Common Criteria and the National Information Assurance Partnership 

common criteria featured

In the evolving world of international IT infrastructure and security, it’s critical that organizations and regulatory bodies have a standard to assess technology effectively. A key player in the United States that works to uphold these standards is the National Information Assurance Partnership (NIAP).

NIAP manages the Common Criteria Evaluation and Validation Scheme (CCEVS) in the United States, ensuring commercial IT products meet robust, internationally recognized security standards. 

This article discusses the relationship between the NIAP and the management of Common Criteria standards in the US, including a discussion of some of those standards. 

 

Read More

Common Criteria and NIST Evaluation

common criteria featured

The Common Criteria, recognized worldwide, provides a standardized framework for evaluating the security attributes of IT products and systems. From defining security requirements to testing and verifying products against these requirements, the Common Criteria assure that the evaluation process is rigorous, repeatable, and thorough.

To ensure the success of the program on a national basis, organizations in those locales will manage certified labs that can test for Common Criteria standards. One such organization and program in the United States is the National Voluntary Laboratory Accreditation Program, or NVLAP).

This article will discuss Common Criteria and how they are managed under NVLAP. 

 

Read More

What Is SOC 2 with Additional Subject Matter (SOC 2+)?

SOC 2+ featured

The Service Organization Control 2 (SOC 2) report has become, for many organizations and industries, the gold standard in security and integrity. While SOC 2 can be relatively comprehensive, more than the basic SOC 2 may be needed as regulatory and industry landscapes evolve. Enter SOC 2+, also known as a SOC 2 report with additional subject matter. 

By incorporating additional subject matter from other compliance frameworks or regulations, SOC 2+ offers a more comprehensive overview of an organization’s control environment. But what does SOC 2+ entail, and how can organizations prepare for this audit? This article will demystify SOC 2+ compliance and provide practical guidance on navigating this complex but critical process.

 

Read More