12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9: Compliance and Storagetion. While FIPS 140-2 focuses on the actual cryptographic module, CCdeal more with the engineering processes employed in the developmentof a product including hardware, software, and/or firmware.Unlike the FIPS 140-2 standard, CC is an international standard developedby the International Organization for Standards (ISO) and theInternational Electrotechnical Commission (IEC) and is specificallyreferred to as ISO/IEC 15408:2005. Several countries contributed todeveloping this standard, including: Australia, New Zealand, Canada,France, Germany, Japan, the Netherlands, Spain, the UK, and the US.It is, however, recognized internationally by 28 countries.CC also employ various accreditation levels, ranging from the lowestevaluation assurance level (EAL) 1 to the most secure level EAL 7. The<strong>Brocade</strong> encryption solution is validated to EAL4+, which is the highestlevel relevant to networking products. The CC validated products listcan be downloaded at: http://csrc.nist.gov/groups/STM/cmvp/validation.html.Vendors seeking CC, or ISO/IEC 15408:2005, accreditation must havetheir product undergo independent testing by an approved laboratory toobtain the desired EAL accreditation level. A security product under CCevaluation is referred to as a target of evaluation (TOE), which can includehardware, operating systems, computer networks, and applications.To evaluate a TOE, the security requirements the product or system isdesigned to address and its security functions must be defined. This requirementsand functions definition is referred to as the security target (ST).Since there are many different security requirements addressing specificsecurity problems, categories are created to simplify classificationof individual products. Each category is represented by an implementation-independentstructure known as a protection profile (PP). Whenevaluators evaluate a TOE, they compare the ST for that product or systemagainst pre-defined PPs and make a statement of compliance ornon-compliance to the PP.Evaluation Assurance Levels (EAL)Consumers may have different security requirements for individualproduct types and require assurances that a product meets specifiedcriteria to address their requirements. CC uses an increasing hierarchicalscale to define these assurance levels: the evaluation assurancelevel (EAL). Table 13 describes the seven EALs defined by ISO/IEC15408:2005.166 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!