Learning Tools and Information Material

As part of the SPA program, IDA releases learning tools and additional information for free download and free use. Commercial redistribution is not permitted. All information and software is being provided "as is" without any warranty of any kind.

The tools do not require installation or administrator rights. Unzipping the files into any directory is sufficient. The tools are developed in Java and require an installation of a Java Runtime Environment for execution.

Learning Tools
SeCCurityRadar Updated - Dec 12
A software tool that introduces a novel approach to "designing" a Security Target (ST) or a Protection Profile (PP) based on visual representation and graphical development. It automates iteration and cross references, and it provides consistency checks required by CC. It includes basic support for reviews and presentations.
This ZIP contains only the files for the tool itself. Extract all files to a working directory and follow the instructions given in the "readme.txt" to manually download other required files.

Download

The installer downloads and installs all files. Execute the jar file inside the ZIP (access to the Internet is required).

Download

The manual for SeCCurityRadar also provides some basic background information for writing ST or PP.

Download

Attack Potential Calculator
Effectiveness of resistance against attacks depends on the sophistication of the attacker and the methods used. This tool demonstrates how the "attack potential" is calculated within Common Criteria and how it relates to the evaluation levels.

Download
(includes JAR-file and Manual)

Information Materials
Security Functional Components
This paper provides a basic overview of the framework provided by CC V3.1, Part 2, 'Security Functional Components' (SFC). It describes in general terms the scope of SFC and its use as 'Security Functional Requirements' (SFR) so that readers can understand the meaning and role of SFRs, and may find some pointers to:

a) identify SFRs or families, which are suitable for their purposes (when writing an ST);
b) identify expected SFRs for procurement purposes (when reading an ST); or
c) gain an overview of unfamiliar SFRs.

Download

Please email to [email protected] for:

  • Registration for updates on bug fixes or new releases (use "[SPA tool]" or [SPA info]" as part of the mail title)
  • Providing feedback on learning tools/information material (use "[SPA Feedback]" as part of the mail title)



Related Information

Was this information useful?

Was this information useful?
Was this information useful?


*
trust-sg