Validated Protection Profile

Protection Profile for Multi-level Operating Systems in Environments Requiring Medium Robustness, Version 1.91

Readers are reminded that the certification of this protection profile is the result of maintenance, rather than an actual re-evaluation of the PP. Maintenance of a PP consists of analyzing the affect of changes to the SFRs/SARs of the original evaluated PP. These changes consist of clarifications of the requirements, or changes that reflect updates to policies of CCEVS or the authoring organization.

A summary of the changes made can be found in the Maintenance Report, which is written in relation to the original validation report and PP.

PP Name: US Government Protection Profile for Multi-Level Operating Systems in a Medium Robustness Environments, version 1.91

Product Type: Operating System

Date of Maintenance Completion: 16 March 2007

Conformance Claim: EAL4, augmented with ADV_IMP.2, ALC_FLR.2, ATE_DPT.2, AVA_VLA.3, and the following explicitly-stated SARs: ADV_ARC_EXP.1, ADV_FSP_EXP.21, ADV_HLC_EXP.21, ADV_INT_EXP.12, ADV_LLD_EXP.11, AMA_AMP_EXP.1, ATE_COV_EXP.21, AVA_CCA_EXP.23

Original Validated PP: Protection Profile for Multi-level Operating Systems in Environments Requiring Medium Robustness, Version 1.22

Previous Maintained versions: None

Please refer to the PP page for information concerning the sunsetting of the earlier version(s) of this PP.

Protection Profile: [PDF Document]

Assurance Continuity Maintenance Report: [PDF Document]
Please note: this serves as an additional addendum to the VR for the Original PP.

Original Validation Report: [PDF Document]
Please note: this is the VR for the original evaluated PP; consequently, it does not refer to this maintained version, although it applies to the maintained version.


  1. Explicit requirement that is equivalent to (meets or exceeds) the analysis for EAL4 CC component
  2. The Modular Decomposition component (ADV_INT_EXP) has been modified to reflect medium robustness by levying modularity requirements on security-enforcing entities within the TSF; this exceeds EAL4.
  3. The covert channel analysis is performed only upon the cryptographic module; this exceeds EAL4.