Top Banner
Russian IT Security Certification Scheme: Steps Toward Common Criteria Approach Alexander Barabanov, Alexey Markov, Valentin Tsirlov
25

Barabanov iccc 2014 (2)

Jun 16, 2015

Download

Presentation from International Common Criteria Conference-2014
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Barabanov  iccc 2014 (2)

Russian IT Security Certification Scheme: Steps TowardCommon Criteria Approach

Alexander Barabanov, Alexey Markov, Valentin Tsirlov

Page 2: Barabanov  iccc 2014 (2)

Agenda

2

Brief overview Current status of the Russian IT Security

Certification Scheme Steps Toward Common Criteria Approach Final Remarks

Page 3: Barabanov  iccc 2014 (2)

Brief overview:Historical Perspective

3

1995

Establishment of Russian IT Security

Certification Scheme

1997

Mandatory requirements for

firewall and access control systems

1999 2003

Guidance based on CC v.2.1

Mandatory requirements for

IPS/IDS(based on CC)

Mandatory requirements for

antiviruses (based on CC)

Mandatory requirements for

source code analysis

2012 2013

Page 4: Barabanov  iccc 2014 (2)

Brief overview:who takes part in the certification process?

4

Page 5: Barabanov  iccc 2014 (2)

Brief overview: typical timeline

5

Obtaining FSTEC ID

Normally 1 monthEvaluation provided by Laboratory

3-4 monthsCertification by Certification Body

1 month and more – there may be delays:

- for solutions that will be used for protection of classified information;

- If a state-owned Certification authority was chosen by FSTEC

Obtaining a certificate from FSTEC of Russia

Normally 1 month

Page 6: Barabanov  iccc 2014 (2)

Brief overview:Accredited Evaluation Laboratories

6

Page 7: Barabanov  iccc 2014 (2)

Brief overview:Accredited Certification Bodies

7

Page 8: Barabanov  iccc 2014 (2)

Brief overview:Classical Major Approaches to Evaluation

8

Evaluation of the security functionality

• Black box testing to ensure that TOE works as it should

Evaluation for the absence of non-declared functions• Testing of source code for the absence of software

vulnerabilities

Page 9: Barabanov  iccc 2014 (2)

Current status of the Russian Scheme: Products

9

Page 10: Barabanov  iccc 2014 (2)

Current status of the Russian Scheme: Certified Products by Types (1)

10

2011-2013 Evaluation Timeline

Page 11: Barabanov  iccc 2014 (2)

Current status of the Russian Scheme: Certified Products by Types (2)

11

Page 12: Barabanov  iccc 2014 (2)

Current status of the Russian Scheme:Russian vs. Non-Russian Developers

12

Page 14: Barabanov  iccc 2014 (2)

Current status of the Russian Scheme: Non-Russian Developers (2)

14

2011-2013 Evaluation Timeline

Page 15: Barabanov  iccc 2014 (2)

Current status of the Russian Scheme:Russian Developers

15

2011-2013 Evaluation Timeline

Page 16: Barabanov  iccc 2014 (2)

Steps Toward Common Criteria Approach:Step #1 (1)

16

Page 17: Barabanov  iccc 2014 (2)

Steps Toward Common Criteria Approach:Step #1 (2)

17

Page 18: Barabanov  iccc 2014 (2)

Steps Toward Common Criteria Approach:Step #1 (3)

18

2003-2013 Evaluation Timeline

Page 19: Barabanov  iccc 2014 (2)

Steps Toward Common Criteria Approach:Step #2 (1)

19

Page 20: Barabanov  iccc 2014 (2)

Steps Toward Common Criteria Approach:Step #2 (2)

20

Page 21: Barabanov  iccc 2014 (2)

Steps Toward Common Criteria Approach:Certified Products, Russian

21

TOE Developer Approved PP

Kaspersky Endpoint Security

Kaspersky Lab. Host IDS, Antivirus, Security Level 2

Kaspersky Antivirus for Novell NetWare

Kaspersky Lab. Antivirus, Security Level 2

Security Studio Endpoint Protection

Security Code Host IDS, Antivirus, Security Level 4 (~ EAL3+)

Kaspersky Security Center

Kaspersky Lab. Antivirus, Security Level 2

Continent 3.7 Security Code Network IDS, Security Level 3

Page 22: Barabanov  iccc 2014 (2)

Steps Toward Common Criteria Approach:Certified Products, Non-Russian

22

TOE Developer Approved PP

Deep Security 8.0 Trend Micro Host IDS, Antivirus, Security Level 4 (~ EAL3+)

McAfee NSP 7.1 McAfee Network IDS,Security Level 5 (~ EAL2+)

Office Scan 10.6 Trend Micro Host IDS, Antivirus, Security Level 4 (~ EAL3+)

McAfee Web Gateway 7.4

McAfee Antivirus, Security Level 5 (~ EAL2+)

Page 23: Barabanov  iccc 2014 (2)

Final Remarks

23

1. First certifications according to the new requirements are certifications of non-Russian products.

2. More and more leading non-Russian developers provide the Russian Evaluations Laboratories with access to their source code, and this tendency shall be observed in future.

3. Efficiency in detection of vulnerabilities in software submitted for certification will enhance.

4. Russian developers will pay more for certification.5. The number of actively working Evaluations Laboratories

will reduce.

Page 24: Barabanov  iccc 2014 (2)

Contact Information

24

Alexander Barabanov, CISSP, CSSLPHead of Certification and Testing DepartmentNPO [email protected]

Alexey Markov, Ph.D, CISSPCEO of NPO [email protected]

Valentin Tsirlov, Ph.D, CISSP, CISMExecutive Director of NPO [email protected]

Page 25: Barabanov  iccc 2014 (2)

25

Thank you for your attention!