<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is the Number of Vulnerabilities a Leading or Lagging Indicator?</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=427" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=427</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Robert E. Lee</title>
		<link>http://spiresecurity.com/?p=427&#038;cpage=1#comment-703</link>
		<dc:creator>Robert E. Lee</dc:creator>
		<pubDate>Sun, 21 May 2006 23:57:59 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=427#comment-703</guid>
		<description><![CDATA[@Pete

&gt; Are you suggesting that Common Criteria is using a metric to determine security level or simply that EAL4 (like one of the Windows variants has) or other is useful in this regard?

Keep in mind that EAL4+ is the level of assurance you have that they met the goals outlined in their Security Target (http://niap.nist.gov/cc-scheme/st/ST_VID4025-ST.pdf).  Those goals are quite low when compared with the goals of Trusted Solaris (http://www.cesg.gov.uk/site/iacs/itsec/media/sectarg/TSolaris8_Issue3.1.pdf).

You can&#039;t compare the assurance metric alone without considering what it is providing assurance of =).

Robert
]]></description>
		<content:encoded><![CDATA[<p>@Pete</p>
<p>> Are you suggesting that Common Criteria is using a metric to determine security level or simply that EAL4 (like one of the Windows variants has) or other is useful in this regard?</p>
<p>Keep in mind that EAL4+ is the level of assurance you have that they met the goals outlined in their Security Target (<a href="http://niap.nist.gov/cc-scheme/st/ST_VID4025-ST.pdf" rel="nofollow">http://niap.nist.gov/cc-scheme/st/ST_VID4025-ST.pdf</a>).  Those goals are quite low when compared with the goals of Trusted Solaris (<a href="http://www.cesg.gov.uk/site/iacs/itsec/media/sectarg/TSolaris8_Issue3.1.pdf" rel="nofollow">http://www.cesg.gov.uk/site/iacs/itsec/media/sectarg/TSolaris8_Issue3.1.pdf</a>).</p>
<p>You can&#8217;t compare the assurance metric alone without considering what it is providing assurance of =).</p>
<p>Robert</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=427&#038;cpage=1#comment-702</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Wed, 10 May 2006 17:53:58 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=427#comment-702</guid>
		<description><![CDATA[@Robert -

Are you suggesting that Common Criteria is using a metric to determine security level or simply that EAL4 (like one of the Windows variants has) or other is useful in this regard?
]]></description>
		<content:encoded><![CDATA[<p>@Robert -</p>
<p>Are you suggesting that Common Criteria is using a metric to determine security level or simply that EAL4 (like one of the Windows variants has) or other is useful in this regard?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert E. Lee</title>
		<link>http://spiresecurity.com/?p=427&#038;cpage=1#comment-701</link>
		<dc:creator>Robert E. Lee</dc:creator>
		<pubDate>Wed, 10 May 2006 13:55:09 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=427#comment-701</guid>
		<description><![CDATA[&gt; What we really need is a better way to evaluate software security without resorting to these numbers.

We already have one - http://www.commoncriteriaportal.org/.  Assurance is much a better measurement than the lagging indicator of vulnerability counts.

Using the vulnerabilty count data to measure how secure a product is reminds me of the villagers logic from Monty Pythons Holy Grail where they attempt to determine if the young lady is a witch - Re-read http://www.mwscomp.com/movies/grail/grail-05.htm and replace the test for being a witch with measuring insecure software. =)

Robert
]]></description>
		<content:encoded><![CDATA[<p>> What we really need is a better way to evaluate software security without resorting to these numbers.</p>
<p>We already have one &#8211; <a href="http://www.commoncriteriaportal.org/" rel="nofollow">http://www.commoncriteriaportal.org/</a>.  Assurance is much a better measurement than the lagging indicator of vulnerability counts.</p>
<p>Using the vulnerabilty count data to measure how secure a product is reminds me of the villagers logic from Monty Pythons Holy Grail where they attempt to determine if the young lady is a witch &#8211; Re-read <a href="http://www.mwscomp.com/movies/grail/grail-05.htm" rel="nofollow">http://www.mwscomp.com/movies/grail/grail-05.htm</a> and replace the test for being a witch with measuring insecure software. =)</p>
<p>Robert</p>
]]></content:encoded>
	</item>
</channel>
</rss>
