What takes place during software product evaluations?
COTS products and bespoke components can be evaluated at one of two levels, of which the first is considered roughly equivalent to EAL 2/3 and the second to EAL4. The CTAS Methodology gives more details but the first level assesses overall confidence in the product by considering available evidence in the following areas: functionality and design, development procedures and basic security functional testing. The second level supplements this with source code analysis and more extensive vulnerability analysis.