atsec information security Evaluates IBM z/OS V1R7
Market Wire, March, 2006
atsec information security corporation, an independent, standards-based IT (information technology) security consulting and evaluation services company announced the completion of its security evaluation of the IBM z/OS V1R7. The operating system received Common Criteria (CC) certification at evaluation assurance level (EAL) 4 .
The challenge? Evaluate IBM z/OS, the world's most complex operating system, at its highest ever level of scrutiny and complete this feat in less than a year. There aren't more than a handful -- a very small handful -- of providers with the experience and confidence needed to take on a task of this order. Among that small set of labs, atsec information security stands head and shoulders above the rest as the world's leading evaluator of large, complex operating systems.
atsec's reputation for excellence and leadership in the Common Criteria industry is built on its consistent record of success in completing evaluation of complex products at ambitious assurance levels. It's not surprising that achieving certification of this class of products presents much larger challenges than evaluating simple applications. All aspects of evaluation are more difficult to achieve from design to test. Beyond that, evaluation of large, complex products tests the Common Criteria standard itself. atsec has never shied away from playing a leadership role in working through the inherent limitations of the standard to adapt it for this larger role.
Operating system evaluation is the greatest test of competence in the field, and from early in its history as a Common Criteria evaluation lab, atsec has led the way in operating system evaluations under both the German BSI and U.S. CCEVS Schemes. atsec's record of evaluation at this level since 2002 includes evaluations of IBM AIX 5.2; six Linux versions on five different platforms; IBM z/OS V1R6 at the EAL3 level, as well as the zSeries-based z/VM and PR/SM virtual machine and logical partitioning products.
Of the 42 successful operating system evaluations performed worldwide, as listed on the official Common Criteria Portal Web site ( www.commoncriteriaportal.org ), 22 were performed by atsec. This list does not yet include the recently finished evaluation of Red Hat Enterprise Linux 4 and the evaluation of z/OS V1R7. Evaluation of the z/OS V1R7 at the rigorous EAL4 level is the most challenging undertaking yet in this series of complex evaluation projects, demonstrating again the world leadership of atsec in the Common Criteria evaluation of operating systems.
atsec has completed more than 30 evaluations since its initial accreditation as a Common Criteria lab by the German BSI Scheme in 2002. Accreditation by the U.S. CCEVS Scheme followed in 2005. Today, the company's security experts work with confidence under both Schemes to offer quality results and maximum flexibility.
The scope of atsec's Common Criteria lab accreditations qualify atsec at the highest currently available level. atsec is accredited to perform evaluations up to and including EAL4 . In addition, atsec is fully eligible to work in direct partnership with either Scheme to conduct evaluations at EAL 5-7. In addition, the company has already completed two EAL5 evaluations of IBM PR/SM products.
atsec's leadership in the Common Criteria industry is also demonstrated by its commitment to helping shape the standard itself. This level of involvement not only includes helping to test new versions of the standard and contribute to Scheme publications, but also includes pushing the boundaries of the standard by applying it to large, complex systems. atsec has recently performed a prototype evaluation of Linux for the main aspects of the assurance level EAL 4 as a test of the draft Common Criteria v.3 standard.
The long experience and many successes of atsec's evaluation staff have built the company's industry-leading ability to deliver complex evaluations in short time frames. The z/OS EAL 4 evaluation has finished less than one year after the z/OS EAL3 evaluation, and just two months after successful conclusion of the Red Hat Enterprise Linux 4 CAPP/EAL4 Common Criteria certification, also for IBM. This is important because in the world of Common Criteria evaluations, time is very definitely money. Sponsors begin to earn back their investment when the certification is finished so there is tremendous value in working with a partner who can complete the process efficiently.
Beyond its enviable record of successful, timely completion of complex evaluations, atsec has also built its reputation on the quality of its evaluation deliverables. Interim and final reports reveal thoughtful analysis of the content of document evidence presented (not just a cursory look at the titles of documentation evidence) and provide real value to sponsors, going well beyond simply filling out a checklist of requirements to achieve certification.
About atsec information security
atsec information security is an independent, standards-based IT (information technology) security consulting and evaluation services company that combines a business-oriented approach to information security with in-depth technical knowledge and global experience. atsec launched its U.S. business in May 2003, building on extensive success in Europe dating back to 2000. atsec leverages its deep security, process, and standards expertise to consult on a wide range of IT security needs, enabling clients to establish integrated security management procedures in order to manage security risk and improve data, product, and business process reliability. atsec works with leading global companies such as IBM, HP, BMW, SGI, Swisscom, RWE, and Vodafone. For more information, please visit http://www.atsec.com/01/zOS .
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- "Do not rely on a single economy" ; Larsen and Toubro (L and T) was affected due to the slowdown particularly the products businesses, which include switchgears, construction equipment and industrial bars.
- "The first deliberate call we took was not to lay off anybody" ; The diversified group decided to reskill all surplus workers.
- "Government had to step up its demand" ; The downturn affected the government as much as India Inc. The outgoing advisor to the Government of India details its impact and its lessons.
- "Help your customers even in difficult times" ; Oil was at an all-time high at over $135 per barrel just before the financial meltdown. Then oil crashed to a low of $35 per barrel in January this year, bringing down any fresh demand for pipes fr
- "You have to be visible as a leader" ; Transparency is a standard operating procedure for communications during a downturn.
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- Using object-oriented analysis and design over traditional structured analysis and design
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- Design a commission plan that drives sales - Sales Commissions
- The best time to buy a car: December is not the only time to get a new set of wheels. We'll show you when to make your move to the dealer's showroom


