package
named set of either security functional or security assurance requirements
Protection Profile (PP)
implementation-independent statement of security needs for a TOE type
Security Target (ST)
implementation-dependent statement of security needs for a specific identified TOE
ST
ST always describes a specific TOE (e.g. Palo Alto Firewall)
PP
intended to describe a TOE type (e.g. Firewalls).
ST
Describes requirements for a TOE.
PP
Describes the general requirements for a TOE type.
Protection Profile is not written for a specific product
PP
Written by User Community, Developer of a TOE, Government or Large Corporation.
ST
Written by the developer of that TOE
PP/ST
PP determines the allowed type of conformance of the ST to the PP.
EAL1
Functionally Tested
EAL2
Structurally Tested
LOW to MODERATE level of independently assured security
EAL3
methodically tested and checked
MODERATE level of independently assured security
EAL4
methodically designed, tested, and reviewed
MODERATE to HIGH level of independently assured security
EAL4
HIGHEST LEVEL at which it is likely to be economically feasible to retrofit to an existing product line.
EAL5
semiformally designed and tested
HIGH level of independently assured security
EAL6
semiformally verified design and tested
high risk situations.
high attack potential
EAL7
semiformally verified design and tested
extremely high risk situations and/or where the high value of the assets justifies the higher costs