<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <title>NIAP CCEVS: LabGrams</title>
    <link>http://www.niap-ccevs.org/labgrams</link>
    <description>LabGrams are a means of communication between the CCEVS and CCTLs (including applicant CCTLs). They are distributed electronically to subscribers of the ccevs-labs &amp; ccevs-applicants mail distribution lists. LabGrams deliver guidance and CCEVS policy until such time that CCEVS publications are updated.</description>
    <pubDate>Tue, 02 Jun 2009 00:00:00 GMT</pubDate>
    <lastBuildDate>Thu, 22 Oct 2009 17:34:21 GMT</lastBuildDate>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/niap-ccevs/labgrams" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
      <title>Labgram #55, Valgram #76 - Update on NIAP CCEVS Strategy</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/hBhfWL2rTvA/</link>
      <description>&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;All,&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;As most of you have probably seen, the Army just released their new Letter to Industry.&amp;nbsp; Since they cite the NEW NIAP Strategy in their letter, I wanted to provide an update on the status of the new Standard PPs and the updates to the Basic Robustness PPs that we&amp;rsquo;re trying to get accomplished by 1 Oct 09.&amp;nbsp; Below is a somewhat prioritized list of these PPs:&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;New Standard Lost Laptop PP &amp;ndash; to be published very soon&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;New Standard USB PP &amp;ndash; being developed&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Updated Basic Robustness VPN PP &amp;ndash; being worked&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Updated Basic Robustness Firewall PP &amp;ndash; being worked&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Updated Basic Robustness Router PP &amp;ndash; being worked&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Updated Basic Robustness IDS PP &amp;ndash; being worked&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Updated Basic Robustness OS PP &amp;ndash; being worked&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Updated Basic Robustness Database PP &amp;ndash; being reviewed&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Updated Basic Robustness Anti-Virus&amp;nbsp;PP &amp;ndash; being reviewed&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: black; mso-themecolor: text1;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: black; mso-themecolor: text1;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Times New Roman;"&gt;We do NOT yet have a prioritized list of the NEW PPs that will be written.&amp;nbsp; We will be asking labs and customers for their recommendations in the very near future.&lt;br /&gt;&lt;br /&gt;Thanks,&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: black; mso-themecolor: text1;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: black; mso-themecolor: text1;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Times New Roman;"&gt;Audrey&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Audrey M. Dale, CISSP&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Director, NIAP CCEVS&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;NSA Commercial Solutions Center&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;a href="mailto:amdale@missi.ncsc.mil"&gt;&lt;span style="font-size: small; color: #3333aa; font-family: Times New Roman;"&gt;amdale@missi.ncsc.mil&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small; font-family: Times New Roman;"&gt;Tel 410-854-4458&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/hBhfWL2rTvA" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 02 Jun 2009 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/55/</feedburner:origLink></item>
    <item>
      <title>Labgram #54, Valgram #74, RSA Conference Certificate Presentation Deadlines</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/StXVj7FvLOk/</link>
      <description>&lt;div style="border-right: medium none; padding-right: 0in; border-top: medium none; padding-left: 0in; padding-bottom: 6pt; border-left: medium none; padding-top: 0in; border-bottom: #999999 1pt dotted; mso-element: para-border-div; mso-border-bottom-alt: dotted #999999 .75pt;"&gt;&lt;span style="font-family: Consolas;"&gt;Validators and Labs,&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;The Director CCEVS will be presenting certificates at the RSA&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;Conference 20-24 April 2009 in San Francisco.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;The following timeline will be used for determining whether a product/PP can be awarded a certificate for presentation at the award ceremony during the conference.&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;*Lab must deliver all final updated documentation to validator on/before 13 Feb 2009.&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;*Validator must deliver Final Package, ST, VR, ETR, etc. to CCEVS on/before 06 March 2009 and,&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;*Vendor &amp;amp; Lab must complete, sign, and deliver all required forms (F8002, F8003, F8004) to CCEVS on/before 06 March 2009.&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;In addition, if the vendor plans to issue a product announcement at the conference that needs CCEVS review, then the Vendor must deliver the draft announcement to the CCEVS on/before 20 March 2009.&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;Please plan accordingly and drop me a line to let me know what evaluations you expect to finish up in time for RSA.&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;Thank you.&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;Regards, Randy&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt; color: #333333; font-family: "&gt;Randy Sullivan&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; color: #333333; font-family: "&gt;NIAP CCEVS Staff&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; color: #333333; font-family: "&gt;410-854-4458 office&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; color: #333333; font-family: "&gt;410-854-6615 fax&lt;/span&gt;&lt;span style="color: #333333; font-family: "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p&gt;&#xD;
&lt;p&gt;&lt;span style="font-size: x-small; font-family: Courier New;"&gt;(U) The information contained herein that is marked (U//FOUO) is for the exclusive use of Government and Contractor personnel with a need-to-know for NIAP CCEVS information. &lt;/span&gt;&lt;span style="font-size: x-small; font-family: Courier New;"&gt;Such information is specifically prohibited from posting on unrestricted bulletin boards or other unlimited access applications.&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/StXVj7FvLOk" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 13 Jan 2009 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/54/</feedburner:origLink></item>
    <item>
      <title>Labgram #53, VOR Scheduling</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/o8M4Si3OpTg/</link>
      <description>&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;CCTLs,&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;Just wanted to let you know the VOR schedule for FY09 can be found on our website at &lt;/span&gt;&lt;a href="http://www.niap-ccevs.org/cc-scheme/vor_schedule.cfm"&gt;&lt;span style="color: #800080; font-family: Consolas;"&gt;http://www.niap-ccevs.org/cc-scheme/vor_schedule.cfm&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Consolas;"&gt;.&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;"&gt;In recent months, CCTL personnel have been contacting Validators directly to coordinate upcoming VORs prior to the read-ahead submission due date. Due to our limited validation resources, this is causing us problems with prioritizing validation activities. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;Please remember that all VOR activity, including any new VORs and follow-ups to failed VORs, must be coordinated with CCEVS prior to contacting the Validation team. This will allow CCEVS to continue to schedule and prioritize validation activities as stated in Policy #16, Validator Oversight Review (VOR) Scheduling Priorities.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Thanks very much for your cooperation.&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/o8M4Si3OpTg" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 24 Oct 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/53/</feedburner:origLink></item>
    <item>
      <title>Labgram #52, Valgram #73, Update Scheme Publications and Policy Letters</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/FrZzQQ-L7mo/</link>
      <description>&lt;p&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;All,&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&#xD;
&lt;div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt;"&gt;           In preparation for the upcoming Voluntary Periodic Assessement (VPA) of CCEVS, all of our Scheme Publications and Policy Letters were reviewed and revised where necessary. The pulications had major revisions and therefore will need to be read in their entirety.  The changes made to the policies are outlined below.&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&#xD;
&lt;div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 1 &amp;ndash; Language in STs, ETRs, VPL &amp;amp; VRs &amp;ndash; remained the same&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 2 &amp;ndash; Reuse of Previous Evaluation Results &amp;amp; Evidence &amp;ndash; remained the same&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 3 &amp;ndash; TOE Security Targets Claiming Conformance to Protection Profiles &amp;ndash; &lt;i&gt;&lt;span style="font-style: italic;"&gt;updated/re-dated it to remove statement that we would accept evaluations against draft PPs&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 4 &amp;ndash; Inactive Evaluations &amp;ndash; was updated/re-dated &amp;ndash; &lt;i&gt;&lt;span style="font-style: italic;"&gt;made some wording changes to a &amp;amp; b &lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 6 &amp;ndash; Location of CCTL Evaluation Testing Activities - &lt;b&gt;&lt;i&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;rescinded since we added that info to the appropriate Pub 4&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 7 &amp;ndash; Evaluation Conflict of Interest - &lt;b&gt;&lt;i&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;rescinded since we added the info from it to Pubs 1 and 4&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 8 -  Rules for Component Evaluations under CCEVS &amp;ndash; &lt;i&gt;&lt;span style="font-style: italic;"&gt;was transferred onto letterhead to match format of all other policy letters, no content changes made.&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 9 &amp;ndash; Crypto in Common Criteria Evaluations &amp;ndash;  remains the same for now&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 10 &amp;ndash; Acceptance of Security Targets (STs) Into NIAP CCEVS Evaluation &amp;ndash; &lt;i&gt;&lt;span style="font-style: italic;"&gt;updated/re-dated with some minor wording changes on VORs &amp;ndash; &lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;i&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt; font-style: italic;"&gt;            &lt;b&gt;&lt;span style="font-weight: bold;"&gt;Addendum to Policy 10 - rescinded&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 11 &amp;ndash; Candidate CCTL Policy &amp;ndash; remained the same&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 12 &amp;ndash; Letter of Interest for CCEVS Evaluations &amp;ndash; &lt;i&gt;&lt;span style="font-style: italic;"&gt;updated/re-dated with minor wording corrections&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 13 &amp;ndash; Acceptable TOE&amp;rsquo;s for Evaluation and it&amp;rsquo;s Addendum &amp;ndash; remained the same&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 15 &amp;ndash; Mandatory Inclusion of Audit Generation Functionality in TOEs &amp;ndash; &lt;i&gt;&lt;span style="font-style: italic;"&gt;updated/re-dated with minor word changes &lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 16 &amp;ndash; Validator Oversight Review (VOR) Scheduling Priorities &amp;ndash; remained the same&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 17 &amp;ndash; Effects of Vulnerabilities in Evaluated Products &amp;ndash; remained the same&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 18 &amp;ndash; Time Limits on CCEVS Evaluations &amp;ndash; remained the same&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;Policy 19 &amp;ndash; Requirements for Evaluations with Components above EAL 4 &amp;ndash; updated&lt;i&gt;&lt;span style="font-style: italic;"&gt;/re-dated para 2 was modified to say CCTLs had to create methodologies where there were none&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&#xD;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style=""&gt;Thanks.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt; &lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;&lt;span style="font-weight: bold; font-size: 10pt; font-style: italic;"&gt;Dianne Hale&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;NIAP CCEVS Staff&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;410-854-4458 office&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt;"&gt;410-854-6615 fax&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/FrZzQQ-L7mo" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 11 Sep 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/52/</feedburner:origLink></item>
    <item>
      <title>Labgram #51, Valgram #72, Policy Letter #19-update 1, Requirements for Evaluations with Components above Evaluation Assurance Level (EAL) 4</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/EJwmbP37QXk/</link>
      <description>&lt;p&gt;All,&lt;/p&gt;&#xD;
&lt;p&gt;Policy Letter 19 has been updated to incorporate &amp;quot;if the NSA evaluation results in product updates, the CCTL must make the necessary evidence updates as required.  Please review this policy to be aware of the changes.&lt;/p&gt;&#xD;
&lt;p&gt;Rebecca Galanakis&lt;/p&gt;&#xD;
&lt;p&gt;NIAP CCEVS Staff&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/EJwmbP37QXk" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 23 Apr 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/51/</feedburner:origLink></item>
    <item>
      <title>Labgram #49, Updated Monthly Schedule Reporting</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/dAq0OrW-r2w/</link>
      <description>&lt;p&gt;CCTLs,&lt;/p&gt;&#xD;
&lt;p&gt;The VOR process, along with the Time Limit Policy and Inactive Evaluations, has eliminated the need for detailed schedule information. We do&amp;nbsp;however need the schedules to project current and future Validator resources and to keep our &amp;quot;in evaluation&amp;quot; listing current.&amp;nbsp; Therefore, we have revised the format for the monthly schedules to include only specific milestones.&amp;nbsp;&lt;/p&gt;&#xD;
&lt;p&gt;Effective immediately,&amp;nbsp; each CCTL is required to submit a spreadsheet consisting of the VID, Product Name, projected TVOR date (projected testing date for those evaluations that do not require a Test VOR), projected FVOR date,&amp;nbsp; and projected Completion Date.&amp;nbsp;Each month, the spreadsheet must be updated and&amp;nbsp;any changes&amp;nbsp;highlighted for ease of database entry.&lt;/p&gt;&#xD;
&lt;p&gt;CCEVS will be forwarding a blank template to each CCTL listing all current projects to start with. Please also note that effective 1 April all new evaluations will be required to have Test VORs in accordance with our VOR Guide.&lt;/p&gt;&#xD;
&lt;div&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;&lt;span style="font-weight: bold; font-size: 10pt; font-style: italic"&gt;Randy Sullivan&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;NIAP CCEVS Staff&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;410-854-4458 office&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;410-854-6615 fax&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/dAq0OrW-r2w" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 28 Mar 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/49/</feedburner:origLink></item>
    <item>
      <title>Labgram #50, Valgram #71, Validation Oversight Review (VOR) Evaluators and Validators Guide 2.0</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/Q8nRjsFZGFU/</link>
      <description>&lt;p&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt;"&gt;All,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt;"&gt;Please be advised that the updated VOR Guide has been posted to the CCEVS web site on our Scheme Publications page under CCEVS Guidance Documents (&lt;a href="http://www.niap-ccevs.org/cc-scheme/policy/ccevs/guidance_docs.cfm"&gt;http://www.niap-ccevs.org/cc-scheme/policy/ccevs/guidance_docs.cfm&lt;/a&gt;).&lt;span&gt; Effective immediately all VORs must follow the process outlined in this guide. Please also note that all new evaluations must now have Test VORs.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span&gt;Thanks.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; font-style: italic;"&gt;Dianne Hale&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt;"&gt;NIAP CCEVS Staff&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt;"&gt;410-854-4458 office&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt;"&gt;410-854-6615 fax&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/Q8nRjsFZGFU" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 28 Mar 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/50/</feedburner:origLink></item>
    <item>
      <title>Labgram #47, Valgram #69, Policy #19, Requirements for Evaluations with Components above EAL4</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/ygN_PRCojTE/</link>
      <description>&lt;p&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt"&gt;All,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please be advised that a new policy has been posted to the CCEVS web site, Policy #19:&amp;nbsp; &lt;span style="layout-grid-mode: line"&gt;Requirements for Evaluations with Components above EAL4.&amp;nbsp;This&amp;nbsp;policy replaces both Policy 5,&amp;nbsp;Evaluation TOEs at Evaluated Assurance Levels (EALs) Above 4 and Policy 14,&amp;nbsp;Requirements for Committing NSA Resources to CCEVS Evaluations. &amp;nbsp;Please read and become familiar with the policy, as appropriate.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt"&gt;&lt;span style="layout-grid-mode: line"&gt;Thanks.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; font-style: italic"&gt;Dianne Hale&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt"&gt;NIAP CCEVS Staff&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt"&gt;410-854-4458 office&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt"&gt;410-854-6615 fax&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/ygN_PRCojTE" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 27 Mar 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/47/</feedburner:origLink></item>
    <item>
      <title>Labgram #48, Valgram #70, Policy #4, Inactive Evaluations</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/848dfn2VnJk/</link>
      <description>&lt;p&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt"&gt;All,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please be advised that&amp;nbsp;Policy 4,&amp;nbsp;Inactive Evaluations&amp;nbsp;has been updated and posted on CCEVS web site.&amp;nbsp;&lt;span style="layout-grid-mode: line"&gt;&amp;nbsp;&amp;nbsp;Please read and become familiar with the policy, as appropriate.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt"&gt;&lt;span style="layout-grid-mode: line"&gt;Thanks.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-weight: bold; font-size: 10pt; font-style: italic"&gt;Dianne Hale&lt;/span&gt;&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt"&gt;NIAP CCEVS Staff&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt"&gt;410-854-4458 office&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: 10pt"&gt;410-854-6615 fax&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/848dfn2VnJk" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 27 Mar 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/48/</feedburner:origLink></item>
    <item>
      <title>Labgram #46, Valgram #68, Policy #18, Time Limits on CCEVS Evaluations</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/VOfYbin8Pg8/</link>
      <description>&lt;p&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;All,&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&#xD;
&lt;div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please be advised that a new policy has been posted to the CCEVS web site, Policy #18:&amp;nbsp; &lt;span style="layout-grid-mode: line"&gt;Time Limits on CCEVS Evaluations.&amp;nbsp; Please read and become familiar with the policy, as appropriate.&amp;nbsp; In addition, please be sure to notify your vendors of this new policy. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt"&gt;&lt;span style="layout-grid-mode: line"&gt;Thanks.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&amp;nbsp;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;&lt;span style="font-weight: bold; font-size: 10pt; font-style: italic"&gt;Dianne Hale&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;NIAP CCEVS Staff&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;410-854-4458 office&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;410-854-6615 fax&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/VOfYbin8Pg8" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 04 Feb 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/46/</feedburner:origLink></item>
    <item>
      <title>Labgram #46, Valgram #68, Policy #18, Time Limits on CCEVS Evaluations</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/VOfYbin8Pg8/</link>
      <description>&lt;p&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;All,&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&#xD;
&lt;div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please be advised that a new policy has been posted to the CCEVS web site, Policy #18:&amp;nbsp; &lt;span style="layout-grid-mode: line"&gt;Time Limits on CCEVS Evaluations.&amp;nbsp; Please read and become familiar with the policy, as appropriate.&amp;nbsp; In addition, please be sure to notify your vendors of this new policy. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;span style="font-size: 10pt"&gt;&lt;span style="layout-grid-mode: line"&gt;Thanks.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&amp;nbsp;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;&lt;span style="font-weight: bold; font-size: 10pt; font-style: italic"&gt;Dianne Hale&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;NIAP CCEVS Staff&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;410-854-4458 office&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;div&gt;&lt;font size="2"&gt;&lt;span style="font-size: 10pt"&gt;410-854-6615 fax&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&#xD;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/VOfYbin8Pg8" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 04 Feb 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/46/</feedburner:origLink></item>
    <item>
      <title>Labgram #45, Valgram #67, Policy #17, Effects of Vulnerabilities in Evaluated Products</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/5kuT9uVCbHs/</link>
      <description>&lt;p&gt;All,&lt;/p&gt;&#xD;
&lt;p&gt;A new policy has been posted to the CCEVS web site. Please read and become familiar with the policy, as appropriate.&lt;/p&gt;&#xD;
&lt;p&gt;Thanks, Becky Galanakis&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/5kuT9uVCbHs" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 23 Jan 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/45/</feedburner:origLink></item>
    <item>
      <title>Labgram #45, Valgram #67, Policy #17, Effects of Vulnerabilities in Evaluated Products</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/5kuT9uVCbHs/</link>
      <description>&lt;p&gt;All,&lt;/p&gt;&#xD;
&lt;p&gt;A new policy has been posted to the CCEVS web site. Please read and become familiar with the policy, as appropriate.&lt;/p&gt;&#xD;
&lt;p&gt;Thanks, Becky Galanakis&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/5kuT9uVCbHs" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 23 Jan 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/45/</feedburner:origLink></item>
    <item>
      <title>Labgram #44, Valgram #66, New Requirement for End of Evaluation Survey (F8004)</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/YAuksVDLdQw/</link>
      <description>&lt;div class="Section1"&gt;&#xD;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;All,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please be advised that vendor's are now required to submit an End of Evaluation Survey for all &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;NIAP evaluations completed from this date forward in order to be posted to the Validated Products &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;List (VPL). &amp;nbsp;This form, (F8004) &amp;ldquo;NIAP CCEVS End of Evaluation Survey,&amp;rdquo; can be found on our web site at:&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;&lt;a title="http://www.niap-ccevs.org/cc-scheme/forms/" href="http://www.niap-ccevs.org/cc-scheme/forms/"&gt;http://www.niap-ccevs.org/cc-scheme/forms/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;The survey may be submitted through the CCTL as part of the final package OR faxed directly to CCEVS &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;at 410-854-6615. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;span style="font-size: 10pt; font-family: Arial"&gt;We welcome all vendors with prior NIAP evaluations to complete a survey!&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#xD;
&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&#xD;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/YAuksVDLdQw" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 18 Jan 2008 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/44/</feedburner:origLink></item>
    <item>
      <title>Validator Oversight Review (VOR) Scheduling Priorities</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/Q41OEoCykk0/</link>
      <description>&lt;p&gt;All,&lt;/p&gt;&#xD;
&lt;p&gt;A new policy has been posted to the CCEVS web site.  Please read and become familiar with the policy, as appropriate.&lt;/p&gt;&#xD;
&lt;p&gt;Thanks, Becky Galanakis&lt;/p&gt;&#xD;
&lt;p&gt;&lt;a href="http://www.niap-ccevs.org/cc-scheme/policy/ccevs/policy-ltrs.cfm"&gt;http://www.niap-ccevs.org/cc-scheme/policy/ccevs/policy-ltrs.cfm&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/Q41OEoCykk0" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 05 Dec 2007 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/43/</feedburner:origLink></item>
    <item>
      <title>Labgram #42, Valgram #64, Letter of Interest Requirement for Acceptance into CCEVS Evaluation</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/XyUPVdBRs3M/</link>
      <description>&lt;p&gt;Please read the new policy #12 with subject above outline the requirement for a letter of interest (LOI) to enter the CCEVS evaluation process. The new policy is effective 1 Oct 07. If you have any questions feel free to contact me or anyone in the NIAP CCEVS office on 410-854-4458.&lt;/p&gt;&#xD;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/XyUPVdBRs3M" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 02 Oct 2007 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/42/</feedburner:origLink></item>
    <item>
      <title>Labgram #41, Valgram #63, Subject:  Vendor Attendance at Validator Oversight Reviews (VORs)</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/6h9wMKNzvk4/</link>
      <description>&lt;p&gt;CCEVS strongly discourages the attendance of vendors at VORs.  VORs are intended to be frank and open technical discussions between CCTL evaluators and CCEVS validators which could be hampered or unduly influenced by vendor attendance.  CCEVS shall consider, on a case-by-case basis, exceptions to this policy.  Vendor requests for an exception must be submitted in writing with appropriate justification through the corresponding CCTL to CCEVS.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/6h9wMKNzvk4" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 29 Jun 2007 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/41/</feedburner:origLink></item>
    <item>
      <title>Labgram #40, Valgram #62, Revised Crypto Policy</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/AXIb4LEpHjg/</link>
      <description>&lt;p&gt;CCTLs,&lt;/p&gt;&#xD;
&lt;p&gt;Policy 9 was issued in June of 2005 as a temporary measure to clarify the CCEVS documentation needed when a Common Criteria evaluation contains crypto. The attached two documents are aimed at building upon Policy 9 and are to be used by the CCTLs as described below.&lt;/p&gt;&#xD;
&lt;p&gt;&amp;ldquo;Specifying Requirements in Security Targets&amp;rdquo; addresses how cryptographic protocols are to be specified in Security Targets. &amp;ldquo;Evaluation of Cryptographic Protocols and Implementation&amp;quot; provides guidance on how cryptographic protocols are to be evaluated in accordance with CCEVS expectations. By 22 January 2007 each CCTL must select a current evaluation containing cryptography on which to apply these documents. Between 22 January and 31 May 2007, the CCTLs will collect and provide CCEVS with feedback regarding the guidance documents.&lt;/p&gt;&#xD;
&lt;p&gt;During this four month trial-use period, please submit your comments and observations regarding the documents to Dave Dignan (dmdigna@niap-ccevs.org) at CCEVS. Upon completion of the four-month trial-use period, the documents will be updated and the documents will be posted as policy on this CCEVS web site.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;CCEVS Validators:&lt;/strong&gt; Please become familiar with these documents and reference them as needed for   your evaluations containing cryptography.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/AXIb4LEpHjg" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 05 Jan 2007 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/40/</feedburner:origLink></item>
    <item>
      <title>Labgram #40, Valgram #62, Revised Crypto Policy</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/AXIb4LEpHjg/</link>
      <description>&lt;p&gt;CCTLs,&lt;/p&gt;&#xD;
&lt;p&gt;Policy 9 was issued in June of 2005 as a temporary measure to clarify the CCEVS documentation needed when a Common Criteria evaluation contains crypto. The attached two documents are aimed at building upon Policy 9 and are to be used by the CCTLs as described below.&lt;/p&gt;&#xD;
&lt;p&gt;&amp;ldquo;Specifying Requirements in Security Targets&amp;rdquo; addresses how cryptographic protocols are to be specified in Security Targets. &amp;ldquo;Evaluation of Cryptographic Protocols and Implementation&amp;quot; provides guidance on how cryptographic protocols are to be evaluated in accordance with CCEVS expectations. By 22 January 2007 each CCTL must select a current evaluation containing cryptography on which to apply these documents. Between 22 January and 31 May 2007, the CCTLs will collect and provide CCEVS with feedback regarding the guidance documents.&lt;/p&gt;&#xD;
&lt;p&gt;During this four month trial-use period, please submit your comments and observations regarding the documents to Dave Dignan (dmdigna@niap-ccevs.org) at CCEVS. Upon completion of the four-month trial-use period, the documents will be updated and the documents will be posted as policy on this CCEVS web site.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;CCEVS Validators:&lt;/strong&gt; Please become familiar with these documents and reference them as needed for   your evaluations containing cryptography.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/AXIb4LEpHjg" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 05 Jan 2007 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/40/</feedburner:origLink></item>
    <item>
      <title>Labgram #39, Valgram #61, Validation Oversight Process: Evaluators and Validators Guide</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/lapzAxSxTHU/</link>
      <description>&lt;p&gt;CCTLs and Validators,&lt;/p&gt;&#xD;
&lt;p&gt;Enclosed is the Validation Oversight Review (VOR) Process Document, written to support the NIAP CCEVS migration to the new evaluation oversight process. Please read the attached document and become familiar with the responsibilities for VOR participants, particularly those pertaining to you.&lt;/p&gt;&#xD;
&lt;p&gt;As CCEVS implements the VOR process, updates may be made to this document, but not until after 1 January 2007. Starting in December 2006, all VORs must follow the process outlined in the enclosed document.&lt;/p&gt;&#xD;
&lt;p&gt;If you have comments regarding the VOR Training Guide please submit them to CCEVS at your earliest opportunity.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/lapzAxSxTHU" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 26 Oct 2006 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/39/</feedburner:origLink></item>
    <item>
      <title>Labgram #36, Valgram #58 -- Implementation of New MSR Templates (Updated 1/04/06)</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/nJgX4VeYumg/</link>
      <description>&lt;p&gt;CCTLs,&lt;/p&gt;&#xD;
&lt;p&gt;As we discussed at the CCTL meeting last week, attached is the updated template we are mandating that all CCTLs use when submitting MSRs to CCEVS validators. Since our previous approach of not specifying a format and timetable did not provide constructive metrics, we feel it is imperative that all labs report in the same format &amp;amp; calendar month cycle. We'd like to implement the Part I CCTL MSR as soon as possible, but no later than the December 2005 reporting period. As a reminder CCTL MSRs are due to your lead validator by the 5th calendar day of the month (if it falls on a weekend, it will be due the following Monday). The validators have until the 10th working day of the month to review the CCTL MSR and submit their MSR Part II along with Part I to CCEVS as one document. The validator is responsible for sending a copy of their MSR (Part II) back to the lab. Attached are templates for the Part I (CCTL MSR) and Part II (Validator MSR).&lt;/p&gt;&#xD;
&lt;p&gt;If you have any questions please contact me. Regards, Becky&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;CCEVS Validators:&lt;/strong&gt; Please begin using the Part II MSR for the Oct 05 reporting period which is due to CCEVS on 10 November 05. The labs have been given some time to incorporate the new MSR into their procedures, so if you haven't received the Part I MSR from the CCTL please still submit Part II by 10 November 05. MSRs should marry up again in Dec 05.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/nJgX4VeYumg" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 20 Oct 2005 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/36/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #10, Acceptance of Security Targets into NIAP CCEVS Evaluation - Additional Information</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/gCgpPHQTuOA/</link>
      <description>&lt;p&gt;CCTLs,&lt;/p&gt;&#xD;
&lt;p&gt;This labgram provides information about the implementation of CCEVS Policy Letter #10.&lt;/p&gt;&#xD;
&lt;p&gt;CCEVS Policy Letter #10 lists the minimum requirements for ST acceptance into evaluation.&lt;/p&gt;&#xD;
&lt;p&gt;Upon receipt of an EAP, we will assign a senior validator to perform a Policy 10 ST review. The validator will be allowed 3-4 business days to perform the review, at which time the ST will be judged as acceptable to enter evaluation, or as deficient per Policy Letter #10. If there are deficiencies, these will be forwarded to the CCTL for correction and ST resubmission. The ST should be resubmitted to the ceap@niap-ccevs.org, with a subject line indicating that it is a Policy Letter #10 ST resubmission.&lt;/p&gt;&#xD;
&lt;p&gt;This process will iterate until the ST is acceptable per Policy Letter #10. Once the ST is acceptable, a validator will be assigned to review the EAP and schedule the kick-off meeting as we have always done.&lt;/p&gt;&#xD;
&lt;p&gt;Please inform your vendors that this ST review means that we are requiring the full 30 days from the time of EAP receipt until the validator is assigned, and it may take longer depending on the calibre of the ST and the number of iterations until the ST is updated and accepted.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/gCgpPHQTuOA" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 04 Oct 2005 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/35/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #10, Acceptance of Security Targets into NIAP CCEVS Evaluation</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/oqI2Sf5Y4IE/</link>
      <description>&lt;p&gt;A new CCEVS policy letter #10 has been posted to the CCEVS web site for clarifying what CCEVS will accept from Common Criteria Testing Laboratories (CCTLs) and Candidate-CCTLs when submitting an ST in an Evaluation Acceptance Package (EAP) for a new evaluation. Please become familiar with this policy letter.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/oqI2Sf5Y4IE" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 27 Jun 2005 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/34/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #10, Acceptance of Security Targets into NIAP CCEVS Evaluation</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/oqI2Sf5Y4IE/</link>
      <description>&lt;p&gt;A new CCEVS policy letter #10 has been posted to the CCEVS web site for clarifying what CCEVS will accept from Common Criteria Testing Laboratories (CCTLs) and Candidate-CCTLs when submitting an ST in an Evaluation Acceptance Package (EAP) for a new evaluation. Please become familiar with this policy letter.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/oqI2Sf5Y4IE" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 27 Jun 2005 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/34/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #9, Crypto in Common Criteria Evaluations</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/60NtALm25xo/</link>
      <description>&lt;p&gt;A new CCEVS policy letter #9 has been posted to the CCEVS web site for clarifying the CCEVS documentation needed when a Common Criteria evaluation contains crypto. Please become familiar with this document and begin using immediately.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/60NtALm25xo" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 15 Jun 2005 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/33/</feedburner:origLink></item>
    <item>
      <title>Content for MSR Reporting</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/eLDqr32kmeQ/</link>
      <description>&lt;p&gt;The CCEVS has agreement with the Common Criteria Testing Laboratories (CCTLs) that, at a minimum, the following content will be provided to the project's lead validator. CCTL management may choose to define a specific format across the board for all of the laboratories projects. In no way shall the validator dictate a specific format for content of MSRs.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;CCTL MSR Content:&lt;/strong&gt; &lt;br /&gt; &lt;strong&gt;Identify Validation ID (VID) Number.&lt;/strong&gt; As multiple projects from many of the same vendors are entering the scheme it is imperative that we all refer to the project by the same VID#. The lab will be given the VID# by CCEVS at the time the validator is assigned.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Identify Status of Evaluation.&lt;/strong&gt; Select only one category to correspond with what activity you are reporting. The categories are Activity/Normal, No Activity/30 days, No activity/60 days, and Recommend Terminate.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Identify Key Points of Contact.&lt;/strong&gt; At a minimum, the CCTL must identify the Lead Evaluator, Lead Validator, Validation Team Leader, and Sponsor Representative. If you would like to add others feel free to do so.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Identify (by classes) the CCTL deliverables and/or status of work performed.&lt;/strong&gt; This may be in the form of a spreadsheet or bulleted text, or any other way of getting the information across. Any "format" is deemed acceptable.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;Identify any problems/risks/concerns the CCTL has with the evaluation/validation.&lt;/strong&gt; The Senior Team Leaders will be responsible for developing a consistent monthly cycle between the CCTL, Validator and CCEVS Records which considers the following:&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;Date MSR is due from CCTL&lt;/li&gt;&#xD;
&lt;li&gt;Date coordination process between validator &amp;amp; CCTL is complete.&lt;/li&gt;&#xD;
&lt;li&gt;Date final MSRs will be sent to records.&lt;/li&gt;&#xD;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/eLDqr32kmeQ" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 18 Feb 2005 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/32/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy #7, Conflicts of Interest</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/9mxW_emkTBU/</link>
      <description>&lt;p&gt;1. The attached CCEVS policy is intended to clarify Section 3.3 of Scheme Publication # 1, Conflicts of Interest.&lt;/p&gt;&#xD;
&lt;p&gt;2. It is effective the date of this correspondence. CCEVS Policy #7 will be posted to the web site in the next content update.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/9mxW_emkTBU" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 22 Nov 2004 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/31/</feedburner:origLink></item>
    <item>
      <title>Addendum to CCEVS Policy #4, Inactive Validations</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/WViebQAIBXA/</link>
      <description>&lt;p&gt;1. The attached addendum is intended to clarify what constitutes evaluation activity for monthly validator reporting to CCEVS.&lt;/p&gt;&#xD;
&lt;p&gt;2. It is effective the date of this correspondence. CCEVS Policy #4 Addendum 1 will be posted to the web site in the next content update.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/WViebQAIBXA" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 12 Mar 2004 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/30/</feedburner:origLink></item>
    <item>
      <title>Maintenance and Re-Evaluation</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/p8ZW9px3R0A/</link>
      <description>&lt;p&gt;The CCEVS is pleased to acknowledge the recent international release of the CCRA Requirements on Assurance Continuity (CCIMB-2004-02-009, February 2004). It is available on the CCEVS website. This guidance is to be used by all CCEVS labs to address the topic of maintenance and re-evaluation. It formally supercedes all previous guidance issued by the CCEVS, including Scheme Publication 6.&lt;/p&gt;&#xD;
&lt;p&gt;The approach outlined in these requirements is that the sponsor will provide a report describing the changes made to the certified TOE, together with an analysis of the security impact of those changes. This report will then be reviewed by the scheme to determine whether these changes require any additional analysis by evaluators ("re-evaluation") or whether the changes are such that the analysis performed in producing the impact analysis report was sufficient ("maintenance").&lt;/p&gt;&#xD;
&lt;p&gt;These requirements present only the minimum mutually-recognized requirements on assurance maintenance and re-evaluation. They acknowledge that schemes may augment these requirements. If such additional guidance is found to be necessary in the future, then a new Scheme Publication on Re-evaluation and Maintenance will be issued. However, at this time, the CCEVS has no additional guidance to provide to its validators, evaluators, or TOE developers.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/p8ZW9px3R0A" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 13 Feb 2004 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/29/</feedburner:origLink></item>
    <item>
      <title>RSA Award Ceremony Deadlines</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/FFm_N3q-iRc/</link>
      <description>&lt;p&gt;The Director, CCEVS will be presenting certificates during the RSA Conference 23-27 February 2004 in San Francisco, California http://www.rsaconference.com/conf2004_portal.html. The following timeline will be used for determining whether a product/PP will be awarded a certificate for presentation at the award ceremony during the conference.&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
    &lt;li&gt;Lab must deliver ETR to validator by 16 January 2004&lt;/li&gt;&#xD;
    &lt;li&gt;Validator must deliver Validation Report package to CCEVS on/before 			26 January 2004, and&lt;/li&gt;&#xD;
    &lt;li&gt;Vendor &amp;amp; Lab must complete, sign and deliver &amp;ldquo;Vendor/CCTL release 			form&amp;rdquo; to CCEVS on/before  			9 February 2004.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;In addition, if the vendor plans to issue a product announcement at the conference that needs CCEVS review, then the Vendor must send the draft announcement to CCEVS on/before 9 February 2004.&lt;/p&gt;&#xD;
&lt;p&gt;Request each CCTL send CCEVS a list of product(s) and vendor(s) that you believe will finish up or have previously completed and would like to receive their certificate at the conference.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/FFm_N3q-iRc" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 14 Jan 2004 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/28/</feedburner:origLink></item>
    <item>
      <title>New ETR Format</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/t7bzraEtStM/</link>
      <description>&lt;p&gt;This ValGram provides a revised template for an Evaluation Technical Report, including an Annex with guidance for documenting individual work units. The ETR template and Annex will become mandatory for use in all new evaluations that begin on or after 1 February 2004.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/t7bzraEtStM" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 22 Dec 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/27/</feedburner:origLink></item>
    <item>
      <title>New ETR Format</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/t7bzraEtStM/</link>
      <description>&lt;p&gt;This ValGram provides a revised template for an Evaluation Technical Report, including an Annex with guidance for documenting individual work units. The ETR template and Annex will become mandatory for use in all new evaluations that begin on or after 1 February 2004.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/t7bzraEtStM" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 22 Dec 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/27/</feedburner:origLink></item>
    <item>
      <title>IASWS Award Ceremony Deadlines</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/WPx_ceqRvlI/</link>
      <description>&lt;p&gt;The Director, CCEVS will be presenting certificates at the Information Assurance Solutions Working Symposium (IASWS) on December 8, 2003 in Anaheim, California http://www.iaevents.com/iasws03/newinfo.cfm. The following timeline will be used for determining whether a product/PP will be awarded a certificate for presentation at the award ceremony during the conference.&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
    &lt;li&gt;Lab must deliver ETR to validator on/before 30 October 2003&lt;/li&gt;&#xD;
    &lt;li&gt;Validator must deliver Validation Report package to CCEVS on/before 10 November 2003, and&lt;/li&gt;&#xD;
    &lt;li&gt;Vendor &amp;amp; Lab must complete, sign and deliver &amp;ldquo;Vendor/CCTL release form&amp;rdquo; to CCEVS on/before 24 November 2003.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;In addition, if the vendor plans to issue a product announcement at the conference that needs CCEVS review, then the Vendor must deliver the draft announcement to CCEVS on/before 24 November 2003.&lt;/p&gt;&#xD;
&lt;p&gt;Request that the CCTLs send CCEVS a list of product(s)/ vendor(s) that you believe will finish up in time for presentation at the conference.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/WPx_ceqRvlI" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 23 Oct 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/26/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #6</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/-1B2465X_us/</link>
      <description>&lt;p&gt;I am forwarding CCEVS Policy #6 -- Location of CCTL Evaluation Testing Activities as ValGram #044 and LabGram #025 respectively. A signed original will be kept in the CCEVS official records and a copy will be posted to the NIAP CCEVS web page by the end of today. If you have any questions pertaining to this policy please contact the CCEVS staff.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/-1B2465X_us" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 20 Oct 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/25/</feedburner:origLink></item>
    <item>
      <title>New CCTL, Criterian Independent Labs</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/pN5Q6KICfLc/</link>
      <description>&lt;p&gt;The Director, CCEVS is pleased to announce the recent NVLAP accreditation and NIAP approval of our eighth Common Criteria Testing Laboratory, Criterian Independent Labs. They are located in Fairmont, West Virginia. Criterian is approved for test methods APE, ASE and EALs 1-4. The Lab Director is Mr. David Esses. Visit our CC Testing Labs page for additional details. Please join us in welcoming Criterian into the CCEVS!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/pN5Q6KICfLc" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 13 Aug 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/24/</feedburner:origLink></item>
    <item>
      <title>4th ICCC Certificate Deadlines</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/BGEg5-Z_8-4/</link>
      <description>&lt;p&gt;The Director CCEVS will be presenting certificates at the 4th ICCC Conference 7-9 September 2003 in Stockholm, Sweden. The following timeline will be used for determining whether a product/PP can be awarded a certificate for presentation during the conference.&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
    &lt;li&gt;Lab must deliver ETR to validator on/before 28 July 2003&lt;/li&gt;&#xD;
    &lt;li&gt;Validator must deliver Validation Report package to CCEVS on/before  				11 August 2003 and,&lt;/li&gt;&#xD;
    &lt;li&gt;Vendor &amp;amp; Lab must complete, sign, and deliver &amp;quot;Vendor/CCTL release 				form&amp;quot; to CCEVS on/before 25 August 2003.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;In addition, if the vendor plans to issue a product announcement at the conference that needs CCEVS review, then the Vendor must deliver the draft announcement to the CCEVS on/before 25 August 2003.&lt;/p&gt;&#xD;
&lt;p&gt;Please discuss with the vendor and plan accordingly. I would appreciate if the CCTLs would drop me a line to let me know what evaluations they expect to finish up in time for this conference.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/BGEg5-Z_8-4" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 07 Jul 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/23/</feedburner:origLink></item>
    <item>
      <title>New Web Info &amp; other News</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/jn6vcwb5cps/</link>
      <description>&lt;p&gt;Some time next week you will see a few additions to the NIAP CCEVS Web site. In particular changes to the &amp;quot;In Evaluation&amp;quot; page. We've had several requests to list the date the product entered into evaluation. We think listing a start date may actually do some good to move along those vendors who just want to &amp;quot;sit&amp;quot; on the in eval list. This is a heads up so that you may inform your vendors if you think it is necessary. We will be using the evaluation kick off date as our &amp;quot;start&amp;quot; date. At that same time, we will add the link to your laboratory web site (on the CCTL contact page), so if you haven't given me the url please do so by early next week.&lt;/p&gt;&#xD;
&lt;p&gt;The ICCC4 in Sweden 7-9 September 2003 will be the next venue for presenting CC certificates. If you have an evaluation nearing completion please discuss whether the vendor would be interested in receiving their certificate in Sweden and let me know. I will be sending out the deadlines for submitting ETRs, Validation Reports, etc. in a separate message.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/jn6vcwb5cps" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 03 Jul 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/22/</feedburner:origLink></item>
    <item>
      <title>Rescission of NIAP Interpretation I-0389</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/D7viaHmQWjo/</link>
      <description>&lt;p&gt;The CCIMB has found that NIAP Interpretation 0389 would violate Mutual Recognition. The interpretation calls for allowing a system to &amp;quot;recoveR&amp;amp;quot; to a previously-known state, rather then a *secure* state. The CCIMB believes such an interpretation could lead to the acceptance of products that revert to states which would compromise the intent of security. For example, if, after a user logs out, the system could revert to a state where that user was logged in, thereby permitting anyone else at that workstation to assume the user's identity. Even more drastically, the interpretation could permit a system reverting to a state that is known to be insecure.&lt;/p&gt;&#xD;
&lt;p&gt;The NIB and CCEVS management agree with the CCIMB that this NIAP interpretation could result in undesirable situations not envisaged by the NIB. CCEVS management therefore rescinds Interpretation I-0389.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/D7viaHmQWjo" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 09 May 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/19/</feedburner:origLink></item>
    <item>
      <title>Rescission of NIAP Interpretation I-0424</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/nDGw7sYYF1M/</link>
      <description>&lt;p&gt;The CCIMB has found that NIAP Interpretation I-0424 would violate Mutual Recognition. I-0424 suggested that FPT_SEP should be restructured to make the nature of hierarchy clearer, and to create a new component that is hierarchical to everything else. The CCIMB believes this is unnecessary, noting that the fact that FDP_SEP.2 can be completed in such a way that makes it equivalent to FDP_SEP.3 does not violate the hierarchical relationship. They also disagreed with the perceived need for a new component that is hierarchical to the current ones. The CCIMB felt that specification of a requirement for isolated reference monitors could be achieved within the existing criteria framework.&lt;/p&gt;&#xD;
&lt;p&gt;The NIB and CCEVS management agree with the CCIMB that this NIAP interpretation is not useful and would only lead to divergence from other schemes. CCEVS management therefore rescinds Interpretation I-0424.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/nDGw7sYYF1M" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 09 May 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/20/</feedburner:origLink></item>
    <item>
      <title>Status of Interpretations</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/N4wuIXLVRhQ/</link>
      <description>&lt;p&gt;In an effort to reduce the perceived divergence between evaluations conducted within CCEVS and those conducted by other schemes, and to address other questions raised, the CCEVS is clarifying its policy concerning NIAP Interpretations.&lt;/p&gt;&#xD;
&lt;p&gt;NIAP Interpretations will continue to be issued by the NIAP Interpretations Board and approved by CCEVS management. The purpose of these interpretations will be to offer clarifications to the CC/CEM in the form of proposed changes to the CC/CEM. NIAP Interpretations will continue to be available for public review.&lt;/p&gt;&#xD;
&lt;p&gt;Upon CCEVS management approval, evaluations are to consider the proposed changes contained within the interpretations as the recommended way to understand the requirements. They will have the same status within evaluations as do Precedents, in that they will provide an informed opinion describing what the requirements mean and an acceptable use. Because all changes to the words are treated as refinements for which rationales must be provided, the rationale for the word changes resulting from the use of a CCEVS interpretation will simply cite the interpretation.&lt;/p&gt;&#xD;
&lt;p&gt;CCEVS will forward each management-approved interpretation to the CCIMB for consideration as it strives to produce regular updates to the Criteria and Methodology. Non-concurrence from the CCIMB will signal the need for rescission of the interpretation by CCEVS management. NIAP Interpretations I-0389 and I-0424 have been rescinded for this reason. Any future rescission of NIAP interpretations will be announced, in the same manner as when interpretations are approved by CCEVS management, on the CCEVS mailing lists and website.&lt;/p&gt;&#xD;
&lt;p&gt;The naming/notation system that has been used in the past will be optional when CCEVS interpretation words are used within an evaluation. For cases when the notation convention is not used, there should be clear note at the point of the use of the interpretation indicating the interpretation applied to a particular component. This can be a footnote, a tailoring or operation note, or some other informative note.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/N4wuIXLVRhQ" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 09 May 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/21/</feedburner:origLink></item>
    <item>
      <title>Methodology for Components above EAL4</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/EpE8GJ1MGlQ/</link>
      <description>&lt;p&gt;CCEVS was recently questioned on what methodology should be used for assurance components above EAL4. In response, the following interim guidance was provided on the ADV_IMP.2, ADV_RCR.2, and AVA_CCA.1 components.This is how these components are to used until more structured methodology is available.&lt;/p&gt;&#xD;
&lt;p&gt;For evaluations including these components, validators are asked to pay particular attention in these areas, and keep CCEVS apprised if anything even remotely questionable comes up, so that we can clarify the interim guidance if necessary.&lt;/p&gt;&#xD;
&lt;p&gt;As other EAL4+ components are included in evaluations, causing other such interim guidance to be generated, these will be collected together and made available in an effort to maintain consistency.&lt;/p&gt;&#xD;
&lt;p&gt;--------&lt;br /&gt; ADV_IMP.2&lt;br /&gt; ADV_IMP.2 applies to the entire TSF, rather than only the subset of the TSF required by ADV_IMP.1. Therefore, an evaluation including ADV_IMP.2 should use the methodology for ADV_IMP.1, but applied to the entire TSF.&lt;/p&gt;&#xD;
&lt;p&gt;The evaluator confirms the information provided meets the requirements of the additional content and presentation element (ADV_IMP.2.3C: "The implementation representation shall describe the relationships between all portions of the implementation") by checking the code to be sure that interactions among the portions of the code are identified. The "portions of code" in question are those portions that implement the modules that are identified in the low-level design.&lt;/p&gt;&#xD;
&lt;p&gt;The importance of having all of the implementation representation -- rather than only the subset -- becomes apparent not in the evaluation work associated with ADV_IMP itself, but in other components. For example, the correspondence between the description of interactions among the modules in the low-level design and the interactions of the portions of the code that implement these modules will be performed as part of ADV_RCR; this ADV_IMP action makes sure the necessary input for that activity is available. Similarly, with the entire implementation representation available, the vulnerability analysis is much more straightforward and lucrative because the evaluator can trace through the code without running into dead ends that would otherwise result from portions of code being unavailable.&lt;/p&gt;&#xD;
&lt;p&gt;ADV_RCR.2&lt;br /&gt; At EAL5, only the Functional Specification and High-Level Design are provided in a semiformal format. ADV_RCR.2 imposes a correspondence determination between these semiformal representations. For all remaining representations that are informal, there must likewise be a correspondence determination. The correspondence determination (at both the semiformal and informal levels) is done in accordance with the methodology for ADV_RCR.1.&lt;/p&gt;&#xD;
&lt;p&gt;AVA_CCA.1&lt;br /&gt; There is no CCA methodology available in the CEM. Until methodology is available, the evaluator confirms the information provided meets the requirements of the content and presentation elements (AVA_CCA.1.1E) using the guidance provided in the Rainbow Document "A Guide to Understanding Covert Channel Analysis of Trusted Systems", November 1993, NCSC_TG-030.&lt;/p&gt;&#xD;
&lt;p&gt;The evaluator confirms that the covert channel analysis shows that the TOE meets its functional requirements (AVA_CCA.1.2E) only for TOEs claiming FDP_IFF.1/FDP_IFC.1 - these are the only functional requirements for which covert channels are meaningful. The policy quoted in these functional components is examined and the evaluator notes any covert channels that violate this policy, including the bandwidth of all such channels. When conducting the covert channel analysis, the evaluator needs to make sure that *all* resources (not just those defined in the applicable FDP_IFC/IFF components) are considered as part of the analysis; if they determine that a resource can be used in a covert channel, yet its use doesn't circumvent the policy set forth by the rules in FDP_IFC/IFF, that covert channel can be ignored.&lt;/p&gt;&#xD;
&lt;p&gt;All channels identified during the covert channel analysis are then included 			in the testing (AVA_CCA.1.3E).&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/EpE8GJ1MGlQ" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 14 Feb 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/18/</feedburner:origLink></item>
    <item>
      <title>RSA Certificate Deadlines</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/INF7cZy4vic/</link>
      <description>&lt;p&gt;The Director CCEVS will be presenting certificates at the RSA Conference 13-17 April in San Francisco. The following timeline will be used for determining whether a product/PP can be awarded a certificate for presentation at the award ceremony during the conference.&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
    &lt;li&gt;Lab must deliver ETR to validator on/before 28 Feb 2003&lt;/li&gt;&#xD;
    &lt;li&gt;Validator must deliver Validation Report package to CCEVS on/before  				14 March 2003 and,&lt;/li&gt;&#xD;
    &lt;li&gt;Vendor &amp;amp; Lab must complete, sign, and deliver &amp;quot;Vendor/CCTL release 				form&amp;quot;    to CCEVS on/before 1 April 2003.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;In addition, if the vendor plans to issue a product announcement at the conference that needs CCEVS review, then the Vendor must deliver the draft announcement to the CCEVS on/before 1 April 2003.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/INF7cZy4vic" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 03 Feb 2003 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/17/</feedburner:origLink></item>
    <item>
      <title>AMA</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/YnKVzF4yXbc/</link>
      <description>&lt;p&gt;Attached is the Draft AMA document that I intend to post as Draft CCEVS Publication #6 prior to 1 January. It includes all of the comments that we have received to date and I am authorizing vendors and labs to utilizing the draft AMA guidance until an agreement is reached by the International CC RA members. This should suffice in providing vendors a way to meet the recent DoDD 8500 policy that states that vendors must keep their products current by being a part of the NIAP AMA process or by re-evaluating each release of their product.&lt;/p&gt;&#xD;
&lt;p&gt;If changes are required to the draft AMA, based on implementation issues, CCEVS asks that CCTL's and Validators note the issue and pass it to CCEVS management for resolution.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/YnKVzF4yXbc" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 20 Dec 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/16/</feedburner:origLink></item>
    <item>
      <title>Welcome to InfoGard, 7th CCTL</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/C6iBgA5DZd0/</link>
      <description>&lt;p&gt;The Director, CCEVS is proud to announce the recent NVLAP accreditation and NIAP approval of our seventh Common Criteria Testing Laboratory, InfoGard Laboratories, Inc. InfoGard is located on the West Coast in San Luis Obispo, California. The Lab point of contact is Mr. Ken Kolstad. InfoGard is approved for test methods APE, ASE, &amp;amp; EALs 1-4. The CCTL webpage update will be available in the next day or so. Please join us in welcoming Ken &amp;amp; InfoGard Laboratories as our newest CCTL!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/C6iBgA5DZd0" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 29 Oct 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/14/</feedburner:origLink></item>
    <item>
      <title>Revision to Forms F8001 &amp; F8002</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/7QGbzHRTaA0/</link>
      <description>&lt;p&gt;Forms F8001, Sponsor Approval to List Product in Evaluation and F8002, Sponsor/CCTL Approval to Release Validation Information have been updated and posted to the website. Effective the date of this lab/ValGram please use the updated forms on the CCEVS website.&amp;nbsp; The previous versions of these forms have been superseded. Please discard any printed stock you may have and replace with the new versions.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/7QGbzHRTaA0" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 29 Oct 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/15/</feedburner:origLink></item>
    <item>
      <title>TOP Proposal, CCEVS Document #CCEVS-00007-02, V1.0 (18 Oct 02)</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/36HxYeRIZOA/</link>
      <description>&lt;p&gt;Attached is the finalized TOP proposal that CCEVS will be piloting on select evaluations. The TOP was created to address your concerns of validator inconsistencies and should, over time, allow you to more accurately price the validation oversight work into your contracts with vendors. This is only the first step that CCEVS is taking to provide you more guidance regarding evaluations.&lt;/p&gt;&#xD;
&lt;p&gt;CCEVS is willing to host a meeting with all of the lab managers to go over the TOP proposal and allow you the opportunity to ask questions if collectively you feel this would be beneficial. Regardless, I will be contacting each of you individually to discuss/negotiate on the selection of the evaluations for which this validation oversight model will be used. We are targeting those evaluations at the EAL 3 and/or 4 levels. I would like to reach agreement with each of you on the selected evaluations by 1 November if it is possible.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/36HxYeRIZOA" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 21 Oct 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/13/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #5, Evaluation TOEs at EALs above 4</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/_K3fe0o26e8/</link>
      <description>&lt;p&gt;I had indicated in some previous email that we were working on a CCEVS policy to address evaluations that are coming in at above an EAL 4 or have parts of the eval at the higher levels. I do not believe that any of this will be new news to you, but we decided to formalize it.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/_K3fe0o26e8" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 13 Sep 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/12/</feedburner:origLink></item>
    <item>
      <title>Use of 3-way NDAs</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/aFD0F991XZU/</link>
      <description>&lt;p&gt;As many of you know the 3-way NDA has raised problems with some vendors and labs alike. As a result of discussions with the lawyer we have decided to move to a 2-way NDA between the lab and CCEVS and do away with the current 3-way model. The new NDA is being written so it will not happen immediately. This note is serve as a heads up that we will not be pressing you to submit the 3-way NDA (for the time being). However, if you have a vendor that is particularly concerned about not having an NDA in place we will still accept the 3-way.&lt;/p&gt;&#xD;
&lt;p&gt;Additionally, all CCEVS employees are bound by law to protect proprietary information (marked as such) provided to CCEVS staff by the vendor and/or lab under individual signed NDAs.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/aFD0F991XZU" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 26 Aug 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/11/</feedburner:origLink></item>
    <item>
      <title>FIAC Certificate Deadlines</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/H_vSKhcXD_k/</link>
      <description>&lt;p&gt;In preparation for the upcoming Federal Information Assurance Conference (FIAC) in College Park, MD 29-31 October 2002, the following timeline will be used for determining whether a product/PP will be awarded a certificate at the award ceremony during the conference.&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
    &lt;li&gt;CCTL must prepare and deliver ETR to validator on/before  				9 Sep 02.&lt;/li&gt;&#xD;
    &lt;li&gt;Validator must prepare and deliver Validation Report, VPL entry, and validator recommendation to CCEVS on/before 30 Sep 02, and&lt;/li&gt;&#xD;
    &lt;li&gt;Vendor and CCTL must complete, sign, and deliver &amp;quot;vendor/CCTL 				release&amp;quot; form to CCEVS on/before 14 Oct 02.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;In addition, if the vendor plans to issue a product announcement/press release of their validated product at the FIAC that needs CCEVS review, then the vendor must deliver the draft announcement to the CCEVS on/before 14 Oct 02.&lt;/p&gt;&#xD;
&lt;p&gt;Please share this information with the vendors and plan accordingly. Labs- please send a consolidated list of the projects you think will meet the schedule. For recordkeeping purposes this notice will be sent to both the labs and validators under separate numbers. The point of contact for this message is Becky Galanakis.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/H_vSKhcXD_k" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 20 Aug 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/10/</feedburner:origLink></item>
    <item>
      <title>Followup from CCEVS Meeting Meeting with Labs</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/5gu3MD0TQdE/</link>
      <description>&lt;p&gt;This information is provided as a followup to our lab meeting yesterday and is not intended as a complete meeting summary.&lt;/p&gt;&#xD;
&lt;p&gt;The CCEVS mail distribution lists archives can be found at 			  http://www.itl.nist.gov/div896/emaildir/index.html. They are in alphabetical order - scroll down to the c's. If you have any additional changes to the ccevs-labs mail list (not noted yesterday) please send them to ccevs-staff and the changes will be made as quickly as possible. Also, take a few minutes periodically to review the information we have listed for you on http://www.niap-ccevs.org/cc-scheme/testing_labs.cfm  and notifiy the staff of any changes. We refer callers to the website so 			  make sure 			the info is correct!&lt;/p&gt;&#xD;
&lt;p&gt;A reminder that the 3-way NDA, Form 8003 is located on the CCEVS website, under Docs &amp;amp; Guidance. You should initiate the review of that form during your contract negotiations, pre-eval work. It's acceptable to have it signed during the kick-off but we have found that the folks attending the kick-off are not comfortable signing with no prior review/warning. Please give the vendor a heads-up as early as possible and if you know the company wants to make a change to the wording please let the staff know as soon as possible. You should certainly keep the validator informed but I will be your POC for follow-up with NDAs.&lt;/p&gt;&#xD;
&lt;p&gt;You have an action to get back to the staff by COB 5 July to let us know what your requirements are for getting our visitors from the UK/Australia/France/Germany into your facility.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/5gu3MD0TQdE" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 26 Jun 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/7/</feedburner:origLink></item>
    <item>
      <title>Followup from CCEVS Meeting Meeting with Labs</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/5gu3MD0TQdE/</link>
      <description>&lt;p&gt;This information is provided as a followup to our lab meeting yesterday and is not intended as a complete meeting summary.&lt;/p&gt;&#xD;
&lt;p&gt;The CCEVS mail distribution lists archives can be found at 			  http://www.itl.nist.gov/div896/emaildir/index.html. They are in alphabetical order - scroll down to the c's. If you have any additional changes to the ccevs-labs mail list (not noted yesterday) please send them to ccevs-staff and the changes will be made as quickly as possible. Also, take a few minutes periodically to review the information we have listed for you on http://www.niap-ccevs.org/cc-scheme/testing_labs.cfm  and notifiy the staff of any changes. We refer callers to the website so 			  make sure 			the info is correct!&lt;/p&gt;&#xD;
&lt;p&gt;A reminder that the 3-way NDA, Form 8003 is located on the CCEVS website, under Docs &amp;amp; Guidance. You should initiate the review of that form during your contract negotiations, pre-eval work. It's acceptable to have it signed during the kick-off but we have found that the folks attending the kick-off are not comfortable signing with no prior review/warning. Please give the vendor a heads-up as early as possible and if you know the company wants to make a change to the wording please let the staff know as soon as possible. You should certainly keep the validator informed but I will be your POC for follow-up with NDAs.&lt;/p&gt;&#xD;
&lt;p&gt;You have an action to get back to the staff by COB 5 July to let us know what your requirements are for getting our visitors from the UK/Australia/France/Germany into your facility.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/5gu3MD0TQdE" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 26 Jun 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/7/</feedburner:origLink></item>
    <item>
      <title>Observation Reports</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/PQQY6dg1Z3Y/</link>
      <description>&lt;p&gt;This LabGram is being sent as a clarification and supplement to 			   Scheme Pub 			#3, for the section entitled "Observation Reports".&lt;/p&gt;&#xD;
&lt;p&gt;Observation Reports (ORs) are submitted by CCTLs to document a question they have on a specific evaluation to receive a quick turn around resolution from the Validation Body. The Validator may also use the OR mechanism for documenting a question about a specific evaluation for which they need formal resolution from the Validation Body even if the CCTL does not agree with the need to submit an OR. Validators may submit ORs to document: 1. a disagreement between a validation team and an evaluation team; or 2. a noteworthy decision by a validation team in which a formal documented resolution from the Validation Body is desired.&lt;/p&gt;&#xD;
&lt;p&gt;ORs can be initiated by the evaluation team or by the validation team. 			Regardless of who initiates an OR, both parties must:&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;agree upon the Statement of the Issue as written in the OR;&lt;/li&gt;&#xD;
&lt;li&gt;be given the opportunity to provide a resolution to the issue in 			  the OR;&lt;/li&gt;&#xD;
&lt;li&gt;be given the opportunity to review the other party's proposed 			  resolution; and&lt;/li&gt;&#xD;
&lt;li&gt;be given the opportunity to provide factors that should be 			  considered by the Validation Body when making the resolution.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;Additionally, the evaluation team must review the OR for proper 			  marking of 			proprietary information.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/PQQY6dg1Z3Y" height="1" width="1"/&gt;</description>
      <pubDate>Sun, 09 Jun 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/9/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #4, Inactive Validations</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/PytH5mHDRno/</link>
      <description>&lt;p&gt;Please read the attached CCEVS Policy #4 -- Inactive Validation Projects issued by the Director, CCEVS. The policy is effective today, 7 June 2002.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/PytH5mHDRno" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 07 Jun 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/8/</feedburner:origLink></item>
    <item>
      <title>Use of Evaluation Acceptance Agreements at Kick-off Meetings</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/34wdGvWz6wg/</link>
      <description>&lt;p&gt;This is a reminder that both Scheme Publication #3, Guidelines 				to Validators of IT Security Evaluations, and Scheme Publication #4, Guidelines 				to Common Criteria Testing Laboratories specify the completion of an Evaluation Acceptance and Non-Disclosure Agreement (F8003) following the Evaluation Kick-off Meeting. Until now, the CCEVS Validation Body has not enforced the requirement for completing this agreement. For all new projects from this date forward an Evaluation Acceptance and Non-Disclosure Agreement is required to be completed. A copy of the agreement can be obtained through the "Forms and Templates" page.&lt;/p&gt;&#xD;
&lt;p&gt;The Validators are responsible for seeing that an Evaluation Acceptance and Non-Disclosure agreement is prepared for each project. The CCTLs are asked to coordinate with the sponsor and the Validator in preparing the agreement, and obtaining the necessary signatures. A copy of the signed agreement will be sent to the sponsor and the CCTL.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/34wdGvWz6wg" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 09 Apr 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/6/</feedburner:origLink></item>
    <item>
      <title>Use of Evaluation Acceptance Agreements at Kick-off Meetings</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/34wdGvWz6wg/</link>
      <description>&lt;p&gt;This is a reminder that both Scheme Publication #3, Guidelines 				to Validators of IT Security Evaluations, and Scheme Publication #4, Guidelines 				to Common Criteria Testing Laboratories specify the completion of an Evaluation Acceptance and Non-Disclosure Agreement (F8003) following the Evaluation Kick-off Meeting. Until now, the CCEVS Validation Body has not enforced the requirement for completing this agreement. For all new projects from this date forward an Evaluation Acceptance and Non-Disclosure Agreement is required to be completed. A copy of the agreement can be obtained through the "Forms and Templates" page.&lt;/p&gt;&#xD;
&lt;p&gt;The Validators are responsible for seeing that an Evaluation Acceptance and Non-Disclosure agreement is prepared for each project. The CCTLs are asked to coordinate with the sponsor and the Validator in preparing the agreement, and obtaining the necessary signatures. A copy of the signed agreement will be sent to the sponsor and the CCTL.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/34wdGvWz6wg" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 09 Apr 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/6/</feedburner:origLink></item>
    <item>
      <title>Use of Evaluation Acceptance Agreements at Kick-off Meetings</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/34wdGvWz6wg/</link>
      <description>&lt;p&gt;This is a reminder that both Scheme Publication #3, Guidelines 				to Validators of IT Security Evaluations, and Scheme Publication #4, Guidelines 				to Common Criteria Testing Laboratories specify the completion of an Evaluation Acceptance and Non-Disclosure Agreement (F8003) following the Evaluation Kick-off Meeting. Until now, the CCEVS Validation Body has not enforced the requirement for completing this agreement. For all new projects from this date forward an Evaluation Acceptance and Non-Disclosure Agreement is required to be completed. A copy of the agreement can be obtained through the "Forms and Templates" page.&lt;/p&gt;&#xD;
&lt;p&gt;The Validators are responsible for seeing that an Evaluation Acceptance and Non-Disclosure agreement is prepared for each project. The CCTLs are asked to coordinate with the sponsor and the Validator in preparing the agreement, and obtaining the necessary signatures. A copy of the signed agreement will be sent to the sponsor and the CCTL.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/34wdGvWz6wg" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 09 Apr 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/6/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #2, Reuse of previous Evaluation Results and Evidence</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/CkLYtbm_yGk/</link>
      <description>&lt;p&gt;Attached is the second in the series of Policy Letters that will be forthcoming from CCEVS. This policy deals with the reuse of previous evaluation results and evidence.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/CkLYtbm_yGk" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 07 Mar 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/4/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #3, TOE STs Claiming Conformance to PPs (Draft or Validated)</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/o4C472T84zY/</link>
      <description>&lt;p&gt;Attached is the third in the series of Policy Letters that will be forthcoming from CCEVS. This policy deals with the TOE security targets claiming conformance to protection profiles (draft and validated).&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/o4C472T84zY" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 07 Mar 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/5/</feedburner:origLink></item>
    <item>
      <title>Scheme Pub #3 and other Docs on Website</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/i9xvNTaMF5s/</link>
      <description>&lt;p&gt;Additional documents have been added to the Scheme Publications page for your information and use.  Scheme Publication #3, Guidance to Validators of IT Security Evaluations is now available. Also, additional CCEVS forms and templates frequently used during the evaluation/validation process have now been posted on the web site for convenient access.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/i9xvNTaMF5s" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 21 Feb 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/3/</feedburner:origLink></item>
    <item>
      <title>Scheme Pub #3 and other Docs on Website</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/i9xvNTaMF5s/</link>
      <description>&lt;p&gt;Additional documents have been added to the Scheme Publications page for your information and use.  Scheme Publication #3, Guidance to Validators of IT Security Evaluations is now available. Also, additional CCEVS forms and templates frequently used during the evaluation/validation process have now been posted on the web site for convenient access.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/i9xvNTaMF5s" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 21 Feb 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/3/</feedburner:origLink></item>
    <item>
      <title>ICCC Certificate Deadlines</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/n41D9o9C8Ec/</link>
      <description>&lt;p&gt;In preparation for the upcoming International Common Criteria Conference (ICCC) in Ottawa, Canada in May 2002, the following timeline will be used for determining whether a product/PP can be awarded a certificate at the award ceremony   during the conference.&lt;/p&gt;&#xD;
&lt;ul&gt;&#xD;
    &lt;li&gt;	Lab must prepare and deliver ETR to validator on/before 1 April 02,&lt;/li&gt;&#xD;
    &lt;li&gt;	Validator must prepare and deliver Validation Report, VPL entry,     and   validator recommendation to CCEVS on/before 15 April 02, and&lt;/li&gt;&#xD;
    &lt;li&gt;	Vendor &amp; Lab must complete, sign, and deliver "Vendor/CCTL release"    form     to CCEVS on/before 1 May 02.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;  In addition, if the vendor plans to issue a product announcement of   their validated         product at the ICCC that needs CCEVS review, then the Vendor must deliver   the draft   announcement to the CCEVS on/before 1 May 02.&lt;/p&gt;&#xD;
&lt;p&gt;  Please share this information with the vendors and plan accordingly.   For recordkeeping purposes this notice is being sent to the validators under         a   separate ValGram.  The point of contact for this LabGram is Becky Galanakis.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/n41D9o9C8Ec" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 19 Feb 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/2/</feedburner:origLink></item>
    <item>
      <title>CCEVS Policy Letter #1 Subj: Appropriateness of Language in ST, ETR, VPL &amp; VRs</title>
      <link>http://feedproxy.google.com/~r/niap-ccevs/labgrams/~3/4tnXPnetp7Q/</link>
      <description>&lt;p&gt;Attached is the first of several Policy Letters that will be forthcoming from CCEVS. This policy deals with the appropriateness of language in security targets, evaluation technical reports, VPL entries, and validation reports.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/niap-ccevs/labgrams/~4/4tnXPnetp7Q" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 10 Jan 2002 00:00:00 GMT</pubDate>
    <feedburner:origLink>http://www.niap-ccevs.org/labgrams/1/</feedburner:origLink></item>
  </channel>
</rss>
