: © Crown Copyright (2000) Module 3.2 Evaluation Management

Conduct Phase - Reporting Progress

• Evaluation Progress Meeting (EPM)

• ETR Production– Draft annexes (activity reports, glossary, list of

deliverables etc.)

• Observation Report Status Register

Page 15: © Crown Copyright (2000) Module 3.2 Evaluation Management

Evaluation Progress Meetings

• Objective

• Attendees

• Timing

• Agenda

Page 16: © Crown Copyright (2000) Module 3.2 Evaluation Management

Observation Report Status - 1

• AGR - Corrective Action Agreed

• CAP - Certifier Action Pending

• CLR - Cleared

• FIX - Fix to be evaluated by CLEF

• ISS - Issued to the Certifier

Page 17: © Crown Copyright (2000) Module 3.2 Evaluation Management

Observation Report Status - 2

• PRO - Corrective Action Proposed

• REJ - Corrective Action Rejected

• REL - Released to the Sponsor / Developer

• WDN - Problem Report Withdrawn

Page 18: © Crown Copyright (2000) Module 3.2 Evaluation Management

Conduct Phase - Observation Reports

• Content (Level 1 and Level 2)– Identifier– Severity Level– Evaluation Activity where raised– Observation– Organisation responsible for resolution– Timescale for resolution

Page 19: © Crown Copyright (2000) Module 3.2 Evaluation Management

Conduct Phase - Issues

• Maintain Independence

• Comply with UKAS Requirements

• Comply with Methodology Requirements

Page 20: © Crown Copyright (2000) Module 3.2 Evaluation Management

Conduct Phase - Outputs

Task Conduct

Work Package Reports

Observation Reports

Scheme ObservationReports

Page 21: © Crown Copyright (2000) Module 3.2 Evaluation Management

Evaluation Management

PreparationPhase

Conduct Phase

ConclusionPhase

Page 22: © Crown Copyright (2000) Module 3.2 Evaluation Management

Conclusion Phase

• Evaluation Technical Report (ETR)

• Certificate and Certification Report

• Task Closedown

Page 23: © Crown Copyright (2000) Module 3.2 Evaluation Management

Assurance Maintenance (CMS)

• Additional Evaluation Task

• See Module 2.8 for more details

Page 24: © Crown Copyright (2000) Module 3.2 Evaluation Management

ITSEC v. CC

• Main difference is work breakdown

• ITSEM/UK SP 05 specify mandatory requirements

• CEM defines Work Units

Page 25: © Crown Copyright (2000) Module 3.2 Evaluation Management

Summary

• Three Phases to evaluation Management– Preparation Phase– Conduct Phase– Conclusion Phase

• Covers whole evaluation

• Terminology difference between ITSEC & CC

Page 26: © Crown Copyright (2000) Module 3.2 Evaluation Management

Further Reading

• UKSP 01

• UKSP 04 Part 1

• UKSP 05 Part 1

• CEM Part 2, Chapter 2

Page 27: © Crown Copyright (2000) Module 3.2 Evaluation Management

Exercise - Planning

• Given the ITT on the handouts, please prepare a TIN and EWP for the task