What is the purpose of evaluation in system security?
Evaluation is a process where the evidence for assurance is gathered and analyzed. This process gives us a measure of trust, i.e., the extent to which the system satisfies the defined security criteria.
What does a formal evaluation methodology provide?
A formal evaluation methodology provides:
What are typically the targets of an evaluation (what is being evaluated)?
The target can either be:
What are the two situations evaluation methods should try to prevent? What requirements are enforced to stop this?
Firstly, an evaluated system should not be determined to to contain serious flaw after an evaluation.
Secondly, different evaluations of the same system/product should not disagree in their assessment.
To prevent this from happening, the following requirements are enforced on evaluation methods:
What are some of the most famous evaluation methodologies?