What is the US DoD policy on using later Solaris updates?
While I can’t speak for the government, I can relate my direct conversations with officials at the Defense Information Systems Agency (DISA) who create and enforce these policies. I have been told that a CC evaluation is a “Checkbox” activity that is NOT the most important item in a security accreditation. The fact that a more recent update of Solaris has not been certified directly should not prevent you from using it. However, if the update has a new security feature that has not been evaluated and you are planning to use that feature, it may be more difficult to get your system accredited. DoD customers should work directly with DISA in this area.