Certification
The AUSTRALASIAN INFORMATION SECURITY EVALUATION PROGRAM (AISEP) is the Common Criteria (CC) evaluation scheme implemented by Australia and New Zealand to evaluate and certify Information Technology (IT) products and systems.
The purpose of the AISEP is to ensure the ready availability of a comprehensive list of independently assured IT products and systems that meet the needs of Australian and New Zealand Government departments and agencies in protecting their official communication and information systems
DSD Evaluation for Secure Objects Incorporating Secure Envelopes
The Common Criteria for Information Technology Security Evaluation (abbreviated as Common Criteria or CC) is an international standard (ISO/IEC 15408) for computer security certification. There are 23 country's around the globe that are currently signed up as partners which include Australia, The US and the UK.
The Evaluation Assurance Level (EAL1 through to EAL7) of an IT product or system is a numerical grade assigned following the completion of a Common Criteria security evaluation, an international standard in effect since 1999.
"EAL4 permits a developer to gain maximum assurance from positive security engineering based on good commercial development practices which, though rigorous, do not require substantial specialist knowledge, skills, and other resources. EAL4 is the highest level at which it is likely to be economically feasible to retrofit to an existing product line. EAL4 is therefore applicable in those circumstances where developers or users require a moderate to high level of independently assured security in conventional commodity TOEs and are prepared to incur additional security-specific engineering costs."
The Evaluated Products List (EPL) is the definitive list of certified information technology products for use by Australian and New Zealand Government agencies in the protection of official information as required by the Information Security Manual (ISM).
The Information Security Manual (ISM), the authoritative source for guidance on IT security matters for Australian Government agencies, contains the circumstances in which Australian Government consumers should or must use IT products from the EPL.