You are on page 1of 11

OVERVIEW

Cybersecurity Certification Guide

Cybersecurity Certification Guide


Global Cyber Landscape
CONTENTS

OVERVIEW 1 Global Cyber Landscape The global cyber landscape has changed

2 Opportunities for Certification dramatically in recent years, with increasing


awareness of the risks and threats faced
by states, businesses, and individuals.
SCHEMES 5 Singapore Common Criteria Scheme
Ransomware attacks, data breaches,
(SCCS)
and other cyber incidents have made
11 National IT Evaluation Scheme (NITES)
the headlines as a stark reminder that
13 The Smart Consumer Device cybersecurity must be taken seriously.
14 Frequently Asked Questions (FAQ)
1
At the same time, people are keen to
maximise the opportunities presented
FUTURE 16 Events & Activities
by the rapid advances in digitalisation
and innovation. Singapore is embarking
on an initiative to create a “Smart Nation”,
and businesses and individuals are keen
to harness the power of technology at
work and play. Singapore’s Cybersecurity
Strategy aims to create a resilient and
trusted digital environment to facilitate that.

New technology products are constantly


coming to market. CSA offers and supports
the use of Certification Schemes to provide
assurance to customers that the product
has been objectively assessed to be more
cyber secure, and has adopted a secure-by-
design approach throughout the product’s
development and life cycle.
OVERVIEW
Cybersecurity Certification Guide

Cybersecurity Certification Guide


Opportunities for Certification

The speed of technology adoption An internationally-recognised The two schemes listed in this guide,
continues to accelerate for both certification mark has become a catering to different market segments, are:
work and play, with new business necessity for local developers to
models and market opportunities expand their market reach globally. Singapore Common Criteria
still being unlocked. Scheme (SCCS), for certification of
commercial IT products targeting
CSA Cybersecurity Certification
the international marketplace;
With greater digitalisation and Centre operates the following
connectivity comes increased schemes aimed at providing
National IT Evaluation Scheme
emphasis on cybersecurity. the security assurance that
(NITES), for evaluation of IT
While cybersecurity is a concern, the product has undergone products that meets high
2 it is also a market opportunity. impartial examination and testing assurance requirement for 3

Based on the IDC forecast made to ascertain that it is securely Cyber Security Agency
Singapore government agencies.
in October 2018, worldwide designed, implemented, and of Singapore (CSA) is
spending for cybersecurity is appropriate in mitigating the the national agency that
projected to reach $133.7 billion by specified security threats. Through these schemes, smaller companies, provides dedicated and
2022 1 ; and the demand for higher- who have yet to establish track records, will centralised oversight
quality and secure products will be able to demonstrate the merits of their of national cybersecurity
continue to increase. products that are benchmarked against functions including
international standards. strategy, international
policy, R&D, outreach,
system and industry
development.

Under the ambit of


CSA is the Cybersecurity
Certification Centre
(CCC) which focuses
on the evaluation
and certification of
cybersecurity products.

1
“New IDC Spending Guide Forecasts Worldwide Spending on Security Solutions will Reach $133.7 Billion in 2022”, International
Data Corporation (IDC) Press Release, 04 October 2018, https://www.idc.com/getdoc.jsp?containerId=prUS44370418
SCHEMES
Cybersecurity Certification Guide

Cybersecurity Certification Guide


About SCCS SCCS: Benefits

Common Criteria (CC), also known For consumers:


as ISO/IEC 15408, is a globally • Trust that the security
recognised technical standard examination of a product is done
for IT security evaluation. To date, impartially, professionally, and
4 5
31 nations have signed the Common meets international standards;
Criteria Recognition Arrangement therefore reducing the need
(CCRA), whereby CC certificates for in-house inspections.
issued by an authorised nation
are mutually recognised across • Better safeguard their digital
all member nations. assets and services by deploying
certified products.
As of January 2019, Singapore
is recognised as a CC Certificate
For developers:
Authorising Nation.
• Meet regulatory requirements
Singapore subscribes to the and gain market access.
objectives of the CCRA: to improve
the availability of IT products • Develop better products
evaluated under high and consistent and differentiate themselves.
standards, and to eliminate the
burden of duplicating evaluations
while improving the efficiency and
effectiveness of the evaluations.
SCHEMES
Cybersecurity Certification Guide

Cybersecurity Certification Guide


Product Security
Accreditation
Evaluation &
& Recognition
Process of Evaluation
Certification
Developers of a product

Common Criteria
Recognition Arrangement
➀ can apply to CSA-CCC
to have their product
evaluated under SCCS.

➄ Supports development
Recognises CSA as
Supervises evaluation of Common Criteria
CC certification body
Developers engage a


of product standard CCTL approved by SCCS
➂ Requests for certification

to undergo evaluation in
➅ Issues certificate to

accordance to internationally
Common Criteria recognised standards.
Testing Laboratory
6 7
(CCTL)

➃ ➁ Approves
Evaluates Engages
as CCTL
product CCTL


After the evaluation,
an assessment will be
submitted to CSA-CCC.
Common Criteria
Sponsor /Developer Testing Laboratory
(CCTL)

➆ ➀ Accredits CCTL
Provides certified Requires security
with ISO 17025
products to assurance from
If successful, CC


certificate will be issued
which raises the level of
trust and assurance in
Consumer
the product.

Recognised Accreditation Bodies

Scan to find out more


For more information: information about
SCCS Certified Products:
SCHEMES
Cybersecurity Certification Guide

Cybersecurity Certification Guide


Testimonials
of developers As a global security
evaluation methodology
How to sieve out design
flaws? How to prove design
In a time of increasing
cyber threats, third party
To be a trusted provider
of mobile security
The Singapore Common
Criteria Scheme not
and labs recognised by more than correctness and provide security evaluation and products and solutions, only strengthens
30 countries, there is no security assurance to certification makes our IT it is important for us to understanding of
other security standard customers? These are the environment more secure have an independent security in technology
in the world that is more questions that developers and reliable. Evaluation assessment of the security products among the
thorough, complete, and often ponder before they activities including security of our technology so as general population,
influential than Common embarked on the CC journey. testing are performed to provide the assurance but also the rigorous
Criteria (CC). The CC What we didn’t foresee was by labs according to that our global customers and internationally
Recognition Arrangement the amount of engineering, the requirements of the need. Common Criteria recognised standard
(CCRA) benefits the testing and documentation Common Criteria (ISO/IEC is a globally-recognised of evaluation and
security ecosystem and effort that is required for 15408). The benefits of the standard that not only certification allows
lowers the barrier of selling product certification. evaluation and certification includes the evaluation developers of quality
your security products using CC are impartiality of our products’ security products to penetrate
to different parts of the It was at this juncture when and comparability. CC functionality but also the new markets. Evaluation
world. Brightsight, the CSA provided crucial support certificates are mutually assurance of our design labs that fall under
number one security lab in knowledge build up and recognised by CCRA and development process. this scheme are also
8 training, as well as their 9
in the world, has not only members. No security Having gone through carefully curated for
contributed to the creation coordinated push for a wider evaluation can reduce Common Criteria evaluation developers’ assurance.
of the latest version of the adoption of CC certification risks to assets to zero, also helped our teams The certification
standard, but also supported in local ecosystem. but to an acceptable level. to formalise many of our process is carried out
developers getting hundreds Attaining CC Certification not Risk owners get a clear processes to enable us to with utmost integrity
of certifications in the past only ensure we deliver more alignment with their actual become a more security- and professionalism
years. Brightsight is working secure and quality products, security policy determines minded organisation. while maintaining
with CSA to enable a smooth it also elevates our competitive at an adequate assurance open communication
evaluation and certification edge in global markets. What level. Common Criteria among all stakeholders.
process where more started as a daunting task has reflects the degree of An Security, a local
developers can benefit from also help to deepen our team’s assurance by different well- security lab, is proud to
CC and face the IoT security expertise and experience in defined Assurance Levels. be participating in this
challenges together. the journey of CC. journey with CSA.

Dirk-Jan Out Goh Eng Choon Dr. Igor Furgel Er Chiang Kai Daryl Koh
Chief Executive Officer Deputy President Head of Certification Body Chief Technology Officer Managing Director
Brightsight Cybersecurity Systems Group, T-Systems V-Key An Security
Electronics,
ST Engineering
SCHEMES
Cybersecurity Certification Guide

Cybersecurity Certification Guide


Common Criteria
Users Forum (CCUF)

The Common Criteria Users Forum (CCUF)


was founded in 2012 and is a community
based around those using the Common About NITES
Criteria and ISO/IEC 15408 standards.
The Common Criteria Users’ Forum mission
is to provide a voice and communications The National IT Evaluation Products that performs
channel between the CC community Scheme (NITES) was launched critical security functions such
and the CC organisational committees, in November 2009. Products as cryptographic operations
10 CC evaluation schemes, and policy makers. intended to be used for handling are likely to be subjected to 11

sensitive government data have security evaluation.


to be evaluated in accordance
with NITES. The most stringent Apart from additional national
requirements are needed when requirement, NITES largely
For more information
it comes to safeguarding adopts the CC methodology of
about CCUF:
Singapore’s national interests. evaluating the products at high
assurance level.
NITES provides the assurance
that the security measures
provided by the product to
For more information,
safeguard the highly classified please contact us at
information in the intended
deployment scenarios are suitable.
SCHEMES
Cybersecurity Certification Guide

Cybersecurity Certification Guide


The Smart Consumer Device

In recent years, consumers are increasingly adopting ‘smart’


devices such as Smart TVs, Smart Home Hubs, and IP Cameras
to improve quality of life. In the future, it is expected that billions
of such devices will be connected to the internet. However,
the growth and proliferation of such devices also increased
cybersecurity concerns and risk of being hacked.

12 13
What’s going on? As a general consumer,
how can we better protect
In the market, a large number ourselves when we are
of devices are being sold with unable to determine if a
poor cybersecurity provisions. product is good or bad?
Hackers generally look for
the easiest systems to attack To help general consumers
that will net the most damage better protect themselves
and returns. against cyber-attacks,
Singapore is exploring a
While consumers will most labelling scheme for these
often choose the more consumer devices. Under this
secure product if available, scheme, the cybersecurity
the amount of security that labels would help to provide an
is built into these devices is indication of the level of security
not usually made known by that is embedded in the products and
the manufacturers. Thus, empower consumers to make more
consumers are unable to informed purchasing decisions. In the
make informed decisions long run, manufacturers would thus
towards purchasing more be encouraged to provide products
secure devices. with better cybersecurity provisions.
SCHEMES
Cybersecurity Certification Guide

Cybersecurity Certification Guide


Frequently Asked Questions
To what levels are the CC certificates
mutually recognised?
Common Criteria (CC) The Common Criteria Recognition Arrangement
mutually recognised certificates based on:
How long do evaluations take? What are the applicable fees for CC? • collaborative Protection Profile (cPP)
up to and including EAL4 and ALC_FLR
A typical evaluation takes around CSA charges a nominal fee (refer
3 to 6 months. The scope of evaluation, to CSA Common Criteria website) • Up to EAL2 and ALC_FLR
complexity of the product, and for certification services. For
readiness of the developer may evaluation fees, please contact the What are the different Evaluation Assurance
also affect the duration of evaluation. approved CCTL under SSCS as Levels (EALs) under Common Criteria?
Products evaluated at higher cost varies based on the scope of The EALs provide an increasing scale that balances
assurance levels will likely take evaluation and complexity of product. the level of assurance obtained with the cost and
longer with more effort needed.
If a product is CC certified with
feasibility of acquiring that degree of assurance.
NITES and CC
14
What can developer do to shorten the highest Evaluation Assurance EAL1 – Functionally tested 15
Which scheme to choose?
the duration of an evaluation? Level (EAL), does it mean that it is EAL2 – Structurally tested
NITES or CC?
impossible to hack the product? EAL3 – Methodically tested and checked
Developers are recommended to Developers who are keen
EAL4 – Methodically designed, tested
adopt the security-by-design approach A product with a higher EAL is not to obtain an internationally-
and reviewed
during the product design phase. an assurance of an elevated level recognised certification to
A product with well-designed of security; instead, it signifies it has EAL5 – Semiformally designed and tested
facilitate the exportability of
security implementations often takes undergone more testing. To achieve EAL6 – Semiformally verified design and tested
their products should strive for
a shorter period of time for evaluation. balance among cost, time, and effort, EAL7 – Formally verified design and tested CC certification. The NITES is a
Developers who are new to CC could an evaluation done at a higher EAL is high-assurance national scheme
consider engaging an independent CC also often for a more targeted scope; What is the difference between an that is recognised only by the
consultant to support them through while an evaluation done at a lower authorising nation and consuming nation? Singapore Government.
the evaluation process. Additional time EAL is likely to be of a broader scope.
The authorising nation is a compliant Certification
and cost will be incurred when the
Consumers and developers should Body operating in their own country and under
developer tries to fit additional security
consider the security requirements the CCRA, that is able to issue certificates which
measures into their existing product
and the intended deployment are mutually recognised. Consuming nation do
design during evaluation.
locations to determine which not operate any compliant Certification Body,
EAL is more appropriate. nonetheless has expressed interest in the
How long will a CC certificate
use of certified IT products.
be valid for?

Each CC certificate issued will be


valid for 5 years from the date of issue.

Members of the CCRA:


EVENTS & ACTIVITIES
Cybersecurity Certification Guide

Events & Activities Contact

Cyber Security Agency


of Singapore
General Enquiries/Feedback:
contact@csa.gov.sg

16

Common Criteria Common Criteria Common Criteria


(Specialisation) Industry Awareness C-Suite Awareness Cybersecurity
Training Workshop Workshop Certification Centre
Schemes Enquiries:
nites@csa.gov.sg
As part of CSA's strategy to A series of industry engagements to The C-Suite Awareness Workshop
build a strong community of spread Common Criteria awareness provides senior decision makers
practice in product evaluation to the local industry, the Industry from the private and public Scan for the latest list of
CCTL approved by SCCS:
and certification, the CC training Awareness Workshop provides sectors with an appreciation of
aims to provide CC evaluators, participants with an appreciation Common Criteria. Through the
developers, certifiers, and project of CC to help companies develop sharing by fellow developers and
managers with CC skills. world-class security products. international experts, the senior
management gained a better
understanding of how CC could
improve security assurance of
product, be leveraged upon to
develop world class security
products and for their companies
to gain access to the wider markets.
Designed by:
APT811 Design & Innovation Agency

You might also like