Scheme Publications

The NIAP CCEVS Validation Body will communicate to sponsors of evaluations, testing laboratories, government agencies, and the general public through a series of technical and administrative publications. The flagship document in the series is Scheme Publication #1, Common Criteria Evaluation and Validation Scheme for IT Security - Organization, Management, and Concept of Operations.

Other publications provide guidance to sponsors of IT security evaluations, guidance to security testing laboratories, guidance on evaluating specific information technologies, guidance on employing and interpreting the Common Criteria and Common Evaluation Methodology, and guidance on protection profile and security target development.

Additional information and guidance will be available on other important scheme topics such as technical oversight, validation, Common Criteria certificates and certificate maintenance. Comments on any scheme publication can be forwarded to the NIAP CCEVS Validation Body using the following email address: scheme-comments@niap-ccevs.org.

Publication #1 NIAP Common Criteria Evaluation and Validation Scheme for IT Security Organization, Management, and Concept of Operations, Version 2.0 May 1999
Publication #2 NIAP Common Criteria Evaluation and Validation Scheme for IT Security Validation Body Standard Operating Procedures, Draft Version 1.5 May 2000
Publication #3 NIAP Common Criteria Evaluation and Validation Scheme for IT Security Guidance to Validators of IT Security Evaluations, Version 1.0 Feb 2000
Publication #4 NIAP Common Criteria Evaluation and Validation Scheme for IT Security Guidance to Common Criteria Testing Laboratories, Draft Version 1.0 Mar 2001
Publication #5 NIAP Common Criteria Evaluation and Validation Scheme for IT Security Guidance to Sponsors of IT Security Evaluations, Draft Version 1.0 Aug 2000
Publication #6 Please see LabGram #29 in reference to this publication  
     
NIST Publications NIST Handbook 150, Procedures and General Requirements
NIST Handbook 150-20, Information Technology Security Testing-Common Criteria
 
     
NIAP Publications NVLAP LAB BULLETIN NUMBER: LB-29-2008: Revision of NIST Handbook 150-20, Sections 3.3.3, 3.3.4 and Annex B  


CCEVS Guidance Documents

The Common Methodology for Information Technology Security Evaluation (CEM), upon which mutual recognition is based, currently includes only those CC components that constitute EAL4 and below, plus ALC_FLR. However, evaluations might also include additional assurance components. For those components, the following sets of guidance are offered by the CCEVS:

The CCEVS has also issued the following guidance: