6 Tips to Help Avoid Surprises In Your Next Common Criteria Evaluation

Jason Lawlor Certifications, Common Criteria

Undertaking a Common Criteria (CC) evaluation should not be an opaque process from a timing, process or cost perspective. In this post, the testing experts at Lightship provide 6 practical tips to ensure that you are getting the best value and outcomes for your certification dollar. The following is targeted primarily at Protection Profile (PP) based evaluations, but most also apply to Security Target (EAL) based projects.

Read More


Lightship at IAEA Meeting on Cyber Risk in the Nuclear Supply Chain

Lachlan Turner Common Criteria, Lightship News

Lightship Security Director of Consulting, Lachlan Turner, was nominated by the Government of Canada to participate in the International Atomic Energy Agency (IAEA) Technical Meeting on Reducing Cyber Risks in the Supply Chain which was held at IAEA’s Headquarters in Vienna, Austria, from 25 to 29 June 2018. Lachlan attended along with some 110 other delegates from around the world. Delegates included nuclear regulators, operators, suppliers and various other industry representatives.Read More

Don’t Call it a Bash Script: Automation is Not Scripting

Alex Thurston Certifications, Common Criteria

Or, maybe it is.  In reality, the answer is that all automation is scripting but not all scripting is automation.  Automation is really a maturation or evolution of scripting.  Calculators script the mathematical principles defined by Thales, Pythagoras, Euclid and Archimedes.  To-do applications script the act of making a list of tasks on a piece of paper and scratching them off.  The directions given by Google Maps on a road trip script the job normally performed by the person with a paper map sitting in the passenger seat.

Read More

Secure Tunnelled NTP Proof of Concept

Greg McLearn Common Criteria

Update 2018-Oct-03: This post has been updated within new information from NDcPP v2.1.

Recently, NIAP issued Technical Decision TD0321: Protection of NTP communications.  It states that network time sources are critical pieces of information that must be protected.  However, having no other agreed-upon mechanism to authenticate the source of, or ensure the integrity of NTP packets, NIAP requires vendors to use NTP over one of only a handful of acceptable trusted communications channels: TLS, DTLS, HTTPS*, SSH or IPSec.

This leaves many vendors in a bind since there are (a) no public-facing NTP servers that operate over any of these permissible channels; and, more importantly, (b) there are no widely available NTP server/client implementations that can be used to build such a solution.

Read More


NIAP TD0321: Protection of NTP communications

Lachlan Turner Certifications, Common Criteria

Update 2018-Oct-03: This post has been updated within new information from NDcPP v2.1.

NIAP has issued Technical Decision TD0321 against the Network Device Collaborative Protection Profile (NDcPPv2.0e) mandating the use of a trusted channel (IPsec, SSH, TLS, DTLS, HTTPS) for NTP (or non-NTP external entity used to set time).  This will impact any in-flight and future NDcPP evaluations that are destined for the NIAP PCL.
Read More

Common Criteria Lab Accreditation

Lachlan Turner Certifications, Common Criteria, Lightship News

We are excited to announce that Lightship Security is a fully accredited Common Criteria laboratory. Prepare for warp-speed certifications! Contact us to find out how our experienced team uses Greenlight automation and Lightship’s industry first functional gap assessment methodology to transform your certification experience.

Full press release: Lightship Security completes accreditation as Common Criteria laboratory

Standards Council of Canada: Directory of Accredited Laboratories – Lightship Security

Communications Security Establishment: Common Criteria Evaluation Facilities


On the Road with Mobile Certifications

Greg McLearn Certifications, Humour

At Lightship Security, we are all about certifying at the speed of development.  Therefore, we are proud to announce our new mobile certifications laboratory.  With over 1200 cubic feet of interior high-tech laboratory goodness, we can handle even your most demanding certification needs.  The 10-cylinder, 350 horsepower motor will have us rolling into your neighbourhood before the ink dries on the contract.

Look for Lightship Security Mobile Certifications near you.  For more information about this amazing industry-first service, click here.