Connecting the Czech Republic to the CCRA

At the end of September 2004, the Czech Republic joined as the twentieth country to the international agreement on mutual recognition of certificates issued in the field of information technology security for the certification of compliance with the criteria of the "Common Criteria for Information Technology Security Evaluation" (hereinafter referred to as "CC"). CC is also an international standard ISO/IEC 15408 and under the title "Common Criteria for Information Technology Security Evaluation" was adopted as the Czech national standard ČSN ISO/IEC 15408.

The certificate recognition agreement is called "Arrangement on the Mutual Recognition of Common Criteria Certificates in the Field of IT Security", commonly abbreviated as CCRA (Common Criteria Recognition Arrangement). The Czech Republic is represented in the CCRA by the National Security Authority.

The NSA requested to join the agreement in January this year as a participant using certificates issued under the CCRA. In September of this year, the admission procedure was successfully completed. Director NBÚ Mgr. Jan Mareš signed the CCRA on 27 September 2004 at the CCRA Steering Committee meeting in Berlin, on the eve of the opening of the fifth International Conference on CC (ICCC). The relevant documents were ceremoniously handed over to the representatives of the Czech Republic in the CCRA Steering Committee on 28 September as part of the established ceremony for the admission of new participants and the handover of newly issued certificates. The representative of the Czech Republic in the CCRA Steering Committee became the Director of the Technical Section of the NSA Ing. Jaroslav Šmíd.

This act defines which certificates issued in the field of information technology security will be automatically accepted by the NSA. It should be emphasised that the use of a CC-certified product or protection profile does not yet guarantee the certification of an information system under Act No 148/1998 on the protection of classified information and amending certain acts, as amended, but it is a very important building block in the construction of a secure information system.

Learn more about CC, CCRA, the mutually recognised level of assessment by CC, certified IT products and protection profiles.