Guidance to Consumers of Validated Products
It is important that consumers of IT products and protection profiles understand how to interpret the results of IT security evaluations conducted within the scheme. These results are described in evaluation technical reports produced by Common Criteria Testing Laboratories (CCTL) and summarized in the associated validation reports and Common Criteria certificates published by the NIAP Validation Body. An IT product is typically evaluated in a generic laboratory setting at a CCTL within the scheme. In that regard, there are some general assumptions made about the operational environment where the product is ultimately to be employed subsequent to the security evaluation. In some cases, an evaluated IT product may be integrated into a more complex configuration of products that compose an IT system. The actual environment of use may also be significantly different from the one described in the original assumptions set forth in the security target. In the end, consumers must assess the overall contribution to assurance made by the evaluated IT product. When making that assessment, there are several things a consumer should consider:
|