Vous êtes sur la page 1sur 7

35036 Federal Register / Vol. 72, No.

122 / Tuesday, June 26, 2007 / Notices

national importance of fostering operations; assess capability gaps; and evaluating, certifying, or validating
technological innovation based upon identify possible solutions. information assurance products under
solid science, resulting in commercially In accordance with section 10(d) of the National Information Assurance
successful products and services. the Federal Advisory Committee Act, Program (NIAP) or successor program.
On March 2, 2007, the Technology Pub. L. 92–463, as amended (5 U.S.C. Table A sets forth the Fee-For-Service
Administration published a notice of App. 2) and 41 CFR 102–3.155, the rates that will be assessed to NIAP
solicitation for nominees for the 2007 Department of Defense has determined accredited commercial Common Criteria
National Medal of Technology. The that these Defense Science Board Testing Labs (CCTLs) for ‘‘validation’’
original deadline for nominees was May Summer Study meeting will be closed to services performed by NIAP validator
31, 2007. Due to server problems the public. Specifically, the Under personnel on information technology
encountered during the submission Secretary of Defense (Acquisition, (IT) security products being evaluated
period, which resulted in the inability Technology and Logistics), with the by the NIAP CCTLs pursuant to the
for some nomination packages to be coordination of the DoD Office of Common Criteria Evaluation and
submitted before the deadline, the General Counsel, has determined in Validation Scheme (CCEVS).
Technology Administration is extending writing that all sessions of these DATES: Comments must be received on
the deadline from May 31, 2007, to July meetings will be closed to the public or before August 27, 2007. Do not
18, 2007. Nomination packages because they will be concerned submit comments directly to the point
submitted and received between May throughout with matters listed in 5 of contact or mail your comments to any
31, 2007 and June 26, 2007 are deemed U.S.C. 552b(c)(1). address other than what is shown
to be timely. All other program Interested persons may submit a below. Doing so will delay the posting
requirements and information published written statement for consideration by of the submission.
in the original solicitation remain the Defense Science Board, Individuals ADDRESSES: You may submit comments,
unchanged. submitting a written statement must identified by docket number and or RIN
Eligibility and Criteria: Information on submit their statement to the Designated number and title, by any of the
eligibility and nomination criteria is Federal Official at the address detailed following methods:
provided on the Nominations below, at any point, however, if a • Federal eRulemaking Portal: http://
Guidelines Form at http:// written statement is not received at least www.regulations.gov. Follow the
www.technology.gov/medal. Applicants 10 calendar days prior to the meeting, instructions for submitting comments.
who do not have internet access should which is the subject of this notice, then • Mail: Federal Docket Management
contact Connie Chang, Research it may not be provided to or considered System Office, 1160 Defense Pentagon,
Director, Technology Administration at by the Defense Science Board. The Washington, DC 20301–1160.
the e-mail address or telephone number Designated Federal Official will review Instructions: All submissions received
above to request this information. all timely submissions with the Defense must include the agency name and
Science Board Chairperson, and ensure docket number or Regulatory
Dated: June 15, 2007.
they are provided to members of the Information Number (RIN) for this
Robert C. Cresanti, Federal Register document. The general
Defense Science Board before the
Under Secretary for Technology, U.S. policy for comments and other
Department of Commerce.
meeting that is the subject of this notice.
FOR FURTHER INFORMATION CONTACT: Ms.
submissions from members of the public
[FR Doc. E7–12327 Filed 6–25–07; 8:45 am] is to make these submissions available
Debra Rose, Executive Officer, Defense
BILLING CODE 3510–18–P
Science Board, 3140 Defense Pentagon, for public viewing on the Internet at
Room 3C553, Washington, DC 20301– http://regulations.gov as they are
3140, via e-mail at debra.rose@osd.mil, received without change, including any
DEPARTMENT OF DEFENSE or via phone at (703) 571–0084. personal identifiers or contact
information.
Office of the Secretary Dated: June 20, 2007.
FOR FURTHER INFORMATION CONTACT:
C.R. Choate,
Audrey M. Dale, 410–854–4458.
Advisory Committee Meetings Alternate OSD Federal Register Liaison
SUPPLEMENTARY INFORMATION: NSA and
Officer, Department of Defense.
AGENCY: Defense Science Board. the National Institute of Standards and
[FR Doc. 07–3111 Filed 6–25–07; 8:45 am]
ACTION:Notice of Advisory Committee Technology (NIST) formed the NIAP in
BILLING CODE 5001–06–M
Meetings. order to promote information security in
various ways, including the evaluation
SUMMARY: The Defense Science Board of IT security products. Commercial IT
DEPARTMENT OF DEFENSE
2007 Summer Study on Challenges to security product vendors initiate the
Military Operations in Support of Office of the Secretary NIAP evaluation process through
National Interests will meet in closed submission of their IT security product
session on August 6–16, 2007; at the [DoD–2007–OS–0066] to a nationally accredited commercial
Beckman Center, Irvine, CA. CCTL for evaluation against the
National Information Assurance
The mission of the Defense Science internationally recognized Common
Program
Board is to advise the Secretary of Criteria (CC) Standard for Information
Defense and the Under Secretary of AGENCY: Department of Defense; Technology Security Evaluation (ISO
Defense for Acquisition, Technology & National Security Agency. Standard 15408). NIAP evaluation is
Logistics on scientific and technical ACTION: Notice of new fees. voluntary for IT security products that
matters as they affect the perceived are acquired by United States
jlentini on PROD1PC65 with NOTICES

needs of the Department of Defense. At SUMMARY: Section 933 of Pub. L. 109– Government (USG) civil agencies and
this meeting, the Board will review 364, the John Warner National Defense non-USG entities, but as per National
previous and ongoing studies regarding Authorization Act for Fiscal Year 2007, Security Telecommunications &
stressing wars; identify defining provides that the Director, National Information Systems Security Policy
parameters for challenges to military Security Agency, may collect charges for (NSTISSP) No. 11, mandatory for IT

VerDate Aug<31>2005 17:07 Jun 25, 2007 Jkt 211001 PO 00000 Frm 00008 Fmt 4703 Sfmt 4703 E:\FR\FM\26JNN1.SGM 26JNN1
Federal Register / Vol. 72, No. 122 / Tuesday, June 26, 2007 / Notices 35037

security products purchased for use on Assurance Levels (EALs) beginning at VOR, the actual VOR meeting (attended
systems that process national security EAL 1 and moving up to the highest by the validators and lab personnel),
information. Additionally, per DoD possible assurance at EAL 7. and the Issue Resolution and Wrap-Up
Instruction 8500.2 the DoD mandates The two primary factors used in phase. During this final phase all
the use of CC or NIAP evaluated IT developing the Validation Fee relevant issues are addressed by the
security products on all DoD networks. Schedules were the EALs of the CCTL then the VOR report is finalized.
Evaluations are conducted by NIAP evaluations and the complexity (simple, At EAL 3s and above, witnessing of
accredited commercial CCTLs, with moderately complex, and complex) of testing by validator personnel may also
oversight provided by NIAP validator the product being evaluated. Higher be required.
personnel who are NSA government EALs require more rigorous and thus
employees, Federally Funded Research more costly evaluations. More complex An additional factor that will affect
& Development Center (FFRDCs) products typically take more time to the validation oversight costs is the
personnel or contractors. Prior to the analyze resulting in longer and more length of the evaluation since monthly
enactment of Sec 933, NSA paid for all costly evaluations. The complexity validation fees will be applied to cover
validation costs. Sec 933 shifts the costs factor takes into account size of the validator coordination and guidance
for this validation oversight from NSA product in terms of lines of code but costs throughout the course of the
to the commercial CCTLs (who may, in must also reflect the fact that new evaluation.
turn, will pass these fees onto the technologies will require additional
The final section of the fee schedule
product vendors seeking NIAP analysis. Simple products would
depicts costs for assurance maintenance
evaluation of their IT security products). include basic routers, switches or file
This change will ensure that NIAP can encryptors. Products of moderate which is the process vendors use to
keep pace with the commercial demand complexity would include simple maintain the currency of their product
for IT security product evaluations and firewalls or general application evaluations. Vendors submit rationale
will not be constrained by NSA’s software. Complex products would for why changes to their product did not
program budget for validation services. include standard operating systems and impact their evaluated product’s
Fee Schedule: TABLE A delineates new/unique IA products or security. The vendor proposals are
the NIAP Validation Oversight Fee technologies. reviewed by a NIAP senior validator
Schedule which will be assessed to While validation oversight occurs who determines if their rationale is
CCTLs for validation services provided throughout the course of an evaluation, sound and makes a recommendation to
in support of their NIAP evaluations. the majority of this oversight is focused NIAP management who then renders a
Fees are predicated on a per hourly on Validation Oversight Reviews verdict on the vendor assurance
basis by validator skill type and are a (VORs). These reviews take place at maintenance proposal.
function of the Evaluation Assurance critical points during the evaluation.
Dated June 19, 2007.
Levels (EALs) along with the type and Evaluations require Initial, Test and
complexity of the product technology. Final VORs. The VOR process typically L.M. Bynum,
The CC standard used for NIAP consists of three phases: the preparation Alternate OSD Federal Register Liaison
evaluations is broken down into phase where validators review Officer, DoD.
increasingly more rigorous Evaluation documents pertaining to that specific BILLING CODE 5001–06–P
jlentini on PROD1PC65 with NOTICES

VerDate Aug<31>2005 17:28 Jun 25, 2007 Jkt 211001 PO 00000 Frm 00009 Fmt 4703 Sfmt 4703 E:\FR\FM\26JNN1.SGM 26JNN1
35038 Federal Register / Vol. 72, No. 122 / Tuesday, June 26, 2007 / Notices
jlentini on PROD1PC65 with NOTICES

EN26JN07.000</GPH>

VerDate Aug<31>2005 17:07 Jun 25, 2007 Jkt 211001 PO 00000 Frm 00010 Fmt 4703 Sfmt 4725 E:\FR\FM\26JNN1.SGM 26JNN1
Federal Register / Vol. 72, No. 122 / Tuesday, June 26, 2007 / Notices 35039
jlentini on PROD1PC65 with NOTICES

EN26JN07.001</GPH>

VerDate Aug<31>2005 17:07 Jun 25, 2007 Jkt 211001 PO 00000 Frm 00011 Fmt 4703 Sfmt 4725 E:\FR\FM\26JNN1.SGM 26JNN1
35040 Federal Register / Vol. 72, No. 122 / Tuesday, June 26, 2007 / Notices
jlentini on PROD1PC65 with NOTICES

EN26JN07.002</GPH>

VerDate Aug<31>2005 17:07 Jun 25, 2007 Jkt 211001 PO 00000 Frm 00012 Fmt 4703 Sfmt 4725 E:\FR\FM\26JNN1.SGM 26JNN1
Federal Register / Vol. 72, No. 122 / Tuesday, June 26, 2007 / Notices 35041
jlentini on PROD1PC65 with NOTICES

EN26JN07.003</GPH>

VerDate Aug<31>2005 17:07 Jun 25, 2007 Jkt 211001 PO 00000 Frm 00013 Fmt 4703 Sfmt 4725 E:\FR\FM\26JNN1.SGM 26JNN1
35042 Federal Register / Vol. 72, No. 122 / Tuesday, June 26, 2007 / Notices

[FR Doc. 07–3114 Filed 6–25–07; 8:45 am] DEPARTMENT OF ENERGY SUMMARY: This notice announces a
BILLING CODE 5001–06–C meeting of the Fusion Energy Sciences
Office of Science; Fusion Energy Advisory Committee. The Federal
Sciences Advisory Committee Advisory Committee Act (Pub. L. 92–
jlentini on PROD1PC65 with NOTICES

463, 86 Stat. 770) requires that public


AGENCY: Department of Energy. notice of these meetings be announced
ACTION: Notice of open meeting. in the Federal Register.
EN26JN07.004</GPH>

VerDate Aug<31>2005 17:07 Jun 25, 2007 Jkt 211001 PO 00000 Frm 00014 Fmt 4703 Sfmt 4703 E:\FR\FM\26JNN1.SGM 26JNN1

Vous aimerez peut-être aussi