SERVICES
More about our services
Our accredited Testing Laboratory performs security (testing / validating) of information technology products and electronic information systems according to accreditation.
Non-accredited business opportunities are also covered without risking impartiality.
Security evaluation of IT products
When evaluating software products with security functionalities, we examine the functional and assurance security requirements laid down by the client in the product’s Security Target according to the ISO/IEC 15408 (-1, -2, -3) standard and ISO/IEC 18045 evaluation methodology, based on the developers’ deliverables written either in Hungarian or in English. Evaluation assurance levels undertaken:
EAL 1 EAL 2 EAL 3 EAL 4As the client’s discretion, we apply the Hungarian counterpart of Common Criteria /CC/ and Common Evaluation Methodology /CEM/ (Evaluation Methodology for products; Committee of IT in the Public Sector /KIB/ Recommendation No 28) as part of the “MIBÉTS” (Hungarian Information Technology Security Evaluation and Certification Scheme- KIB Recommendation 25th), which are supported by Hungarian manuals („Model and processes”, „Guidance for Vendors”, „Guidance for Developers”).
In this case we examine developers’ deliverables written in Hungarian, at MIBÉTS levels basic, moderate or high.
Security evaluation of electronic information systems
When evaluating the security of electronic information systems one evaluation option is to apply the administrative, physical and logical controls defined in the Decree 41/2015 (VII.15.) of the Ministry of Interior at security levels 2, 3 and 4.
The other evaluation option is to evaluate the fulfilment of the security controls and control enhancements specified in NIST SP 800-53 Rev5 security control guidance (Security and Privacy Controls for Federal Information Systems and Organisation) according to the Low and Moderate control baseline.
In both cases the evaluation methodology in NIST SP 800-53A Rev5 publication is followed.
Consultation service to be prepared
We - as an IT security consultation provider - undertake to help our customers to prepare for the evaluation and certification of information technology products and services.
WE GIVE SUPPORT FOR:
In these areas our experts pursue solely such activities that do not conflict with our accredited evaluation services.