본문 바로가기
  • Home

Requirements and Processes of Vulnerability Assessment for IT Security Products in Common Criteria

  • Journal of Knowledge Information Technology and Systems
  • Abbr : JKITS
  • 2011, 6(2), pp.51-57
  • Publisher : Korea Knowledge Information Technology Society
  • Research Area : Interdisciplinary Studies > Interdisciplinary Research
  • Published : April 30, 2011

이지연 1 길민욱 2

1동남보건대학교
2문경대학교

Candidate

ABSTRACT

CC(Common Criteria) requires to collect vulnerability information and vulnerability analysis by using penetration testing for evaluating IT security products. However, CC has been criticized from developers or QA managers due to its complexity of terms, abstract description of evaluation methods and non-existence of guidelines. In this paper, we propose a guideline of vulnerability assessment for developers and evaluators by analyzing and summarizing of its requirements and processes defined in CC. To do this, we classify the evaluation process of AVA assurance family into 4 parts and describe each evaluation working systematically unit under every steps.

Citation status

* References for papers published after 2023 are currently being built.