5. CESTI approval procedure
Information Technology Security Assessment Centers (ITSACs) are private companies, independent of product developers and sponsors. ITSEFs may be part of a group of companies, but their activities must be strictly segregated from the group's other activities. CESTIs are responsible for evaluation operations in the CSPN and CC certificate procedures.
CESTIs are accredited by the ANSSI certification center. They are made up of a team of experts in information systems security. In addition to their technical skills and knowledge of CCs, ITSEFs must be impartial. It must therefore have no ties with the client. ANSSI constantly checks that the ITSEF complies with the conditions for approval. The approval procedure enables CESTIs to be strictly selected.
Decree no. 2002-535 of April 18, 2002, on the evaluation and certification of the security...
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed?
Log in!
Ongoing reading
CESTI approval procedure