Re: [Fed-Talk] EAL3 v EAL4
Re: [Fed-Talk] EAL3 v EAL4
- Subject: Re: [Fed-Talk] EAL3 v EAL4
- From: "Timothy J. Miller" <email@hidden>
- Date: Wed, 31 Aug 2005 13:24:18 -0500
Boyd Fletcher wrote:
EAL4 with the Single-Level Operating Systems in Medium Robustness
Environments is the requirement.
I believe EAL4 with CAPP will be around for at least another 12-18 months.
Unfortunately it is getting very difficult in DOD to use operating systems
that are not EAL 4 with CAPP certified. We all know its a paper drill and
that the CC process as implemented in the US Government actually
significantly reduces our security posture, but until someone can convince
the government and congress to changes the rules we have to live by them.
Hear, hear. CAPP is completely inappropriate for any system on a
network, no matter what classification. SLOSPP-MR is a better profile.
-- Tim
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden