Common Criteria Life Cycle Support Documentation
Go Back to Services PageImplementation Representation Configuration Management Coverage
The objective of this family is to require the developer's Configuration Management system to have certain capabilities. These are meant to reduce the likelihood that accidental or unauthorized modifications of the configuration items will occur. The Configuration Management system should ensure the integrity of the Target of Evaluation from the early design stages through all subsequent maintenance efforts.
Delivery Procedures
The concern of this family is the secure transfer of the finished Target of Evaluation from the development environment into the responsibility of the user.
The requirements for delivery call for system control and distribution facilities and procedures that detail the measures necessary to provide assurance that the security of the Target of Evaluation is maintained during distribution of the Target of Evaluation to the user. For a valid distribution of the Target of Evaluation, the procedures used for the distribution of the Target of Evaluation address the objectives identified in the Protection Profile/Security Target relating to the security of the Target of Evaluation during delivery.
Identification of Security Measures
Development security is concerned with physical, procedural, personnel, and other security measures that may be used in the development environment to protect the Target of Evaluation and its parts. It includes the physical security of the development location and any procedures used to select development staff.
Developer Defined Life-Cycle Model
A life-cycle model encompasses the procedures, tools and techniques used to develop and maintain the Target of Evaluation. Aspects of the process that may be covered by such a model include design methods, review procedures, project management controls, change control procedures, test methods, and acceptance procedures. An effective life-cycle model will address these aspects of the development and maintenance process within an overall management structure that assigns responsibilities and monitors progress.

