Common Criteria certified open source software - fact or fiction?
نویسنده
چکیده
In 2012 the two open source projects CESeCore and EJBCA were Common Criteria certified [CCP], using open source tools and open source methodologies. As the actual software and its long term evolution is perhaps the most important result for most users, we will look at how certification, distribution and maintenance is managed. Can they be done in an open source way, and is certification always suitable? The Common Criteria for Information Technology Security Evaluation (Common Criteria) is a standard for IT security certification defined by ISO/IEC 15408 [WP]. The Common Criteria provides trust that processes for specification, implementation and evaluation has been performed in a rigorous and standardized way. Recognized world wide and governed by national certification bodies, Common Criteria is used as requirement for procurement and use of security software in governments, banks and enterprises. Common Criteria has been criticized for large costs and potential discrimination against Open Source Software [DW]. Given the rigorous system that Common Criteria enforces, how can open source software be certified, and maintained as certified? Drawbacks and benefits of a Common Criteria certification will be described, and how certification limits the maintenance of an open source project. Common Criteria certified open source software – fact or fiction? After this presentation software developers will be able to determine if their open source project is suitable for Common Criteria certification, whilst software users will have a good idea if they should require certification.
منابع مشابه
Using Iron-Chelating Agents in Critically Ill Patients with Iron Overload. Fact or Fiction?
Recently, some evidence has shown that the failure of iron homeostasis may occur in critically ill patients and can lead to iron overload. Elevated ferritin levels as a body iron burden index in critically ill patients may be associated with depressed level of consciousness and greater mortality. However, the necessity of using iron-chelating agents in clinical situation is still unknown for th...
متن کاملA Systematic Approach to Evaluating Open Source Software
Selecting appropriate Open Source Software (OSS) for a given problem or a set of requirements can be very challenging. Some of the difficulties are due to the fact that there is not a generally accepted set of criteria to use in evaluation and that there are usually many OSS projects available to solve a particular problem. In this study, the authors propose a set of criteria and a methodology ...
متن کاملDependability Issues in Open Source Software DIRC Project Activity 5 Final Report
The term Open Source is widely applied to describe some software development methodologies. This paper does not provide a judgment on the open source approach, but exposes the fact that simply stating that a project is open source does not provide a precise description of the approach used to support the project. By taking a multidisciplinary point of view, we propose a collection of characteri...
متن کاملTowards a New Evaluation Model to Improve Open Source Software - Application in Moroccan SMEs
Open Source Software (OSS) is widely used as it offers several advantages such as cost saving, security and ability to modify the source code, which encourages companies to adopt it [1]. Morocco like many countries has been hit by the global crisis that affected its economy; several companies of different sizes have closed and employees were left without a fixed workplace. The objective of this...
متن کاملInterdisciplinary Insights on Open Source
The term “open source” is widely applied to describe some software development methodologies. This paper does not provide a judgment on the open source approach, but exposes the fact that simply stating that a project is open source does not provide a precise description of the approach used to support the project. By taking a multidisciplinary point of view, we propose a collection of characte...
متن کامل