Re: Vulnerability Assessment of a EAL 4 system



Answer to all of your questions is , evaluate the Linux system according the documentation developed
by Klaus Weidner <klaus@xxxxxxxxx>.

http://www-128.ibm.com/developerworks/linux/library/os-ltc-security/

Thanks & Regards,
Shashi Kanth

castellan2004-fd@xxxxxxxxx wrote:
I am looking at a Linux server which has been
accredited as a EAL4 system by IBM. During the
assessment, I was looking for standard Linux
protections like iptables, ssh etc. On this server,
there is no iptables.

Regardless, I would like to know how to evaluate a EAL
4 system. What do you need to look for in the EAL 4
system in production that could become vulnerable?

Thank you in advance for any help.




Relevant Pages