Journal of Information Security Research ›› 2017, Vol. 3 ›› Issue (7): 638-646.

Previous Articles     Next Articles

A Supporting Environment for IT System Security Evaluation Based on CC and CEM


  • Received:2017-07-19 Online:2017-07-15 Published:2017-07-18

基于国际标准CC 和CEM 的计算机系统信息安全性评估认证支持平台


  1. 崎玉大学信息与计算机科学系
  • 通讯作者: 宝达
  • 作者简介:宝达 工学硕士

Abstract: The whole security of IT systems can be guaranteed only if it is designed, implemented, used, maintained according to some common standards. Therefore, the standardization of IT system security is always a common issue all over the world. CC and CEM are a pair of ISO-NIEC international standards for information security evaluation and certification. CC and CEM establish a trustworthy relationship with common basis among all stakeholders of the target system that is evaluated and certified, and therefore CC and CEM are widely used all over the world. However, evaluation and certification based on CC and CEM is very complex. Evaluation and certification process involves of tens of documents and tasks. Performing evaluation and certification process by human shall cost lots of time. Besides, it is also difficult to ensure that evaluation and certification is fair and no subjective mistakes. These issues not only may result in consuming a lot of time, but also may affect the correctness, accuracy, and fairness of evaluation and certification results. Thus, it is necessary to provide a supporting environment that supports all tasks related to the evaluation and certification process automatically to improve the quality of evaluation results,at the same time reduce the complexity of all evaluator and certifiers work. However, there is no such environment existing until now. This paper presents a supporting environment we are developing for IT system security evaluation and certification based on CC and CEM that provides comprehensive facilities to support the whole evaluation and certification process. This is the first supporting environment to support the whole security evaluation and certification process.

Key words: CC, CEM, information technology, security evaluation, information security evaluation and certification

摘要: 信息系统的整体安全性只有遵照统一的标准来设计、实现、运用、维护,才能在系统的整个生命周期中得到保障.因此,信息系统的安全性标准化工作一直都是世界各国共同关注的问题.CC和CEM是一套信息系统安全性评估和认证的通用标准,并且已经被国际标准化组织ISO收录并颁布.基于CC和CEM标准的评估和认证,可以在被评估认证系统的所有利害相关者之间建立起具有共同基础的信任关系,因此CC和CEM已在世界范围内被广泛应用.然而,基于此套标准的评估和认证过程非常复杂.评估认证过程中的具体工作任务繁杂,涉及的相关文档种类繁多,由人工来进行评估和认证工作需要花费大量的时间,同时需要从事者有极高的专业水平和丰富的经验.并且,由人工进行评估和认证工作,不可避免地会产生人为性错误和由主观倾向导致的偏向性误差,这些问题都会降低评估认证结果的正确性、准确性、公平性.所以,为了提高评估认证工作的效率,保证评估结果的正确性、准确性、公平性,同时降低评估认证工作者的工作难度,一套能够支持评估认证工作整体流程的自动化工具是迫切需要的.但是,以往在世界上并不存在此类工具.为此,提出、设计、开发了世界上第1个基于CC和CEM的评估认证全过程的评估认证支持平台.此平台通过使用自动化方法,帮助相关人员完成评估认证全过程中的各项繁琐的具体工作.介绍了这个基于CC和CEM的评估认证支持平台的设计思想和开发细节.

关键词: CC, CEM, 信息技术, 安全技术, 信息安全性评估认证