HCISPP · Question #269
Which of the BEST internationally recognized standard for evaluating security products and systems?
The correct answer is B. Common Criteria (CC). Common Criteria (ISO/IEC 15408) is the internationally recognized standard specifically designed for evaluating the security properties of IT products and systems. It provides a framework for defining security requirements (Protection Profiles), specifying security claims…
Question
Which of the BEST internationally recognized standard for evaluating security products and systems?
Options
- APayment Card Industry Data Security Standards (PCI-DSS)
- BCommon Criteria (CC)
- CHealth Insurance Portability and Accountability Act (HIPAA)
- DSarbanes-Oxley (SOX)
How the community answered
(36 responses)- A3% (1)
- B94% (34)
- D3% (1)
Explanation
Common Criteria (ISO/IEC 15408) is the internationally recognized standard specifically designed for evaluating the security properties of IT products and systems. It provides a framework for defining security requirements (Protection Profiles), specifying security claims (Security Targets), and independently evaluating products at defined assurance levels (EAL 1–7). Governments and organizations worldwide use CC evaluations to certify products before procurement. The other options are not product evaluation standards: PCI-DSS governs payment card data security for merchants; HIPAA is U.S. healthcare privacy and security regulation; and SOX (Sarbanes-Oxley) addresses financial reporting and internal controls for public companies.
Topics
Community Discussion
No community discussion yet for this question.