[ previous ] [ next ] [ threads ]
 
 From:  "Kristian Shaw" <monowall at wealdclose dot co dot uk>
 To:  <m0n0wall at lists dot m0n0 dot ch>
 Subject:  Re: [m0n0wall] ITSEC Security Question...
 Date:  Wed, 9 Aug 2006 20:30:08 +0100
Hello,

To get an E3 rating the product has to be submitted for testing. I think the 
company also has to prove they meet certain standards for documentation etc.

If you need an E3 firewall you should also be looking at products with an 
EAL4 rating as this is equivalent. In fact, it will be easier to get an EAL4 
rated product since this is non-UK specific, but it still recognised as 
valid in the UK.

Since getting approval costs money you aren't going to find any inexpensive 
firewall product that has it. You will be looking at products from peeople 
like Cisco and Checkpoint and even then very specific products since the 
approval only covers the configuration that was tested.

Kris.

----- Original Message ----- 
From: "Mark Jawdoszak" <MarkJ at logsysgroup dot com>
To: <m0n0wall at lists dot m0n0 dot ch>
Sent: Wednesday, August 09, 2006 11:34 AM
Subject: [m0n0wall] ITSEC Security Question...


Hi All,



I was wondering if m0n0wall or any other firewall following the same
ideas (i.e. free) have or will be covered under the EU's ITSEC rules?



http://www.cesg.gov.uk/site/iacs/index.cfm?menuSelected=1&displayPage=12



I've been using m0n0walls for many different applications (as well as a
firewall :D), but management want (and need) to know of E3 security
certified firewalls.  I want to use m0n0 boxes for this, but as they
don't seem to be covered under ITSEC regulations, I was wondering if
this could be done?


I have already searched the site, and the mailing list.


Thanks in advance,



Mark Jawdoszak

Logsys Support, Leeds

+44 (0)113 384 0400 - ext 411

markj at logsysgroup dot com






This message and any attachments are intended for the stated recipient only 
and in no
way constitute a binding contractual agreement, order, or commitment by the 
sender
WHO IS NOT TO BE BOUND BY ANYTHING CONTAINED HEREIN. If you have
received this message in error, please return it to the sender, indicating 
such and then
delete and destroy all copies in your possession.