Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

How is the claim that a PP is appropriate for a given robustness level verified?

0
10 Posted

How is the claim that a PP is appropriate for a given robustness level verified?

0
10

A PP is a set of user defined requirements for use in a certain environment that must adhere to organizational policies. The author of the PP in concert with the users of the products that will claim compliance to that PP will determine the given robustness. There is also a PP Review Board that ensures that every PP with a Robustness Level adheres to the rules set forth in the Consistency Instruction Manuals (CIM). It also ensures the minimal functional requirements in the CIM have been addressed by the author of the PP. It should be noted that some early PPs were created before the definitions of Robustness levels were completely codified or the Consistency Instruction Manuals were written; consequently, some are called “Medium Robustness” despite being only EAL2 assurance. These are denoted as such on the list of Validated PPs.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123