Bangalore: India should adopt the common criteria standard evolved y US and Canada
for certification and security evaluation of the trustworthiness of increasing
number of commercially available information technology products (CAR) director, has
said.
Presenting his paper on 'Information system security assurance and certification, an
Indian perspective' at the two-day national seminar on information and network
security, he said that the "common criteria" evolved by the US, Canada and some
European countries for security evaluation of IT products was adopted by the
International Standards Organisation (ISO) as ISO Standard 15408.
These countries signed mutual recognition agreement to recognise each other’s
evaluation/certification with the expectation that it would lead to a wider choice
of evaluated products for the consumers and a greater market access for the
developers, he said.
He said that the information systems used for e-commerce, e-governance and e-
marketing and business needed to be secured against data loss, unauthorised use,
disclosure or modification.
But since their trustworthiness based on formal evaluation was absent there was an
urgent need for certification through a common criteria even as the commercially
available IT products were increasing.
He said that India could set up a national certification agency as the trusted
agency for issuing common criteria certificates, and encourage establishment and
accreditation of Indian evaluation infrastructure in private or public sectors which
could function as accredited evaluation centres.
PTI