Commercial Product Assurance Explained
Commercial Product Assurance (CPA) is a CESG approach to gaining confidence in the security of commercial products.
It is intended to supplant other approaches such as Common Criteria (CC) and CCT Mark for UK government use.
Organisation
CPA is being developed under the auspices of the UK Government's CESG[1] as the UK National Technical Authority (NTA) for Information Security.
Architectural patterns
CESG also produce Architectural Patterns which cover good practices for common business problems,[2] which looks to use CPA product.
Current Architectural Patterns include:
- Walled Gardens for Remote Access[3]
- Mobile Remote End Point Devices[4]
- Data Import between Security Domains[5]
Comparisons
In comparison to other schemes:
- Unlike Common Criteria, there is no Mutual Recognition Agreement (MRA) for CPA, which means that products tested in the UK will not normally be accepted in other markets
- Unlike the CCT Mark, the coverage of CPA is limited to Information Security products, and therefore excludes services. The target audience for CPA also appears to be focused on Central Government ("I'm protecting Government data")[6] rather than including the Wider Public Sector (WPS) and Critical National Infrastructure (CNI) segments that were target customers for CCT Mark
References
- Web site: CESG Home Page . 2010-09-26 . https://web.archive.org/web/20040711011436/http://www.cesg.gov.uk/ . 2004-07-11 . dead .
- Web site: CPA (reference to Architectural Patterns). CESG. 24 January 2013. https://web.archive.org/web/20130205011004/http://www.cesg.gov.uk/servicecatalogue/CPA/Pages/Using-a-CPA-product.aspx. 5 February 2013. dead.
- Web site: Reference to Walled Gardens for Remote Access. CESG. 24 January 2013. https://web.archive.org/web/20121115060926/http://www.cesg.gov.uk/publications/Documents/cpa-sc_ipsec_vpn_for_remote_working-software_client_v1-2.pdf. 15 November 2012. dead.
- Web site: Reference to Mobile Remote End Point Devices. CESG. 2013-02-03. https://web.archive.org/web/20121115060652/http://www.cesg.gov.uk/Publications/Documents/cpa-sc_software_execution_control.pdf. 2012-11-15. dead.
- Web site: Reference to Data Import between Security Domains. Cabinet Office. 24 January 2013. https://web.archive.org/web/20121218180609/http://gps.cabinetoffice.gov.uk/sites/default/files/files/Minimum%20Requirements%20doc..docx. 18 December 2012. dead.
- http://www.cesg.gov.uk/products_services/iacs/cpa/index.shtml CESG CPA Home Page