This Site Has Been Decomissioned

This site remains for historical review purposes only. Any changes made to the data will not be saved.

 
NIAP: U.S. Government Approved Protection Profile - collaborative Protection Profile for Application Software Version 1.0e

NIAP Oversees Evaluations of Commercial IT Products for Use in National Security Systems
Questions?  We're here to help
  NIAP  »»  Protection Profiles  »»  Approved PPs  »»  Details  
U.S. Government Approved Protection Profile - collaborative Protection Profile for Application Software Version 1.0e

Short Name: cpp_app_sw_v1.0e

Technology Type: Application Software

CC Version: 3.1

Date: 2024.06.17

Conformance Claim: None

Protection Profile [PDF]

Supporting Docs [PDF]


 

PP OVERVIEW

This is a Collaborative Protection Profile (cPP) whose Target of Evaluation (TOE) is software applications. Under this cPP software applications can be categorized under the following broad categories:

  1. Enterprise Server Applications

  2. Enterprise Server Applications with their Agent(s)

  3. Enterprise Desktop Applications

  4. Enterprise-grade Mobile Applications

This cPP is the Base-PP against which all of the above categories of software applications may be evaluated. The Base-PP is sufficient to evaluate Enterprise Desktop Applications. Separate PP-Modules will provide additional requirements for Enterprise Server Applications and Enterprise-grade Mobile Applications

In addition to the above categories there are large number of applications (Desktop and Mobile) that fall under “Consumer-grade” category. While such applications could be evaluated under the Application Software cPP, it is not the intention of this iTC to specifically address this category. The iTC doesn’t believe the consumer grade app ecosystem would support the historical cost and timelines associated with a Common Criteria evaluation.

One more way (and perhaps a more useful way in the context of creating SFRs) to categorize apps is based on type of installation/deployment. The following categories are in scope of the first iteration of the cPP:

  1. Traditional software running on an execution environment, e.g. enterprise agent applications/sensors

  2. Software appliance type of applications, e.g. enterprise management application

  3. Distributed applications, e.g. enterprise resource planning systems

  4. Virtualized and Containerized applications (e.g. running in a Docker container)

The following categories are out of scope of the first iteration of the cPP:

  1. Software defined network appliances

  2. Web applications

  3. Applications running on bare metal i.e. directly on hardware without an execution environment such as operating system.

This U.S. Government Approved Protection Profile is not assigned to any Validated Products

This U.S. Government Approved Protection Profile does not have any related Technical Decisions

Please forward any Protection Profile specific comments to the applicable Technical Rapid Response Team (TRRT).

Please forward any general questions to our Q&A tool.

 
Site Map              Contact Us              Home