You are here: silicon.com > Software > Security Strategy

Security Strategy

Global software standard gets seal of approval

By Felicity Ussher

Published: 16 December 1998 15:40 GMT

An international benchmark for evaluating software security will be rubber-stamped this week by the ISO (International Organisation for Standardisation). The Common Criteria (CC) will enable users to compare the quality of software across international markets.

ISO's technical management is finalising a draft of the standard this week. It will then be released for a two month period of feedback, prior to final publication in May or June 1999.

Nigel Hickson, who represents the Department of Trade and Industry's Information Security Policy Group, told Silicon.com: "This is good news for everyone that matters. It will give users greater choice in choosing software and it will mean one single accreditation for software manufacturers."

Hickson said only the evaluation industry would lose out, as CC would introduce global competition. "But this is all to the good of the user," he added. There are currently five software evaluators in the UK, including IBM, Logica and Admiral.

The governments of the UK, US, Canada, France, Germany and the Netherlands devised CC as an alternative to the US testing scheme Tcsec, Canada's Ctcpec and Europe's Itsec. The schemes enable users to find products with the right level of security for their needs.

Some software evaluators already use CC, but the ISO standard is expected to boost its usage. Krystyna Passia, who represents ISO sub-committee 27, said that she was already having enquiries from Israel, Singapore and Indonesia. Hickson estimated it would take CC five years to replace Itsec altogether.

Passia said a draft of the ISO standard would be published any day now. The industry will have until March 1999 to give its comments.

Copies of the draft standard will be available from the British Standards Institution for a small charge (www.bsi.org.uk), and from ISO's other members worldwide.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Materials Specialist - Health & Safety

Evaluation Committee "EHS Assessments". EHS assessment completion in the SQUAT tool Coordination of requests for EHS assessments from M&P specialists ...

Lead Security Consultant - PCI-DSS/ISO 27001

This role will include: Providing Security Consultancy on compliance standards such as PCI-DSS (Data Security Standard) and ISO 27001; The ideal ...

Clinical Research Project Manager - Medical Devices - ISO 14155

Clinical Research Project Manager - Medical Devices - ISO 14155 - North West A growing Medical Devices company in the North West are currently ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: