SlideShare ist ein Scribd-Unternehmen logo
1 von 38
Downloaden Sie, um offline zu lesen
 CC data collection with CCScraper
 CC statistics for 2020
 CC Statistics for 5 years
 Some historical CC statistics
 Conclusions
Contents
 Web scraper written in Python. Created in 2018 by jtsec.
 CCScraper collects data about certified products from commoncriteriaportal.org
and from the websites of the Certification Body.
 Tons of interesting data collected: date of certification, EAL, PP, Product
Category, certification lab, etc. and even SFRs used or technical terms in the ST!
 Data is interpreted and organized / merged into a list of unique certified
products. We generate the statistics from that data.
What is CCScraper
 CCScraper v1.0 was first presented here in the ICCC in 2018.
 Only data from commoncriteriaportal.org was collected.
 CCScraper v2.0 was presented in ICCC 2019.
 Main feature: add information from CB websites and merge into
unique products
 CCScraper v2.1 presented today in ICCC 2020.
 Efficiency dramatically improved: 18 hours vs 5 days of execution.
 Nothing is perfect… so we implemented logging and email alert logic in
case we find errors / uncontemplated cases.
CCScraper history
 New laboratories found!… we had to review our parsing logic and reports!
 CSEC website changed it structure during this year: we had to re-code its
scraper.
 NSCIB started to upload Site Security Certifications and dates were
removed from the product listing.
 The scraper run an OK test in September but… in November the Australian
CB ACSC website had entirely changed!
Latest challenges for CCScraper
 With the statistics generated, we publish CC statistics reports in jtsec
webpage, at least once per year.
CCscraper reports
 https://www.jtsec.es/blog-entry/25/common-criteria-
statistics-report-for-2018
 https://www.jtsec.es/blog-entry/44/common-criteria-
statistics-report-for-2019
Statistics – 2020 (10 months)
 315 products certified during 2020 (data from 05/11/2020)
 Top certifier schemes in 2020
Statistics – 2020 (10 months)
Statistics – 2020 (10 months)
 The top 3 schemes add up to 55% of the certifications!
 Certified products compliance in 2020
Statistics – 2020 (10 months)
 Product assurance level per country during 2020
Statistics – 2020 (10 months)
 Top 10 Laboratories (2020)
Statistics – 2020 (10 months)
Statistics – 2020 (10 months)
 Protection Profile certifications
Statistics – 2020 (10 months)
 PP and cPP compliant certifications in 2020
 Top 5 manufacturers of certified products (2020)
Statistics – 2020 (10 months)
 Top product categories (2020) and their evolution
Statistics – 2020 (10 months)
 Products uploaded to CC Portal vs products only in CB websites
Statistics – 2020 (10 months)
 Number of certifications
in the last 5 years
 Will 2020 be the worst
year of the last five?
Statistics – 5 years trend
 Compliance with EAL or PP of certified products (5 year)
Statistics – 5 years trend
 High vs Low assurance in five years
Statistics – 5 year trend
 Certifications per country scheme in the last 5 years
Statistics – 5 year trend
Statistics – 5 year trend
Top-certifier countries (6th to 10th)
 Evolution of top 5 laboratories
Statistics – 5 year trend
 Evolution of top product categories (five years)
Statistics – 5 year trend
 Product publication: commoncriteriaportal.org vs CBs sites
Statistics – 5 year trend
 Number of certifications per country, historical (archived included)
Statistics – Historical Trends
 Number of certifications per year
Statistics – Historical Trends
INITIAL GROWING
TRENDS (until 2007)
Stabilization
2008-2010
Sustained growth
2011-2016
Decay?
2017-2020
 Technological terms found in Security Targets
Statistics – Historical Trends
Conclusions for 2020
 PP compliant certifications and High-assurance certifications (EAL5+EAL4)
predominated. EAL5 slightly > than EAL5 in 2020.
 2020 brought new winners to the scene:
 A new top vendor
 A new top evaluation lab
 A new top certifying scheme in the top-3
 CPP_ND was the most used CPP; PP084 was the most used regular PP.
 ICs & Smartcards were the most certified category, followed by Network Devices.
Has the lockdown affected the industry?
 2020 currently has less certifications than 2016, 2017, 2018 an 2019. And
65 certifications below 2019.
 The top certifying schemes lowered their number of certifications, except
Netherlands.
 Most of the top certification laboratories certified significatively less
products in 2020.
Has the lockdown affected the industry?
 No noticeable variations between Q1, and Q2-Q3 of 2020 (when lockdown).
 Unfortunately, we don’t collect data about products under evaluation and:
 Usually the whole CC process until certification takes between 6 and 12 months.
 EAL4 and higher require a site audit, the lockdown possibly delayed them.
 We think that many evaluations were started in 2019: labs and certifiers tried not
to stop them due to lockdown and we saw numbers in 2020 related to those
certifications.
 In our opinion, the COVID could have delayed evaluations starting in 2020.
 Hence, we expect the same decreasing trend in 2021… with worst numbers?
jtsec: Beyond IT Security
Granada & Madrid – Spain
hello@jtsec.es
@jtsecES
www.jtsec.es
Contact
“Any fool can make something complicated. It takes a
genius to make it simple.”
Woody Guthrie

Weitere ähnliche Inhalte

Was ist angesagt?

Vicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guanVicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guanJuan C. Vasquez
 
[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT SuccessElectric Imp
 
Open Source IoT- Timm McShane
Open Source IoT- Timm McShaneOpen Source IoT- Timm McShane
Open Source IoT- Timm McShaneInman News
 
Developing Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz SaracevicDeveloping Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz SaracevicBosnia Agile
 
Fundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentFundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentMark Szewczul, CISSP
 
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...Bosnia Agile
 
InfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to workInfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to workInfostretch
 
IoT Developer Survey 2017
IoT Developer Survey 2017IoT Developer Survey 2017
IoT Developer Survey 2017Eclipse IoT
 
Digital Security by Design Vision
Digital Security by Design VisionDigital Security by Design Vision
Digital Security by Design VisionKTN
 
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...apidays
 
call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)ijassn
 
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsATMOSPHERE .
 
Integrators list brochure1
Integrators list brochure1Integrators list brochure1
Integrators list brochure1Jo Thorgen
 
Open source IoT
Open source IoTOpen source IoT
Open source IoTIoT613
 
Security Research Day Summary of Input
Security Research Day Summary of InputSecurity Research Day Summary of Input
Security Research Day Summary of InputIoTUK
 
IoT Developer Survey 2016
IoT Developer Survey 2016IoT Developer Survey 2016
IoT Developer Survey 2016Eclipse IoT
 
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsATMOSPHERE .
 

Was ist angesagt? (20)

Vicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guanVicinity glo tsummit yajuan guan
Vicinity glo tsummit yajuan guan
 
[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success[Webinar] Why Security Certification is Crucial for IoT Success
[Webinar] Why Security Certification is Crucial for IoT Success
 
Open Source IoT- Timm McShane
Open Source IoT- Timm McShaneOpen Source IoT- Timm McShane
Open Source IoT- Timm McShane
 
Developing Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz SaracevicDeveloping Enterprise-Level IoT Solutions by Fariz Saracevic
Developing Enterprise-Level IoT Solutions by Fariz Saracevic
 
Reliable Engineering for Insurance
Reliable Engineering for InsuranceReliable Engineering for Insurance
Reliable Engineering for Insurance
 
Fundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product DevelopmentFundamental Best Practices in Secure IoT Product Development
Fundamental Best Practices in Secure IoT Product Development
 
Quality 4.0 and reimagining quality
Quality 4.0 and reimagining qualityQuality 4.0 and reimagining quality
Quality 4.0 and reimagining quality
 
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
Connect, Secure & Automate the Distribution Grid with CISCO SCADA RTU - Eximp...
 
InfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to workInfoStretch & Peloton - Putting IoT to work
InfoStretch & Peloton - Putting IoT to work
 
IoT Developer Survey 2017
IoT Developer Survey 2017IoT Developer Survey 2017
IoT Developer Survey 2017
 
Digital Security by Design Vision
Digital Security by Design VisionDigital Security by Design Vision
Digital Security by Design Vision
 
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
apidays LIVE Paris 2021 - Evaluate and improve the footprint of digital servi...
 
Pitch Deck
Pitch DeckPitch Deck
Pitch Deck
 
call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)call for papers - International Conference on Networks & IOT (NeTIOT 2020)
call for papers - International Conference on Networks & IOT (NeTIOT 2020)
 
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
 
Integrators list brochure1
Integrators list brochure1Integrators list brochure1
Integrators list brochure1
 
Open source IoT
Open source IoTOpen source IoT
Open source IoT
 
Security Research Day Summary of Input
Security Research Day Summary of InputSecurity Research Day Summary of Input
Security Research Day Summary of Input
 
IoT Developer Survey 2016
IoT Developer Survey 2016IoT Developer Survey 2016
IoT Developer Survey 2016
 
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital MarketsSemantic Analytics: The accelerator of Artificial Intelligence Digital Markets
Semantic Analytics: The accelerator of Artificial Intelligence Digital Markets
 

Ähnlich wie 2020 Statistics Report. Is the industry surviving to lockdown?

2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...Javier Tallón
 
ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?Javier Tallón
 
ICCC21 2021 statistics report
ICCC21 2021 statistics reportICCC21 2021 statistics report
ICCC21 2021 statistics reportJavier Tallón
 
CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates Craig Willetts ISO Expert
 
Ip Action Plan
Ip Action PlanIp Action Plan
Ip Action Plangiri77
 
The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14Shane Coughlan
 
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization successISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization successHarold van Heeringen
 
ODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps ManifestoODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps ManifestoDataKitchen
 
Assocham global conference audit data standards - 28.10.2020
Assocham global conference   audit data standards - 28.10.2020Assocham global conference   audit data standards - 28.10.2020
Assocham global conference audit data standards - 28.10.2020Vinod Kashyap
 
The programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth WatsonThe programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth WatsonWorkiva
 
Smart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partnersSmart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partnersJohn Niz
 
Performance Measurement and Management in Industry 4.0
Performance Measurement and Management in Industry 4.0Performance Measurement and Management in Industry 4.0
Performance Measurement and Management in Industry 4.0CAREL Industries S.p.A
 
Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)Shuki Mann
 
Cross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data ConferenceCross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data ConferenceCharles Farina
 
IoT digital disruption and new IoT business models
IoT digital disruption and new IoT business modelsIoT digital disruption and new IoT business models
IoT digital disruption and new IoT business modelsIoTAnalytics
 

Ähnlich wie 2020 Statistics Report. Is the industry surviving to lockdown? (20)

2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...2022 CC Statistics report: will this year beat last year's record number of c...
2022 CC Statistics report: will this year beat last year's record number of c...
 
ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?ICCC2023 Statistics Report, has Common Criteria reached its peak?
ICCC2023 Statistics Report, has Common Criteria reached its peak?
 
ICCC21 2021 statistics report
ICCC21 2021 statistics reportICCC21 2021 statistics report
ICCC21 2021 statistics report
 
CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates CAW Newsletter Including ISO & Legislation Updates
CAW Newsletter Including ISO & Legislation Updates
 
Ip Action Plan
Ip Action PlanIp Action Plan
Ip Action Plan
 
The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14The State of Open Source for Software Alliance Germany 2023-04-14
The State of Open Source for Software Alliance Germany 2023-04-14
 
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization successISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
ISMA 9 - van Heeringen - Using IFPUG and ISBSG to improve organization success
 
ODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps ManifestoODSC May 2019 - The DataOps Manifesto
ODSC May 2019 - The DataOps Manifesto
 
2023-06-classic
2023-06-classic2023-06-classic
2023-06-classic
 
2023-06-cute
2023-06-cute2023-06-cute
2023-06-cute
 
Assocham global conference audit data standards - 28.10.2020
Assocham global conference   audit data standards - 28.10.2020Assocham global conference   audit data standards - 28.10.2020
Assocham global conference audit data standards - 28.10.2020
 
INGENIUS_XIMB_Iron and Steel
INGENIUS_XIMB_Iron and SteelINGENIUS_XIMB_Iron and Steel
INGENIUS_XIMB_Iron and Steel
 
2023-06-corporate
2023-06-corporate2023-06-corporate
2023-06-corporate
 
The programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth WatsonThe programmable RegTech Eco System by Liv Apneseth Watson
The programmable RegTech Eco System by Liv Apneseth Watson
 
Simmethod growth and value creation sales index
Simmethod growth and value creation sales indexSimmethod growth and value creation sales index
Simmethod growth and value creation sales index
 
Smart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partnersSmart Health Devices looking for distribution partners
Smart Health Devices looking for distribution partners
 
Performance Measurement and Management in Industry 4.0
Performance Measurement and Management in Industry 4.0Performance Measurement and Management in Industry 4.0
Performance Measurement and Management in Industry 4.0
 
Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)Charles Farina - Analytics Pros (All Things Data 2015)
Charles Farina - Analytics Pros (All Things Data 2015)
 
Cross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data ConferenceCross Device Measurement - All Things Data Conference
Cross Device Measurement - All Things Data Conference
 
IoT digital disruption and new IoT business models
IoT digital disruption and new IoT business modelsIoT digital disruption and new IoT business models
IoT digital disruption and new IoT business models
 

Mehr von Javier Tallón

Evolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio IIEvolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio IIJavier Tallón
 
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...Javier Tallón
 
ICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNJavier Tallón
 
Experiences evaluating cloud services and products
Experiences evaluating cloud services and productsExperiences evaluating cloud services and products
Experiences evaluating cloud services and productsJavier Tallón
 
TAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxTAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxJavier Tallón
 
La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...Javier Tallón
 
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfEUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfJavier Tallón
 
Evolucionado la evaluación Criptográfica
Evolucionado la evaluación CriptográficaEvolucionado la evaluación Criptográfica
Evolucionado la evaluación CriptográficaJavier Tallón
 
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...Javier Tallón
 
EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896Javier Tallón
 
EUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemesEUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemesJavier Tallón
 
EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045Javier Tallón
 
Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...Javier Tallón
 
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?Javier Tallón
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Javier Tallón
 
CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2Javier Tallón
 
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...Javier Tallón
 
Automating Common Criteria
Automating Common Criteria Automating Common Criteria
Automating Common Criteria Javier Tallón
 
CCCAB - Making CABs life easy
CCCAB -  Making CABs life easyCCCAB -  Making CABs life easy
CCCAB - Making CABs life easyJavier Tallón
 

Mehr von Javier Tallón (20)

Evolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio IIEvolucionando la evaluación criptográfica - Episodio II
Evolucionando la evaluación criptográfica - Episodio II
 
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
Cómo evaluar soluciones biométricas para incluir productos de videoidentifica...
 
ICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCNICCC23 -The new cryptographic evaluation methodology created by CCN
ICCC23 -The new cryptographic evaluation methodology created by CCN
 
Experiences evaluating cloud services and products
Experiences evaluating cloud services and productsExperiences evaluating cloud services and products
Experiences evaluating cloud services and products
 
TAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptxTAICS - Cybersecurity Certification for European Market.pptx
TAICS - Cybersecurity Certification for European Market.pptx
 
La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...La ventaja de implementar una solución de ciberseguridad certificada por el C...
La ventaja de implementar una solución de ciberseguridad certificada por el C...
 
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdfEUCA23 - Evolution of cryptographic evaluation in Europe.pdf
EUCA23 - Evolution of cryptographic evaluation in Europe.pdf
 
Hacking your jeta.pdf
Hacking your jeta.pdfHacking your jeta.pdf
Hacking your jeta.pdf
 
Evolucionado la evaluación Criptográfica
Evolucionado la evaluación CriptográficaEvolucionado la evaluación Criptográfica
Evolucionado la evaluación Criptográfica
 
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
España y CCN como referentes en la evaluación de ciberseguridad de soluciones...
 
EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896EUCA 22 - Let's harmonize labs competence ISO 19896
EUCA 22 - Let's harmonize labs competence ISO 19896
 
EUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemesEUCA22 Panel Discussion: Differences between lightweight certification schemes
EUCA22 Panel Discussion: Differences between lightweight certification schemes
 
EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045EUCA22 - Patch Management ISO_IEC 15408 & 18045
EUCA22 - Patch Management ISO_IEC 15408 & 18045
 
Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...Cross standard and scheme composition - A needed cornerstone for the European...
Cross standard and scheme composition - A needed cornerstone for the European...
 
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
¿Cómo incluir productos y servicios en el catálogo CPSTIC (CCN-STIC 105)?
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?
 
CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2CCCAB tool - Making CABs life easy - Chapter 2
CCCAB tool - Making CABs life easy - Chapter 2
 
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
CCCAB, la apuesta europea por la automatización de los Organismos de Certific...
 
Automating Common Criteria
Automating Common Criteria Automating Common Criteria
Automating Common Criteria
 
CCCAB - Making CABs life easy
CCCAB -  Making CABs life easyCCCAB -  Making CABs life easy
CCCAB - Making CABs life easy
 

Kürzlich hochgeladen

From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 

Kürzlich hochgeladen (20)

From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 

2020 Statistics Report. Is the industry surviving to lockdown?

  • 1.
  • 2.
  • 3.  CC data collection with CCScraper  CC statistics for 2020  CC Statistics for 5 years  Some historical CC statistics  Conclusions Contents
  • 4.
  • 5.  Web scraper written in Python. Created in 2018 by jtsec.  CCScraper collects data about certified products from commoncriteriaportal.org and from the websites of the Certification Body.  Tons of interesting data collected: date of certification, EAL, PP, Product Category, certification lab, etc. and even SFRs used or technical terms in the ST!  Data is interpreted and organized / merged into a list of unique certified products. We generate the statistics from that data. What is CCScraper
  • 6.  CCScraper v1.0 was first presented here in the ICCC in 2018.  Only data from commoncriteriaportal.org was collected.  CCScraper v2.0 was presented in ICCC 2019.  Main feature: add information from CB websites and merge into unique products  CCScraper v2.1 presented today in ICCC 2020.  Efficiency dramatically improved: 18 hours vs 5 days of execution.  Nothing is perfect… so we implemented logging and email alert logic in case we find errors / uncontemplated cases. CCScraper history
  • 7.  New laboratories found!… we had to review our parsing logic and reports!  CSEC website changed it structure during this year: we had to re-code its scraper.  NSCIB started to upload Site Security Certifications and dates were removed from the product listing.  The scraper run an OK test in September but… in November the Australian CB ACSC website had entirely changed! Latest challenges for CCScraper
  • 8.  With the statistics generated, we publish CC statistics reports in jtsec webpage, at least once per year. CCscraper reports  https://www.jtsec.es/blog-entry/25/common-criteria- statistics-report-for-2018  https://www.jtsec.es/blog-entry/44/common-criteria- statistics-report-for-2019
  • 9.
  • 10. Statistics – 2020 (10 months)  315 products certified during 2020 (data from 05/11/2020)
  • 11.  Top certifier schemes in 2020 Statistics – 2020 (10 months)
  • 12. Statistics – 2020 (10 months)  The top 3 schemes add up to 55% of the certifications!
  • 13.  Certified products compliance in 2020 Statistics – 2020 (10 months)
  • 14.  Product assurance level per country during 2020 Statistics – 2020 (10 months)
  • 15.  Top 10 Laboratories (2020) Statistics – 2020 (10 months)
  • 16. Statistics – 2020 (10 months)  Protection Profile certifications
  • 17. Statistics – 2020 (10 months)  PP and cPP compliant certifications in 2020
  • 18.  Top 5 manufacturers of certified products (2020) Statistics – 2020 (10 months)
  • 19.  Top product categories (2020) and their evolution Statistics – 2020 (10 months)
  • 20.  Products uploaded to CC Portal vs products only in CB websites Statistics – 2020 (10 months)
  • 21.
  • 22.  Number of certifications in the last 5 years  Will 2020 be the worst year of the last five? Statistics – 5 years trend
  • 23.  Compliance with EAL or PP of certified products (5 year) Statistics – 5 years trend
  • 24.  High vs Low assurance in five years Statistics – 5 year trend
  • 25.  Certifications per country scheme in the last 5 years Statistics – 5 year trend
  • 26. Statistics – 5 year trend Top-certifier countries (6th to 10th)
  • 27.  Evolution of top 5 laboratories Statistics – 5 year trend
  • 28.  Evolution of top product categories (five years) Statistics – 5 year trend
  • 29.  Product publication: commoncriteriaportal.org vs CBs sites Statistics – 5 year trend
  • 30.
  • 31.  Number of certifications per country, historical (archived included) Statistics – Historical Trends
  • 32.  Number of certifications per year Statistics – Historical Trends INITIAL GROWING TRENDS (until 2007) Stabilization 2008-2010 Sustained growth 2011-2016 Decay? 2017-2020
  • 33.  Technological terms found in Security Targets Statistics – Historical Trends
  • 34.
  • 35. Conclusions for 2020  PP compliant certifications and High-assurance certifications (EAL5+EAL4) predominated. EAL5 slightly > than EAL5 in 2020.  2020 brought new winners to the scene:  A new top vendor  A new top evaluation lab  A new top certifying scheme in the top-3  CPP_ND was the most used CPP; PP084 was the most used regular PP.  ICs & Smartcards were the most certified category, followed by Network Devices.
  • 36. Has the lockdown affected the industry?  2020 currently has less certifications than 2016, 2017, 2018 an 2019. And 65 certifications below 2019.  The top certifying schemes lowered their number of certifications, except Netherlands.  Most of the top certification laboratories certified significatively less products in 2020.
  • 37. Has the lockdown affected the industry?  No noticeable variations between Q1, and Q2-Q3 of 2020 (when lockdown).  Unfortunately, we don’t collect data about products under evaluation and:  Usually the whole CC process until certification takes between 6 and 12 months.  EAL4 and higher require a site audit, the lockdown possibly delayed them.  We think that many evaluations were started in 2019: labs and certifiers tried not to stop them due to lockdown and we saw numbers in 2020 related to those certifications.  In our opinion, the COVID could have delayed evaluations starting in 2020.  Hence, we expect the same decreasing trend in 2021… with worst numbers?
  • 38. jtsec: Beyond IT Security Granada & Madrid – Spain hello@jtsec.es @jtsecES www.jtsec.es Contact “Any fool can make something complicated. It takes a genius to make it simple.” Woody Guthrie