|
Security Profiles are created, taking into account both vendors and buyers’ pain in processing and maintaining ICT/IoT product certifications.
Therefore, a simple and clear process is defined providing for each stakeholder involved documentation and metrics that are tailored to its level of understanding of the security problem definition.
Business Lines are included in the list of stakeholders to help in defining the set of security requirements to be used as the basis of certification. These security requirements are defined in what we call a Security Profile which is a summarized representation of the results of a risk analysis conducted on a type of product such as connected camera or a smart TV or a LORA module, etc.. The creation of the security profile process is defined in 3 steps using the available generic catalogue of security requirements. It is included in the scheme to allow a harmonized creation of security profiles. This is very important to guarantee the most objective and comparable results.
Finally, the vendor will have to complete a Vendor Questionnaire with the info satisfying the requirements before sharing these with the CABs who will generate an evaluation report and issue a certificate. |