Information About

Itsec




ITSEC is a structured set of criteria for evaluating computer security within products and systems. Each evaluation involves a detailed examination of IT security features culminating in comprehensive and informed functional and penetration testing. This work is undertaken using an agreed Security Target as the baseline for ensuring that a product or system meets its security specification. ITSEC operates the concept of assurance levels E0 to E6. This scale represents ascending levels of confidence that can be placed in the TOEs security functions and determines the rigour of the evaluation.

Since the launch of ITSEC in 1990, a number of other European countries have agreed to recognise the validity of ITSEC evaluations.


SEE ALSO




EXTERNAL LINKS