Sign In
Tim Myers' Security Evaluations FAQ / Blog
Security Evaluations, Microsoft Security Engineering Center (MSEC), Trustworthy Computing Security
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Common Tasks
Blog Home
Email Blog Author
About
OK
RSS for posts
Atom
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
AISEP
BSI
CC
Common Criteria
EAL1
EAL4
EAL4+
Evaluation Technical Report
FIPS
Guidance Documentation
Hyper-V
ICCC
IIS
JITC
NIAP CCEVS
NSA
Security
SP2
SP3
TCSEC
Vista
Windows 7
Windows Server 2003 R2
Windows Server 2008
Windows Server 2008 R2
Monthly Archives
Archives
April 2011
(1)
December 2009
(1)
November 2009
(1)
September 2009
(4)
August 2009
(1)
July 2009
(2)
June 2009
(1)
April 2009
(2)
March 2009
(3)
February 2009
(6)
January 2009
(1)
December 2008
(1)
November 2008
(1)
October 2008
(5)
September 2008
(1)
August 2008
(3)
July 2008
(2)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Tim Myers' Security Evaluations FAQ / Blog
Microsoft Windows 7, Windows Server 2008 R2 and SQL Server 2008 SP2 Now Certified as Common Criteria Validated Products
Posted
9 months ago
by
Tim Myers - SECURITY
For details, please see the Future Fed blog post: http://www.futurefed.com/blog/29/microsoft-windows-7-windows-server-2008-r2-and-sql-server-2008-sp2-now-certified-as-common-criteria-validated-products.aspx
Tim Myers' Security Evaluations FAQ / Blog
Windows Vista and Windows Server 2008 are on the NIAP CCEVS Validated Products List
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft Windows Vista and Microsoft Windows Server 2008 were Common Criteria (CC) validated on August 31, 2009. The CC conformance claim is Evaluation Assurance Level 4 (EAL4) augmented with flaw remediation ALC_FLR.3 and vulnerability analysis AVA_VLA...
Tim Myers' Security Evaluations FAQ / Blog
Windows 7 and Windows Server 2008 R2 in Common Criteria Evaluation
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft Windows 7 and Microsoft Windows Server 2008 R2 formally entered evaluation for Common Criteria Evaluation Assurance Level 4 augmented with flaw remediation (ALC_FLR.3), commonly referred to as EAL4+. The Protection Profile in use is PP_GPOSPP_V7...
Tim Myers' Security Evaluations FAQ / Blog
Windows Server 2003 Web Edition and CC Revisited
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft Windows Server 2003 Web Edition is a proper subset of the Windows Server 2003 editions that were included in the Target of Evaluation (TOE) of several Common Criteria security evaluations. The Web Edition has no more security functions than...
Tim Myers' Security Evaluations FAQ / Blog
Windows Vista and Windows Server 2008 are Common Criteria Certified at EAL4+
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft Windows Vista and Microsoft Windows Server 2008 received their Common Criteria (CC) certificate on September 23 rd at the 10 th International Common Criteria Conference in Tromsø, Norway. The CC Evaluation Assurance Level is 4 (EAL4+). The target...
Tim Myers' Security Evaluations FAQ / Blog
Microsoft Windows Server 2008 Hyper-V Role is now Common Criteria Certified at EAL4+
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft Windows Server 2008 Hyper-V Role has successfully completed validation against the Common Criteria at Evaluation Assurance Level 4 augmented by ALC_FLR.3 Flaw Remediation (EAL4+). The German Bundesamt für Sicherheit in der Informationstechnik...
Tim Myers' Security Evaluations FAQ / Blog
Windows Mobile 6.1 Certified with Common Criteria at EAL4
Posted
over 3 years ago
by
Tim Myers - SECURITY
Windows Mobile 6.1 with System Center Mobile Device Manager 2008 and System Center Mobile Device Manager 2008 Service Pack 1 (SP1) have been validated at Common Criteria (CC) Evaluation Assurance Level 4 (EAL4). The CC evaluation was conducted by Stratsec...
Tim Myers' Security Evaluations FAQ / Blog
Does Microsoft plan to evaluate Windows 7 and Windows Server 2008 R2 under CC?
Posted
over 3 years ago
by
Tim Myers - SECURITY
Q: Does Microsoft plan to evaluate Windows 7 and Windows Server 2008 R2 under CC? A: Microsoft has evaluated every release of the Windows NT product family under Common Criteria, both Client and Server versions, since Windows 2000. It is currently...
Tim Myers' Security Evaluations FAQ / Blog
The Database Engine of Microsoft SQL Server 2005 SP2 Common Criteria Certification
Posted
over 3 years ago
by
Tim Myers - SECURITY
The Database Engine of Microsoft SQL Server 2005 SP2, Enterprise Edition (English) Version 9.00.3068.00 was validated/certified as meeting Evaluation Assurance Level 4 Augmented (EAL4+) in a CC evaluation. The certification includes verification of compliance...
Tim Myers' Security Evaluations FAQ / Blog
Microsoft SQL Server 2000 TCSEC Class C2 Certification
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft SQL Server 2000 was validated against the DoD/NSA NCSC Trusted Computer System Evaluation Criteria ( TCSEC ). Its rating was Class C2 . This kind of security evaluation was a predecessor to the Common Criteria (CC). Unfortunately, the DoD/NSA...
Tim Myers' Security Evaluations FAQ / Blog
Has Windows Storage Server 2003 SP1 been Common Criteria Certified?
Posted
over 3 years ago
by
Tim Myers - SECURITY
No, Windows Storage Server 2003 SP1 has not been certified/validated in a Common Criteria (CC) evaluation. An inspection of the Security Targets and Validation Reports for the following evaluated products should help you determine whether the components...
Tim Myers' Security Evaluations FAQ / Blog
SharePoint DoD 5015.2 Certification
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft Office SharePoint Server 2007 with DoD Add-On Pack complies with the DoD 5015.02-STD Joint Interoperability Test Command (JITC) Records Management Application (RMA) Design Criteria Standard rather than the Common Criteria. Press http...
Tim Myers' Security Evaluations FAQ / Blog
SQL Server 2008 Database Engine CC Validated at EAL1+
Posted
over 3 years ago
by
Tim Myers - SECURITY
The Database Engine of Microsoft SQL Server 2008 Enterprise Edition (English) x86 and x64, Version 10.0.1600.22 was Common Criteria validated / certified at EAL1+ by the BSI in Germany. The certification report and security target are available here:...
Tim Myers' Security Evaluations FAQ / Blog
Has Windows Server 2003 Web Edition been certified?
Posted
over 3 years ago
by
Tim Myers - SECURITY
It is understood that there are no plans to evaluate the Web Edition of Windows Server 2003 against the Common Criteria (CC). There isn't anything contained in the Web Edition that you can't find in the Standard Edition, Enterprise Edition, or Datacenter...
Tim Myers' Security Evaluations FAQ / Blog
Internet Security and Acceleration (ISA) Server 2006 is Common Criteria Certified
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft Internet Security & Acceleration (ISA) Server 2006 has been validated and certified to have met Common Criteria Evaluation Assurance Level 4 with augmentation of AVA_VLA.3 and ALC_FLR.3 (EAL4+.) For details, please see the ISA team blog...
Tim Myers' Security Evaluations FAQ / Blog
Composite Common Criteria Evaluations
Posted
over 3 years ago
by
Tim Myers - SECURITY
Composite Common Criteria evaluations -- those that have a dependency on another CC evaluation, i.e., SQL Server and Windows Server -- can proceed in parallel. It is my understanding from the 8th ICCC that the other component/platform evaluation needn...
Tim Myers' Security Evaluations FAQ / Blog
When will SP 1,2,3,… be CC certified?
Posted
over 3 years ago
by
Tim Myers - SECURITY
Generally, we do not certify every Service Pack (SP), just major product releases. For example, our customers have seen a long term commitment by Microsoft to certify each major release of Windows. If a new SP’s ship date happens to line up with...
Tim Myers' Security Evaluations FAQ / Blog
Is IIS included in the Windows Server 2003 R2 CC evaluation?
Posted
over 3 years ago
by
Tim Myers - SECURITY
The Common Criteria validation of Windows Server 2003 R2 includes IIS as a web server. Please see the Security Target for details: http://www.niap-ccevs.org/cc-scheme/st/vid10184/
Tim Myers' Security Evaluations FAQ / Blog
Active Directory Federation Services (ADFS) and CC
Posted
over 3 years ago
by
Tim Myers - SECURITY
Active Directory Federation Services (ADFS) was included in the Common Criteria validation of Microsoft Windows XP and Windows Server 2003 R2. Please see the Security Target (ST) for details: http://www.niap-ccevs.org/cc-scheme/st/vid10184/ Guidance...
Tim Myers' Security Evaluations FAQ / Blog
Windows 2000 CC Certification and Microsoft Support Lifecycle
Posted
over 3 years ago
by
Tim Myers - SECURITY
Microsoft Windows 2000 Professional, Server, and Advanced Server were Common Criteria certified in 2002. The Security Target, Validation Report, and certificate are available here: http://www.niap-ccevs.org/cc-scheme/st/vid4002/ Although mainstream...
Tim Myers' Security Evaluations FAQ / Blog
What about Windows XP Embedded?
Posted
over 3 years ago
by
Tim Myers - SECURITY
MS Windows XP Embedded, Version 5.1 SP2 has been Common Criteria certified. This gives embedded products a sound basis for the assurance of the platform. I’ve been asked whether SP1 and SP3 have also been certified. They have not and it is understood...
Tim Myers' Security Evaluations FAQ / Blog
Have Terminal Services and RDP been certified?
Posted
over 3 years ago
by
Tim Myers - SECURITY
Terminal Services and the RDP protocol were not included in the Target of Evaluation (TOE) of the Windows Server 2003 Common Criteria certification. Although the Windows Server 2003 CC evaluations have covered the richest set of features and services...
Tim Myers' Security Evaluations FAQ / Blog
Trusted System Development Methodology (TSDM) Level 2 vs. Common Criteria
Posted
over 3 years ago
by
Tim Myers - SECURITY
Certain draft PKI RFCs and DoD PKI requirements documents refer to the “Trusted System Development Methodology (TSDM) Level 2”, it also goes by other names such as “Trusted Software Development Methodology” and “Trusted Software Methodology”. The actual...
Tim Myers' Security Evaluations FAQ / Blog
What actually makes products more secure? SDL
Posted
over 4 years ago
by
Tim Myers - SECURITY
Common Criteria security evaluations and certifications give us some measurable assurance that products such as Microsoft Windows live up to their security claims. Microsoft has successfully completed these and similar security evaluations since Windows...
Tim Myers' Security Evaluations FAQ / Blog
Can you decipher this message?
Posted
over 4 years ago
by
Tim Myers - SECURITY
2
Comments
Can you decipher this message? If so, please send me an email with the answer. NEPUZ PUSBN DGDTN UPJSJ PTNFU
Page 1 of 2 (36 items)
1
2