What Does Common Criteria for Information Technology Security Evaluation (CC) Mean?
The Common Criteria for Information Technology Security Evaluation (CC) is an international standard based on computer security product and system evaluations. CC provides guidance on required functionality and assurance for security-related products and other items in a specific environment. CC evaluations are conducted for product consumers, users, technology developers and evaluators.
CC is also known as ISO/IEC 15408.
Techopedia Explains Common Criteria for Information Technology Security Evaluation (CC)
A CC evaluation is performed on a Target of Evaluation (TOE), including separate or combined hardware, firmware and software. Not always a full IT product, a TOE may be a newly developed item or consolidated package and configured as follows:
Software application only
OS only
Software application and OS
Software application, OS and workstation
OS and workstation
Smart card integrated circuit only
Cryptographic coprocessor only (a smart card integrated circuit component)
Local area network (LAN), including terminals, network equipment, software and servers
Database application only (without remote client software)
General CC/TOE model and introduction: Provides a basic TOE evaluation outline
Security function component section: Relates common IT product and technology security requirements
Security assurance component section: Relates common IT product and technology assurance requirements