Common Criteria
Common Criteria is an ISO standard (ISO 15408) that describes a certification program for technology products and services.
- outlines an approach for certifying a cloud solution
- security requirements
- assigning an assurance level
- and approving it for operations
- mostly used in government agencies
- mostly applies to hardware and software products
- as opposed to services
Evaluation Assurance Level (EAL)
Evaluation assurance level (EAL) is a numerical rating that indicates the depth and rigor of evaluation from level 1 (basic) to level 7 (most stringent).
- EAL1
- EAL2
- applies when the system has been structurally tested
- EAL3
- EAL4
- EAL5
- EAL6
- EAL7
- applies when a system has been formally verified, designed, and tested