How is assurance maintained in Systems and Products?
Once an evaluation has been completed, it is likely that the system/product will be subject to change throughout its operational life. CESG recommends that changes are routinely assessed by an evaluation company to ensure that no security weaknesses are introduced during system upgrades. The CTAS Methodology describes the maintenance review and audit approach in more detail.