U.S. Government Approved Protection Profiles [RSS Feed]

Effective October 1, 2009, any product accepted into evaluation under the U.S. CC Scheme must claim compliance to a U.S. Government approved Protection Profile. The following Protection Profiles (PP) have been approved for use by vendors for evaluation of products under the NIAP Common Criteria Evaluation and Validation Scheme (CCEVS) and the Common Criteria Recognition Arrangement (CCRA).

In addition, NIAP is currently in the process of updating our PPs. Our first step is to update existing U. S. Government Basic Robustness Protection Profiles to reflect more current threat and functional requirements. We are referring to these as Interim PPs and, as they are completed, they will replace the corresponding Basic PPs.

Concurrently, NIAP is creating a Standard Protection Profile for each technology that will replace any corresponding U.S. Government Protection Profile. NIAP is working with industry, our customers, and the Common Criteria community to create these profiles. The first generation of these Protection Profiles will take into account the current assurance that is achievable for a technology and the Evaluation Assurance Level (EAL) will be set based on the availability of the documentation, test plans, and tools needed to obtain consistent and comparable results (see PPs in Development for a status of each PP).

Please see the announcement from the NIAP Director, “Sunsetting of NIAP Protection Profiles – Effective 1 September 2011”, dated 2 August 2011.

10 Validated Protection Profiles
   Tech Type    Profile Name    Conformance Claim       CC Ver.    Short Name    Sponsor    Date(s)
This list was generated on Saturday, February 04th, 2012 at 2:13AM
Network Devices Network Device Protection Profile (NDPP) Extended Package Stateful Traffic Filter Firewall None 3.1 PP_ND_TFFW_EP_V1.0 NSA 2011-12-19
Encrypted Storage Protection Profile for Full Disk Encryption None 3.1 PP_FDE_v1.0 NSA 2011-12-01
VPN Protection Profile for IPsec Virtual Private Network (VPN) Clients None 3.1 pp_vpn_ipsec_client_v1.0 NSA 2011-12-29
Encrypted Storage Protection Profile for USB Flash Drives None 3.1 PP_USB_FD_v1.0 NSA 2011-12-01
Wireless LAN Protection Profile for Wireless Local Area Network (WLAN) Access Systems 15 November 2011 Version 1.0 None 3.1 PP_WLAN_AS_V1.0 NSA 2011-12-01
Wireless LAN Protection Profile for Wireless Local Area Network (WLAN) Clients None 3.1 PP_WLAN_CLI_V1.0 NSA 2011-12-19
Network Devices Security Requirements for Network Devices US Standard - EAL1 3.1 PP_ND_V1.0   2010-12-10
Operating System U.S. Government Protection Profile for General-Purpose Operating Systems in a Networked Environment, Version 1.0 EAL2 Augmented 3.1 PP_GPOSPP_V1.0 NSA 2010-08-30
Multi Function Device U.S. Government Protection Profile for Hardcopy Devices Version 1.0 (IEEE Std. 2600.2™-2009) EAL2 Augmented 3.1 PP_HCD_EAL2_V1.0 IEEE Computer Society Information Assurance (C/IA) Committee 2010-02-26
Peripheral Switch Validated Protection Profile - Peripheral Sharing Switch for Human Interface Devices Protection Profile, Version 2.1 EAL2 Augmented 3.1 PP_PSSHID_V2.1 NSA 2010-09-07