Navigation and service

Notes on Application and Interpretation (AIS)

The following table lists all AIS notes in the evaluation process of the German certification scheme. Please note that the AIS notes and associated documents in PDF format are not necessarily barrier-free.

As part of the further development of the CC, countries that have signed the SOG-IS 1 agreement on the recognition of IT security certificates at the European level generate JIL documents on different aspects of the CC. Documents agreed at the international level, which are known as CC supporting documents, are published on the Common-Criteria-website.

In the German scheme, these documents are associated with specific AIS

Tabelle 1: AIS the German scheme
AIS no.Vers.TopicAnnexes to AIS
AIS 501.0Guidance for tool-supported and automated software testing

Fuzzing_Primer_V1.6

ETR-Part_ATE_AVA_Fuzzing-Template_V1.0

AIS 491.0Evaluation methodology for hardware devices with security boxesJIL document: 'Application of Attack Potential to Hardware Devices with Security Boxes'
AIS 481.0Requirement for testing security labels
AIS 471.1Rules for the certification of development and production sites in accordance with Common Criteria (Site Certification)

Guidance for Site Certification (GuideSite) - Version 1.1

Details for the structure and content of the ETR for Site Certification (CreateETR) - Version 1.0

Supporting Document: Guidance for Site-Certification (SiteCert) - Version 1.1

Template ETR Part ALC (TempALC) - Version 1.0

Template ETR Part AST (TempAST) - Version 1.0

AIS 46

3

Information regarding the evaluation of cryptographic algorithms and additional information for the evaluation of random number generators

Guidelines for Evaluating Side-Channel and Fault Attack Resistance of Elliptic Curve Implementations

Guidelines for Evaluating Side-Channel-Attack Resistance of RSA, DSA and Diffie-Hellman Key Exchange Implementations

Methodology for cryptographic rating of memory encryption schemes used in smartcards and similar devices (MEguide) - Version 1.0

AIS 421Information on creating manufacturer documents for product evaluation according to Common Criteria Guidelines for Developer Documentation according to Common Criteria Version 3.1 (GD_DEV) - Version 3.1
AIS 412Instructions on creating protection profiles and security targets The PP/ST-Guide [PP/ST] - Version 2.0
AIS 401Application of the interpretation for the certification of digital tachographs JIL-Document "Interpretation for Security Evaluation and Certification of Digital Tachographs" (JIL-Tacho) - Version 1.12
AIS 393Development and evaluation of formal security models Guideline for the Development and Evaluation of formal security policy models in the scope of ITSEC and Common Criteria (FM-Guide) - Version 2.0
AIS 382Reuse of evaluation results
AIS 373Terminology for and preparation of smartcard evaluations

JIL-Document "Smartcard evaluation guidance"

The corresponding document from the international CCRA agreement can be found on the CCRA webportal.

AIS 365ETR supplement for the support of smartcard composition certifications (ETR for composition)

JIL-Document "Certification of "open" smart card products" (JIL-Open_SC) - Version 1.1 (for trial use)

JIL-Document "ETR template for composite evaluation" (JIL-COMP_ETR_TEMPL) - Version 1.1

JIL-Document "Composite product evaluation for Smart Cards and similar devices" (JIL-COMP) - Version 1.4

The corresponding document from the international CCRA agreement can be found on the CCRA webportal.

AIS 352Public version of a Security Target (ST-lite) CC Supporting Document "ST-lite" (MC-ST-LITE) - Version 1.0
AIS 343Evaluation methodology for the assurance class EAL5+
AIS 327CC-interpretations in the German certification scheme

Precise definition of (requirements for) "demonstrable conformance"

Extension of definition of (requirements for) "strict conformance"

Interpretationen im deutschen Schema zur CC Version 3.1

Übersicht CC-Zertifizierung / Fristen und Übergangsregelungen (ÜBERGANG) - Stand 07.06.2011

AIS 313Functionality classes and evaluation methodology for physical random number generators

Evaluation of random number generators - (RNGEV) - Version 0.1

A proposal for: Functionality classes for random number generators - Version 2.0

A proposal for: Functionality classes and evaluation methodology for true (physical) random number generators

Referenzimplementierung der statistischen Tests /Reference implementation of the statistical tests

Developer evidence for the evaluation of a physical true random number generator

Evaluation Report as part of the Evaluation Technical Report. Part B. ETR-Part. True Physical and Hybrid Random Number Generator

AIS 275Transition from ITSEC to Common Criteria
AIS 2610Evaluation methodology for circuits integrated in hardware

JIL-Document "Application of Attack Potential to Smartcards" (JIL-AP-SC) - Version 2.9

Das entsprechende Dokument aus dem internationalen CCRA-Abkommen finden Sie auf dem CCRA-Webportal.

AIS 259Applying the CC to integrated circuits

JIL-Document "The Application of CC to Integrated Circuits" (HW-IC-CC) - Version 3.0

JIL-Document "Security Architecture Requirements (ADV_ARC) for smart cards and similar devices" (JIL-HW-ADV_ARC) - Version 2.0

JIL-Document "Security Architecture Requirements (ADV_ARC) for smart cards and similar devices Appendix 1" - Version 2.0

JIL-Document "Security Requirements for post-delivery code loading" (JIL_SecReq-CodeLoad) - Version 1.0
Validity of conducted tests on Security Smart Card ICs in dependence of test date (Test-Valid) - Version 1

Das entsprechende Dokument aus dem internationalen CCRA-Abkommen finden Sie auf dem CCRA-Webportal.

AIS 234Gathering evidence from developers JIL-Document "Collection of Developer Evidence" (JIL-CDE) - Verion1.5
Folgendes Dokument ist inhaltlich identisch mit dem JIL-Dokument und nur zur Vollständigkeit veröffentlicht:
Collection of Developer Evidence (CCDB-CDA) - Version 1.5
AIS 203Functionality classes and evaluation methodology for deterministic random number generators

Evaluation of random number generators - (RNGEV) - Version 0.1

A proposal for: Functionality classes for random number generators (KS2011) - Version 2.0

Developer evidence for the evaluation of a deterministic random number generator (DRGDEV) - Version 0.9

ETR-Part Deterministic Random Number Generator (DRGEV) - Version 0.1

Functionality Classes and Evaluation Methodology for Deterministic Random Number Generators (AIS20V1) - Version 2.0

AIS 199Structure of the ETR
AIS 147Requirements for the structure and content of individual audit reports for evaluators according to CC

Guidelines for Evaluation Reports (GD_EVAL) - Version 2.0

Checkliste für die Qualitätssicherung von ETR-Teilen (QSCHCK) - Version 1.0

AIS 114Performance of the site visit in the development environmentChecklist for JIL-Minimum-site-security-requirements-v0.96
JIL-Minimum-Site-security-Requirements-V1.1(for_trial_use)