CCEVS Interpretations
Interpretations and Evolution of the Criteria and Methodology
The OR Submission
Within 8 days, the scheme issues an Observation Decision (OD) in response to the OR; it is given the same number as the OR that it answers. This response is binding upon the evaluation for which it was generated. However, because of the quick turn-around, it might not have been as thoroughly investigated as one might hope. In order to address this, the OR and OD are forwarded to the Observation Decision Review Board.
The Appeal Process
The formal appeal must be submitted to Director, NIAP CCEVS with a copy to scheme-comments@niap-ccevs.org and include:
The Director, NIAP CCEVS will acknowledge receipt of the appeal within 3 business days. After consultation with the involved parties and the Observation Decision Review Board (ODRB), the final verdict is rendered to either uphold the original decision or issue a revised OD. The appeal resolution process ends when the Director, NIAP CCEVS issues the scheme's response to the appeal. The ODRB reviews the OD whether appealed or not.
The ODRB
If, during deliberations, the ODRB finds a problem with the wording of the Criteria and/or methodology, an interpretation request is sent to the NIAP Interpretations Board. The ODRB meets two times per quarter, the goal being a fairly current review of decisions.
The NIB
The NIB employs a database to track all of its technical concerns with the criteria and/or methodology. An entry is added to the queue for each request for interpretation that is received. During discussions, other issues concerning the criteria and/or methodology might be discovered; for each such question or concern raised, another queue entry is generated. The initial state of a database entry is an identified problem or question concerning the wording of the Common Criteria or Common Evaluation Methodology. Progression of the entry involves investigating the criteria as well as related literature. The NIB attempts to agree on an interpretation of the words in question, or on a proposed rewording of the criteria/methodology. The database entries are processed by NIB members between meetings as their schedules permit. Database entries may also be processed by members of the public interested in investigating and developing solutions to issues that have been identified. Once a proposal is formulated and properly formatted by the NIB, it is posted for review by the scheme, evaluation community, validation community, and other interested parties. Comments that are received are then discussed in subsequent NIB meetings, and incorporated into an updated version; the cycle continues iteratively until a final proposal is created. This is then forwarded to scheme management for approval, at which time it becomes a CCEVS Interpretation, applicable to all subsequent evaluations within the CCEVS. Once the CCEVS Interpretation is adopted, it is also forwarded to the Common Criteria Management Board (CCMB), which is responsible for maintaining the official international version of the crietia and methodology. If a proposal is never formulated by the NIB because of fundamental questions concerning the criteria/methodology, the NIB constructs a Request for Interpretation and submits it to the CCMB for clarification. For more details on the CCMB and requests for interpretations, see the CCMB's website (www.commoncriteriaportal.org). |