What level of risk does CTAS address?
CTAS is primarily intended to address risks that would normally call for an equivalent of Common Criteria at Evaluation Assurance Levels in the range EAL2 – EAL4 for Impact Levels 2 to 4. For lower risks, there may be alternative approaches including: • CSIA Claims Tested Mark(CCTM) • ISO/IEC 27001 • IT Health Checks However, CTAS can also be used to address EAL1 in some cases i.e. if the other approaches are not considered appropriate by the Customer. In such instances, this can be discussed with CESG. If the residual risk analysis indicates that a level equivalent to EAL5 or higher is required, then CESG should be contacted to discuss possible approaches. The contact details in this instance are: iacs@cesg.gsi.gov.uk.