Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

What level of risk does CTAS address?

address CTAs level risk
0
Posted

What level of risk does CTAS address?

0

CTAS is primarily intended to address risks that would normally call for an equivalent of Common Criteria at Evaluation Assurance Levels in the range EAL2 – EAL4 for Impact Levels 2 to 4. For lower risks, there may be alternative approaches including: • CSIA Claims Tested Mark(CCTM) • ISO/IEC 27001 • IT Health Checks However, CTAS can also be used to address EAL1 in some cases i.e. if the other approaches are not considered appropriate by the Customer. In such instances, this can be discussed with CESG. If the residual risk analysis indicates that a level equivalent to EAL5 or higher is required, then CESG should be contacted to discuss possible approaches. The contact details in this instance are: iacs@cesg.gsi.gov.uk.

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123