What takes place during the Assurance Maintenance Phase?
The CTAS Methodology describes the approach in more detail. In essence the evaluators review proposed changes prior to implementation and confirm whether they agree with the impact of the changes as summarised in an outline Security Impact Analysis provided by the Developer. A periodic Maintenance Review (e.g. annually) is later performed to audit the correct implementation of these changes. The latter review may include a check for new vulnerabilities, a review of the patches applied, an audit of maintenance procedures, a review of Developer testing and a test of updated security functionality.