What takes place during system evaluations?
The CTAS Methodology describes the approach in more detail. In essence the evaluators review the architecture and design of the system, carry out testing (normally including penetration testing) and can audit operational procedures (as required by the Accreditor). Ongoing ‘assurance maintenance’ is normally recommended for operational systems.