Perhaps the greatest challenge Information Technology (IT) professionals face today is providing evidence that the systems they develop are secure'. To provide this evidence, they must use a standardized process that will foster a high level of confidence in the security features of the IT system. This process must provide a means to quantify and measure the extent to which the security of the IT system has been evaluated and assessed. No matter what type of system is to be developed, there must be assurance that... Copyright SANS Institut