Updated: July 12, 2020 (December 9, 2002)

  Analyst Report

Windows 2000 Gains Common Criteria Certification

My Atlas / Analyst Reports

547 wordsTime to read: 3 min
Michael Cherry by
Michael Cherry

Michael analyzed and wrote about Microsoft's operating systems, including the Windows client OS, as well as compliance and governance. Michael... more

Microsoft has certified Windows 2000 against the ISO Common Criteria and will do the same with both Windows XP and Windows .NET Server, in a sign of the Windows division’s continuing focus on improving the security of its products. Windows 2000 with Service Pack 3 has been awarded Evaluation Assurance Level 4 (EAL4) for the Common Criteria (CC) version 2.1. These criteria are also known as the International Organisation for Standardisation (ISO) Evaluation Criteria for Information Technology Security (ISO 15408) and are the result of collaboration between national security and standards organizations from Canada, France, Germany, the Netherlands, the United Kingdom, and the United States. Customers should not read too much into such a certification, as applying the criteria against how a given organization specifically configures and administers Windows is not easy.

In the U.S., the supporting agencies are the National Institute for Standards and Technology and the National Security Agency, and the CC reflects criteria from both the Federal Criteria for Information Technology Security version 1.0 and the Trusted Computer System Evaluation Criteria (TCSEC or “Orange Book”). This rating for Windows 2000 Server is analogous to the C2 rating of Windows NT. A mutual recognition agreement commits the collaborating countries to recognize the certification of products against the CC as if the product has been evaluated against a collaborating country’s own standard.

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now