Przejdź do treści głównej
Flaga Unii Europejskiej

Star Methodology

The “Site Technical Audit Report” (STAR) is designed to contain and provide the necessary information to support re-use of ALC-related evaluation evidences and results across (similar) TOEs and between ITSEFs and CBs. 

  • Informacja uzupełniająca

Informacje szczegółowe

Data publikacji
20 marca 2025 (Ostatnia aktualizacja: 19 grudnia 2025)
Autor
Agencja Unii Europejskiej ds. Cyberbezpieczeństwa

Opis

The assurance class ALC “Life-cycle support” is addressing the aspect of establishing appropriate security controls and mechanisms at the developer’s sites for the development, production, delivery and maintenance of the TOE. For some ALC assurance components (in particular for high assurance evaluations) the evaluator activities for this class usually include an on-site evaluation of these security controls and mechanisms. The security controls and mechanisms documented and implemented by the site are often applicable to other TOEs of the same developer and also from other developers, especially where the TOE follows the same life-cycle support processes.

The “Site Technical Audit Report” (STAR) is designed to contain and provide the necessary information to support re-use of ALC-related evaluation evidences and results across (similar) TOEs and between ITSEFs and CBs.

The STAR methodology template provided below is recommended for use.

Pliki

  • 28 KWIETNIA 2025
STAR Methodology - Report template v1
  • 16 GRUDNIA 2025
EUCC_SotA_STAR Methodology v1 (final)