SlideShare a Scribd company logo
1 of 21
Download to read offline
0
PUBLIC - EU CSA CONFERENCE 2022
PUBLIC
NXP, THE NXP LOGO AND NXP SECURE CONNECTIONS FOR A SMARTER WORLD ARE TRADEMARKS OF NXP B.V. ALL OTHER PRODUCT OR
SERVICE NAMES ARE THE PROPERTY OF THEIR RESPECTIVE OWNERS. © 2022 NXP B.V.
M AY 2 0 2 2
EU CYBERSECURITY ACT
CONFERENCE 2022
CROSS STANDARD AND SCHEME COMPOSITION
1
PUBLIC - EU CSA CONFERENCE 2022
SUBJECT
The proliferation of new cybersecurity standards/schemes shows the interest of all the stakeholders to
require cybersecurity for ICT products. On the other hand, a need for harmonization/recognition between
standards/schemes is needed. Otherwise, there could be too many standards that become non-cost-
effective for developers certifying their products
For instance, almost every IoT vertical has its own set of cybersecurity standards. But IoT devices and it‚ is
supply chain is not limited within a single vertical. In fact, the contrary holds, that building blocks of an IoT
device find appliance in a couple of other verticals. Assuming that these building blocks demonstrated
cybersecurity compliance of some form, say for a particular vertical, it will be key for the economy to not
repeat those proofs of compliance but instead accept across standards and schemes where applicable
This talk will highlight the importance of the acceptance of certification and standard compliance results
across different schemes or security standards. We will show examples (e.g., smart metering in France with
de-facto acceptance of underlying CC results, SESIP to IEC62443-4-2) where this has been applied
successfully, but will also look at existing standards or schemes where this would be possible (e.g. EUCC,
FITCEM, etc) or proposals on how to apply this for Industrial IoT (IACS ERNCIP recommendations to the EU
commission)
2
PUBLIC - EU CSA CONFERENCE 2022
ABOUT US
José Ruiz:
• Co-Founder & CTO
• Common Criteria, FIPS 140-2 & 3 Expert
• Member of the SCCG (Stakeholder Cybersecurity
Certification Group)
• ICCC Former Program Director
• Editor at thematical group “IACS Cybersecurity
certification “.
• Editor at JTC13 WG3: “Cybersecurity Evaluation
Methodology for ICT products”
3
PUBLIC - EU CSA CONFERENCE 2022
ABOUT US
Fabien Deboyser:
• Security Certification Expert
• Common Criteria, FIPS 140-2 & 3, PCI-HSM,
SESIP & ISO17025 Expert
• Member of ISO/CEN committees: TC 224,
ISO19790, ISO17825
• Eurosmart CDI representative
• Former Common Criteria laboratory director
4
PUBLIC - EU CSA CONFERENCE 2022
Think Connect Act
Sense
Everything Safe & Secure
Everything
Aware
Everything
Smart
Everything
Connected
Everything
Efficient
5
PUBLIC
HORIZONTAL CERTIFICATION SCHEME IS IN DEMAND
TO ADDRESS VARIOUS REQUIREMENTS
Government Legislation:
• European Cyber Security Act
• Singapore CSL
• S.734 - Internet of Things Cybersecurity
Improvement Act of 2019
• Cal. SB-327
Baseline Requirements:
• CSA/MATTER (Zigbee etc)
• ETSI 303 645 (Consumer)
• NISTIR 8259 (Device Manufacturers)
• UL 2900 (SW)
Sector Specific:
• ISO/SAE 21434 (Auto)
• IEC 62443 (Industrial)
• NFC/FiRa/CCC
• Hospital & at-home Patient Monitoring
• Personal Health & Fitness Monitoring​
6
INTERNAL
CURRENT SITUATION = VENDOR PERSPECTIVE
7
PUBLIC - EU CSA CONFERENCE 2022
CURRENT SITUATION = VENDOR PERSPECTIVE
8
PUBLIC - EU CSA CONFERENCE 2022
Learning Inference
Big Data Big Model Application
Training
Query
Decision
Feedback
Connected devices are always
online and can be monitored
for unusual behaviour using AI
both in the cloud and more and
more at the edge.
Security profiles can be loaded
and adapted in real time
SECURITY WILL CONSTANTLY EVOLVE IN REAL TIME
9
PUBLIC - EU CSA CONFERENCE 2022
No mutual recognition Standards checking the same work
Chaos of certifications and overlapping of standards/schemes
CURRENT SITUATION = LABORATORY PERSPECTIVE
1 0
PUBLIC - EU CSA CONFERENCE 2022
Lack of personnel Too Many Accreditation Audits
PROBLEMS FROM THE LABORATORY PERSPECTIVE
1 1
PUBLIC - EU CSA CONFERENCE 2022
1 2
PUBLIC - EU CSA CONFERENCE 2022
• The art of putting “things together”,
to create harmony
• In security certification:
• the art of reusing existing compliance
proofs without re-evaluation, re-audit
or re-testing
• This can be done within a scheme or
multiple schemes
WHAT IS COMPOSITION?
Secure
processor
HW block
Secure
processor
HW crypto
Module
HW clock
OS
OS
Device
Module
Secure
Storage
Secure
Comm
…
1 3
PUBLIC - EU CSA CONFERENCE 2022
CC PP0084
CC PP0099
SESIP
NXP Secure Product Development Process
IEC62443-4-1
IEC62443-4-2
SOLUTIONS FROM THE VENDOR PERSPECTIVE = CROSS SCHEME AND COMPOSI TION IN
PRACTICE
1 4
PUBLIC - EU CSA CONFERENCE 2022
CROSS STANDARD & SCHEME COMPOSITION
Cross Standard & Scheme composition
To reuse existing compliance proofs across different certification schemes or standards without
(or only limited) re-evaluation, re-audit or re-testing.
AVA
AGD
ATE
ASE
ALC
ADV
IEC 62443-4-2
Certificate
IEC 62443-4-1
Certificate
ETSI EN 303 645
Certificate
ISO27001
Certificate
LINCE/CSPN/BSZ/FITCEM
Certificate
Re-use of the Certificate with Conditions
Re-use of the Certificate with Conditions
Re-use of the Certificate for ALC_DVS with Conditions
Re-use of the Certificate
Re-use of the Certificate for ALC with Conditions
COMMON CRITERIA
1 5
PUBLIC - EU CSA CONFERENCE 2022
INTERESTING INITIATIVES FROM THE LAB PERSPECTIVE
Mutual recognition –
CSPN & BSZ
ECSO – Product Certification
Composition
IACS ERNCIP Recommendations –
Definition of the scheme
FITCEM
URWP – New Schemes
1 6
PUBLIC - EU CSA CONFERENCE 2022
Recognition between countries for lightweigths schemes or
A ligthweight horizonal scheme in Europe under the CSA
Food for thoughts
1 7
PUBLIC - EU CSA CONFERENCE 2022
New version of Common Criteria includes exact conformance
LET’S USE IT!
LET’S INNOVATE!
Eg.- Develop an PP for IoT devices mandating
an ETSI certificate + AVA_VAN activities
This will allow to reuse the ETSI certificate
saving a lot of time related to the CC
certification
Food for thoughts
1 8
PUBLIC - EU CSA CONFERENCE 2022
• Technical WGs to discuss technical
details/challenges of Cross Standard and scheme
composition at ENISA
• New Cybersecurity Act schemes should integrate
cross standard and scheme composition from the
very beginning
Food for thoughts
1 9
PUBLIC - EU CSA CONFERENCE 2022
Questions?
2 0
PUBLIC - EU CSA CONFERENCE 2022
Thanks
José Ruiz
jruiz@jtsec.es
Fabien Deboyser
fabien.deboyser@nxp.com

More Related Content

Similar to Cross standard and scheme composition - A needed cornerstone for the European cybersecurity certification framework

Contributing to the Development and Application of Cybersecurity Standards
Contributing to the Development and Application of Cybersecurity StandardsContributing to the Development and Application of Cybersecurity Standards
Contributing to the Development and Application of Cybersecurity StandardsYokogawa1
 
Automation-based Certification for Cloud Services in Euro
Automation-based Certification for Cloud Services in EuroAutomation-based Certification for Cloud Services in Euro
Automation-based Certification for Cloud Services in EuroMEDINA
 
The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14Shane Coughlan
 
Smart Manufacturing
Smart ManufacturingSmart Manufacturing
Smart ManufacturingCSA Group
 
TAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxTAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxJavier Tallón
 
Lightscene 2018: Global Market Access – What should I know when I am exportin...
Lightscene 2018: Global Market Access – What should I know when I am exportin...Lightscene 2018: Global Market Access – What should I know when I am exportin...
Lightscene 2018: Global Market Access – What should I know when I am exportin...Institution of Lighting Professionals
 
Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System ...
Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System ...Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System ...
Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System ...promediakw
 
Jd for " staff applications engineer "
Jd  for " staff applications engineer "Jd  for " staff applications engineer "
Jd for " staff applications engineer "AmruthaBHH
 
Prioritizing Documentation for MDR Transition Planning
Prioritizing Documentation for MDR Transition PlanningPrioritizing Documentation for MDR Transition Planning
Prioritizing Documentation for MDR Transition PlanningGreenlight Guru
 
IEEE Digital Senses Initiative - Standards Activities 3/30/2017
IEEE Digital Senses Initiative - Standards Activities   3/30/2017IEEE Digital Senses Initiative - Standards Activities   3/30/2017
IEEE Digital Senses Initiative - Standards Activities 3/30/2017yymedia
 
1 mrk511305 uen--_en_communication_protocol_manual__lon__670_series_2.0__iec
1 mrk511305 uen--_en_communication_protocol_manual__lon__670_series_2.0__iec1 mrk511305 uen--_en_communication_protocol_manual__lon__670_series_2.0__iec
1 mrk511305 uen--_en_communication_protocol_manual__lon__670_series_2.0__iecOlusegun Abode
 
Requirements of ISO 26262
Requirements of ISO 26262Requirements of ISO 26262
Requirements of ISO 26262Torben Haagh
 
Paving the road towards continuous auditbased certification for cloud service...
Paving the road towards continuous auditbased certification for cloud service...Paving the road towards continuous auditbased certification for cloud service...
Paving the road towards continuous auditbased certification for cloud service...MEDINA
 
Overcome Hardware And Software Challenges - Medical Device Case Study
Overcome Hardware And Software Challenges - Medical Device Case StudyOvercome Hardware And Software Challenges - Medical Device Case Study
Overcome Hardware And Software Challenges - Medical Device Case StudyICS
 
2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...Javier Tallón
 
First Impressions on Experimenting with Automated Monitoring Requirements of ...
First Impressions on Experimenting with Automated Monitoring Requirements of ...First Impressions on Experimenting with Automated Monitoring Requirements of ...
First Impressions on Experimenting with Automated Monitoring Requirements of ...MEDINA
 
Towards a certification scheme for IoT security evaluation
Towards a certification scheme for IoT security evaluationTowards a certification scheme for IoT security evaluation
Towards a certification scheme for IoT security evaluationAxel Rennoch
 
Spanish catalogue of qualified products - a new way of using CC for procurement
Spanish catalogue of qualified products - a new way of using CC for procurementSpanish catalogue of qualified products - a new way of using CC for procurement
Spanish catalogue of qualified products - a new way of using CC for procurementJavier Tallón
 

Similar to Cross standard and scheme composition - A needed cornerstone for the European cybersecurity certification framework (20)

Contributing to the Development and Application of Cybersecurity Standards
Contributing to the Development and Application of Cybersecurity StandardsContributing to the Development and Application of Cybersecurity Standards
Contributing to the Development and Application of Cybersecurity Standards
 
Automation-based Certification for Cloud Services in Euro
Automation-based Certification for Cloud Services in EuroAutomation-based Certification for Cloud Services in Euro
Automation-based Certification for Cloud Services in Euro
 
The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14
 
Smart Manufacturing
Smart ManufacturingSmart Manufacturing
Smart Manufacturing
 
Standards for protection of data on storage device are emerging from both the...
Standards for protection of data on storage device are emerging from both the...Standards for protection of data on storage device are emerging from both the...
Standards for protection of data on storage device are emerging from both the...
 
TAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxTAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptx
 
Lightscene 2018: Global Market Access – What should I know when I am exportin...
Lightscene 2018: Global Market Access – What should I know when I am exportin...Lightscene 2018: Global Market Access – What should I know when I am exportin...
Lightscene 2018: Global Market Access – What should I know when I am exportin...
 
Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System ...
Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System ...Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System ...
Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System ...
 
Jd for " staff applications engineer "
Jd  for " staff applications engineer "Jd  for " staff applications engineer "
Jd for " staff applications engineer "
 
Prioritizing Documentation for MDR Transition Planning
Prioritizing Documentation for MDR Transition PlanningPrioritizing Documentation for MDR Transition Planning
Prioritizing Documentation for MDR Transition Planning
 
IEEE Digital Senses Initiative - Standards Activities 3/30/2017
IEEE Digital Senses Initiative - Standards Activities   3/30/2017IEEE Digital Senses Initiative - Standards Activities   3/30/2017
IEEE Digital Senses Initiative - Standards Activities 3/30/2017
 
1 mrk511305 uen--_en_communication_protocol_manual__lon__670_series_2.0__iec
1 mrk511305 uen--_en_communication_protocol_manual__lon__670_series_2.0__iec1 mrk511305 uen--_en_communication_protocol_manual__lon__670_series_2.0__iec
1 mrk511305 uen--_en_communication_protocol_manual__lon__670_series_2.0__iec
 
Requirements of ISO 26262
Requirements of ISO 26262Requirements of ISO 26262
Requirements of ISO 26262
 
Paving the road towards continuous auditbased certification for cloud service...
Paving the road towards continuous auditbased certification for cloud service...Paving the road towards continuous auditbased certification for cloud service...
Paving the road towards continuous auditbased certification for cloud service...
 
Overcome Hardware And Software Challenges - Medical Device Case Study
Overcome Hardware And Software Challenges - Medical Device Case StudyOvercome Hardware And Software Challenges - Medical Device Case Study
Overcome Hardware And Software Challenges - Medical Device Case Study
 
2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...
 
First Impressions on Experimenting with Automated Monitoring Requirements of ...
First Impressions on Experimenting with Automated Monitoring Requirements of ...First Impressions on Experimenting with Automated Monitoring Requirements of ...
First Impressions on Experimenting with Automated Monitoring Requirements of ...
 
Towards a certification scheme for IoT security evaluation
Towards a certification scheme for IoT security evaluationTowards a certification scheme for IoT security evaluation
Towards a certification scheme for IoT security evaluation
 
Spanish catalogue of qualified products - a new way of using CC for procurement
Spanish catalogue of qualified products - a new way of using CC for procurementSpanish catalogue of qualified products - a new way of using CC for procurement
Spanish catalogue of qualified products - a new way of using CC for procurement
 
Intelligent Buildings and IAQ - COVID
Intelligent Buildings and IAQ - COVID Intelligent Buildings and IAQ - COVID
Intelligent Buildings and IAQ - COVID
 

More from Javier Tallón

Evolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio IIEvolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio IIJavier Tallón
 
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...Javier Tallón
 
ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?Javier Tallón
 
ICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNJavier Tallón
 
La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...Javier Tallón
 
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfEUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfJavier Tallón
 
Evolucionado la evaluación Criptográfica
Evolucionado la evaluación CriptográficaEvolucionado la evaluación Criptográfica
Evolucionado la evaluación CriptográficaJavier Tallón
 
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...Javier Tallón
 
EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896Javier Tallón
 
EUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemesEUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemesJavier Tallón
 
EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045Javier Tallón
 
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?Javier Tallón
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Javier Tallón
 
CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2Javier Tallón
 
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...Javier Tallón
 
Automating Common Criteria
Automating Common Criteria Automating Common Criteria
Automating Common Criteria Javier Tallón
 
CCCAB - Making CABs life easy
CCCAB -  Making CABs life easyCCCAB -  Making CABs life easy
CCCAB - Making CABs life easyJavier Tallón
 
ICCC21 2021 statistics report
ICCC21 2021 statistics reportICCC21 2021 statistics report
ICCC21 2021 statistics reportJavier Tallón
 
jtsec Arqus Alliance presentation
jtsec Arqus Alliance presentationjtsec Arqus Alliance presentation
jtsec Arqus Alliance presentationJavier Tallón
 

More from Javier Tallón (20)

Evolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio IIEvolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio II
 
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
 
ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?
 
ICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCN
 
La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...
 
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfEUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
 
Hacking your jeta.pdf
Hacking your jeta.pdfHacking your jeta.pdf
Hacking your jeta.pdf
 
Evolucionado la evaluación Criptográfica
Evolucionado la evaluación CriptográficaEvolucionado la evaluación Criptográfica
Evolucionado la evaluación Criptográfica
 
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
 
EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896
 
EUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemesEUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemes
 
EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045
 
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?
 
CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2
 
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
 
Automating Common Criteria
Automating Common Criteria Automating Common Criteria
Automating Common Criteria
 
CCCAB - Making CABs life easy
CCCAB -  Making CABs life easyCCCAB -  Making CABs life easy
CCCAB - Making CABs life easy
 
ICCC21 2021 statistics report
ICCC21 2021 statistics reportICCC21 2021 statistics report
ICCC21 2021 statistics report
 
jtsec Arqus Alliance presentation
jtsec Arqus Alliance presentationjtsec Arqus Alliance presentation
jtsec Arqus Alliance presentation
 

Recently uploaded

Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesZilliz
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 

Recently uploaded (20)

Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector Databases
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 

Cross standard and scheme composition - A needed cornerstone for the European cybersecurity certification framework

  • 1. 0 PUBLIC - EU CSA CONFERENCE 2022 PUBLIC NXP, THE NXP LOGO AND NXP SECURE CONNECTIONS FOR A SMARTER WORLD ARE TRADEMARKS OF NXP B.V. ALL OTHER PRODUCT OR SERVICE NAMES ARE THE PROPERTY OF THEIR RESPECTIVE OWNERS. © 2022 NXP B.V. M AY 2 0 2 2 EU CYBERSECURITY ACT CONFERENCE 2022 CROSS STANDARD AND SCHEME COMPOSITION
  • 2. 1 PUBLIC - EU CSA CONFERENCE 2022 SUBJECT The proliferation of new cybersecurity standards/schemes shows the interest of all the stakeholders to require cybersecurity for ICT products. On the other hand, a need for harmonization/recognition between standards/schemes is needed. Otherwise, there could be too many standards that become non-cost- effective for developers certifying their products For instance, almost every IoT vertical has its own set of cybersecurity standards. But IoT devices and it‚ is supply chain is not limited within a single vertical. In fact, the contrary holds, that building blocks of an IoT device find appliance in a couple of other verticals. Assuming that these building blocks demonstrated cybersecurity compliance of some form, say for a particular vertical, it will be key for the economy to not repeat those proofs of compliance but instead accept across standards and schemes where applicable This talk will highlight the importance of the acceptance of certification and standard compliance results across different schemes or security standards. We will show examples (e.g., smart metering in France with de-facto acceptance of underlying CC results, SESIP to IEC62443-4-2) where this has been applied successfully, but will also look at existing standards or schemes where this would be possible (e.g. EUCC, FITCEM, etc) or proposals on how to apply this for Industrial IoT (IACS ERNCIP recommendations to the EU commission)
  • 3. 2 PUBLIC - EU CSA CONFERENCE 2022 ABOUT US José Ruiz: • Co-Founder & CTO • Common Criteria, FIPS 140-2 & 3 Expert • Member of the SCCG (Stakeholder Cybersecurity Certification Group) • ICCC Former Program Director • Editor at thematical group “IACS Cybersecurity certification “. • Editor at JTC13 WG3: “Cybersecurity Evaluation Methodology for ICT products”
  • 4. 3 PUBLIC - EU CSA CONFERENCE 2022 ABOUT US Fabien Deboyser: • Security Certification Expert • Common Criteria, FIPS 140-2 & 3, PCI-HSM, SESIP & ISO17025 Expert • Member of ISO/CEN committees: TC 224, ISO19790, ISO17825 • Eurosmart CDI representative • Former Common Criteria laboratory director
  • 5. 4 PUBLIC - EU CSA CONFERENCE 2022 Think Connect Act Sense Everything Safe & Secure Everything Aware Everything Smart Everything Connected Everything Efficient
  • 6. 5 PUBLIC HORIZONTAL CERTIFICATION SCHEME IS IN DEMAND TO ADDRESS VARIOUS REQUIREMENTS Government Legislation: • European Cyber Security Act • Singapore CSL • S.734 - Internet of Things Cybersecurity Improvement Act of 2019 • Cal. SB-327 Baseline Requirements: • CSA/MATTER (Zigbee etc) • ETSI 303 645 (Consumer) • NISTIR 8259 (Device Manufacturers) • UL 2900 (SW) Sector Specific: • ISO/SAE 21434 (Auto) • IEC 62443 (Industrial) • NFC/FiRa/CCC • Hospital & at-home Patient Monitoring • Personal Health & Fitness Monitoring​
  • 7. 6 INTERNAL CURRENT SITUATION = VENDOR PERSPECTIVE
  • 8. 7 PUBLIC - EU CSA CONFERENCE 2022 CURRENT SITUATION = VENDOR PERSPECTIVE
  • 9. 8 PUBLIC - EU CSA CONFERENCE 2022 Learning Inference Big Data Big Model Application Training Query Decision Feedback Connected devices are always online and can be monitored for unusual behaviour using AI both in the cloud and more and more at the edge. Security profiles can be loaded and adapted in real time SECURITY WILL CONSTANTLY EVOLVE IN REAL TIME
  • 10. 9 PUBLIC - EU CSA CONFERENCE 2022 No mutual recognition Standards checking the same work Chaos of certifications and overlapping of standards/schemes CURRENT SITUATION = LABORATORY PERSPECTIVE
  • 11. 1 0 PUBLIC - EU CSA CONFERENCE 2022 Lack of personnel Too Many Accreditation Audits PROBLEMS FROM THE LABORATORY PERSPECTIVE
  • 12. 1 1 PUBLIC - EU CSA CONFERENCE 2022
  • 13. 1 2 PUBLIC - EU CSA CONFERENCE 2022 • The art of putting “things together”, to create harmony • In security certification: • the art of reusing existing compliance proofs without re-evaluation, re-audit or re-testing • This can be done within a scheme or multiple schemes WHAT IS COMPOSITION? Secure processor HW block Secure processor HW crypto Module HW clock OS OS Device Module Secure Storage Secure Comm …
  • 14. 1 3 PUBLIC - EU CSA CONFERENCE 2022 CC PP0084 CC PP0099 SESIP NXP Secure Product Development Process IEC62443-4-1 IEC62443-4-2 SOLUTIONS FROM THE VENDOR PERSPECTIVE = CROSS SCHEME AND COMPOSI TION IN PRACTICE
  • 15. 1 4 PUBLIC - EU CSA CONFERENCE 2022 CROSS STANDARD & SCHEME COMPOSITION Cross Standard & Scheme composition To reuse existing compliance proofs across different certification schemes or standards without (or only limited) re-evaluation, re-audit or re-testing. AVA AGD ATE ASE ALC ADV IEC 62443-4-2 Certificate IEC 62443-4-1 Certificate ETSI EN 303 645 Certificate ISO27001 Certificate LINCE/CSPN/BSZ/FITCEM Certificate Re-use of the Certificate with Conditions Re-use of the Certificate with Conditions Re-use of the Certificate for ALC_DVS with Conditions Re-use of the Certificate Re-use of the Certificate for ALC with Conditions COMMON CRITERIA
  • 16. 1 5 PUBLIC - EU CSA CONFERENCE 2022 INTERESTING INITIATIVES FROM THE LAB PERSPECTIVE Mutual recognition – CSPN & BSZ ECSO – Product Certification Composition IACS ERNCIP Recommendations – Definition of the scheme FITCEM URWP – New Schemes
  • 17. 1 6 PUBLIC - EU CSA CONFERENCE 2022 Recognition between countries for lightweigths schemes or A ligthweight horizonal scheme in Europe under the CSA Food for thoughts
  • 18. 1 7 PUBLIC - EU CSA CONFERENCE 2022 New version of Common Criteria includes exact conformance LET’S USE IT! LET’S INNOVATE! Eg.- Develop an PP for IoT devices mandating an ETSI certificate + AVA_VAN activities This will allow to reuse the ETSI certificate saving a lot of time related to the CC certification Food for thoughts
  • 19. 1 8 PUBLIC - EU CSA CONFERENCE 2022 • Technical WGs to discuss technical details/challenges of Cross Standard and scheme composition at ENISA • New Cybersecurity Act schemes should integrate cross standard and scheme composition from the very beginning Food for thoughts
  • 20. 1 9 PUBLIC - EU CSA CONFERENCE 2022 Questions?
  • 21. 2 0 PUBLIC - EU CSA CONFERENCE 2022 Thanks José Ruiz jruiz@jtsec.es Fabien Deboyser fabien.deboyser@nxp.com