# Common Criteria for IT Security Evaluation (ISO/IEC 15408)

Framework id: `common_criteria`. Evaluation Standard. Publisher: CCRA (Common Criteria Recognition Arrangement). Version: 3.1 R5 (ISO/IEC 15408:2022). Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.commoncriteriaportal.org/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (13, average coverage 56%)
- CC Part 1 — PP Protection Profile (PP) Development — PP structure, conformance claims, security problem definition, and PP evaluation: PL-02, PL-07, PL-08, SA-04, SA-08, PM-07 (30%)
- CC Part 1 — ST Security Target (ST) Development — TOE description, security objectives, SFR/SAR selection, and conformance claims: PL-02, PL-08, SA-04, SA-08, SA-17, CA-06 (35%)
- CC Part 2 — FAU Security Audit (FAU) — audit data generation, analysis, review, event storage, and selection: AU-01, AU-02, AU-03, AU-04, AU-05, AU-06, AU-07, AU-08, AU-09, AU-10, AU-11, AU-12, AU-13, AU-14, SI-04 (85%)
- CC Part 2 — FCS Cryptographic Support (FCS) — key management and cryptographic operations: SC-12, SC-13, SC-17, SC-08, SC-28, IA-07, CM-14 (78%)
- CC Part 2 — FDP User Data Protection (FDP) — access control policy, information flow control, data exchange, and residual information: AC-03, AC-04, AC-05, AC-06, AC-16, AC-24, SC-04, SC-07, SC-08, SC-16, SI-12, MP-06 (75%)
- CC Part 2 — FIA Identification and Authentication (FIA) — user identification, authentication mechanisms, and authentication failure handling: IA-01, IA-02, IA-03, IA-04, IA-05, IA-06, IA-07, IA-08, IA-09, IA-10, IA-11, IA-12, AC-07 (82%)
- CC Part 2 — FMT Security Management (FMT) — management functions, security roles, TSF data management, and revocation: AC-01, AC-02, AC-05, AC-06, CM-05, CM-06, CM-07, CM-09, PL-09, PM-02, PS-06 (72%)
- CC Part 2 — FPR Privacy (FPR) — anonymity, pseudonymity, unlinkability, and unobservability: PT-01, PT-02, PT-03, PT-04, PT-05, PT-06, PT-07, PT-08, SI-19 (55%)
- CC Part 2 — FPT Protection of the TSF (FPT) — fail secure, self-testing, internal TOE transfer, TSF data integrity, replay detection, and state management: SC-04, SC-07, SC-08, SC-24, SI-06, SI-07, SI-16, CM-14, CP-12, SA-11 (68%)
- CC Part 2 — FRU/FTA/FTP Resource Utilisation (FRU), TOE Access (FTA), and Trusted Path/Channels (FTP): SC-05, SC-06, SC-10, SC-23, AC-07, AC-08, AC-10, AC-11, AC-12, AC-17, CA-03, SC-11 (70%)
- CC Part 3 — SAR Security Assurance Requirements (SAR) — EAL levels, vulnerability analysis, development documentation, testing, and life-cycle support: SA-03, SA-04, SA-08, SA-10, SA-11, SA-15, SA-17, CA-02, CA-08, RA-05 (40%)
- CCRA Common Criteria Recognition Arrangement (CCRA) — mutual recognition, certificate acceptance levels, and certification body accreditation: SA-04, SA-09, PM-08, CA-06 (15%)
- CEM Common Evaluation Methodology (CEM) — evaluator actions, verdict criteria, evidence requirements, and evaluation technical reports: CA-02, CA-04, CA-07, CA-08, SA-11 (22%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=common_criteria
- Control-to-clause mappings as JSON: /api/v1/frameworks/common_criteria?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/common-criteria.json
- Page for people: /frameworks/common-criteria/
