Cross Domain Systems for handling classified information complicate the certification test and evaluation problem, because along with multiple data owners comes duplicate responsibility for residual risk. Over-reliance on independent verification and validation by certifiers and accreditors representing different government agencies is interpreted as conflating the principle of defence-in-depth with the practice of repeated verification and validation testing. Using real-world examples of successful and unsuccessful certification test and evaluation efforts to guide the development of a new communication tool for accreditors, this research aims to reduce time and cost wasted on unnecessary retesting of the same or similar security requireme...
Within Europe, there is a very high level of knowledge and experience in product and facility certif...
Current reliable strategies for information security are all chosen using incomplete information. Wi...
High assurance Cyber-Physical Systems (CPS) are the supporting pillars of the critical infrastructur...
In practicable multi-level secure systems it is necessary occasionally to transfer information in vi...
The difficulty of cross domain systems security accreditation lies inherent in the fact that, by def...
The Common Criteria (CC) certification framework defines a widely recognized, multi-domain certifica...
Software certification processes have become so intertwined with development processes that true pro...
Certification is an important process in the aviation industry. The certified status of aircraft, ai...
Exhaustive testing, documentation, code re-view, and formal methods have been the main ap-proaches f...
The safety critical community – those involved in developing and verifying safety critical systems –...
This research develops a framework which allows the many IT security certifications to be compared b...
The development and verification of safety-critical systems increasingly relies on the use of tools ...
Certification is an important process in the aviation industry. The certified status of aircraft, ai...
Department of Defense (DoD) information assurance (IA) certification and accreditation relies on a m...
This study examines the traditional approach to software development within the United Kingdom Gover...
Within Europe, there is a very high level of knowledge and experience in product and facility certif...
Current reliable strategies for information security are all chosen using incomplete information. Wi...
High assurance Cyber-Physical Systems (CPS) are the supporting pillars of the critical infrastructur...
In practicable multi-level secure systems it is necessary occasionally to transfer information in vi...
The difficulty of cross domain systems security accreditation lies inherent in the fact that, by def...
The Common Criteria (CC) certification framework defines a widely recognized, multi-domain certifica...
Software certification processes have become so intertwined with development processes that true pro...
Certification is an important process in the aviation industry. The certified status of aircraft, ai...
Exhaustive testing, documentation, code re-view, and formal methods have been the main ap-proaches f...
The safety critical community – those involved in developing and verifying safety critical systems –...
This research develops a framework which allows the many IT security certifications to be compared b...
The development and verification of safety-critical systems increasingly relies on the use of tools ...
Certification is an important process in the aviation industry. The certified status of aircraft, ai...
Department of Defense (DoD) information assurance (IA) certification and accreditation relies on a m...
This study examines the traditional approach to software development within the United Kingdom Gover...
Within Europe, there is a very high level of knowledge and experience in product and facility certif...
Current reliable strategies for information security are all chosen using incomplete information. Wi...
High assurance Cyber-Physical Systems (CPS) are the supporting pillars of the critical infrastructur...