The CCN (spanish National Cryptologic Center) has published the LINCE - National Essential Safety Certification evaluation methodology on its website.
The CCN indicates in its website the following:
❝LINCE is oriented to the evaluation and certification of ICT security products for inclusion in the CPSTIC catalogue for medium or low levels of the ENS in accordance with CCN-STIC-107 and CCN-STIC-141 guides. It can also be used for the performance of complementary STIC Evaluations as specified in CCN-STIC-106 and CCN-STIC-140 guides.
This methodology will therefore facilitate the inclusion in the CPSTIC Catalog which regulates the acquisition of IT products in the Spanish administration.
The main features of the LINCE certification aren:
- Focused on vulnerability analysis and penetration testing.
- It analyzes product compliance with your critical security requirements.
- Temporarily limited in both effort (25 man/days) and duration (8 weeks)
- Reduces manufacturer effort compared to other evaluation methodologies such as Common Criteria.
- Applicable when the threat level is basic or medium.
- The evaluation will be carried out by laboratories accredited by the CCN.
The certification body has published the following documents
-
CCN-LINCE-001: Definition
- This document includes the definition of LINCE, as well as the definition of the actors involved in the evaluation process, and the different phases of the evaluation process.
-
CCN-LINCE-002: Evaluation Methodology
- This document contains the evaluation methodology to be followed by the laboratories.
-
CCN-LINCE-003: Security Statement Template
- The purpose of this template is to make it easier for developers to write the Security Targetrequired for the LINCE assessment.
-
CCN-LINCE-004: Template for the Technical Evaluation Report
- The aim of this template is to make the validation of the reports issued by the laboratories more effective by the CB (Certification Body).
This methodology, created by the certification body, is aligned with other similar initiatives in European countries such as CSPN in France and with the levels of assessment defined in the Cybersecurity Act promoted by the European Commission.
If you need any information on how to include your product in the catalogue (CPSTIC) or about the LINCE certification, please do not hesitate to contact us at hello[en]jtsec.es.
You may also take a look at our LINCE evaluation service section for further information.