Standardization and Security Criteria: Security Evaluation of Computer Products
摘要
Our growing dependence on technology and the corresponding skyrocketing security problems arising from it have all created a high demand for comprehensive security mechanisms and best practices to mitigate these security problems. Solutions on two fronts are sought for. First, well-implemented mechanisms and best practices are needed for fundamental security issues such as cryptography, authentication, access control, and audit. Second, comprehensive security mechanisms are also needed for all security products so that consumers are assured of products and systems that meet their business security needs. The response to this high demand for security products has been an avalanche of products of all types, capabilities, varying price range, effectiveness, and quality. As the market place for security products becomes saturated, competing product vendors and manufacturers make all sorts of claims about their products in order to gain a market niche. In this kind of environment then, how can a customer shop for the right secure product, what security measures should be used, and how does one evaluate the security claims made by the vendors? Along the way, choosing a good effective security product for your system or business has become a new security problem. This chapter focuses on two processes: standardization and security evaluation of products.