AMC3

Automated

Methodology for Common Criteria Certification

Duration of the project

01/02/2024 – 31/07/2027

Key words

cybersecurity, certification

Budget

1 673 000 €


AMC3’s goals

Developing a structured andautomated/agile approach that takes into account software updates and applying it to the Belgian Defence sector


Modernise

To modernise Defence cybersecurity certification processes.

Automate

To automate the process and drastically decrease human load.

AMC3 : A new project of the Defence-related Research Action – DEFRA

Belgian Defence is increasingly relying on software, both in terms of pure software applications as well as in the form of cyber-physical systems.

When this software suffers from defects, vulnerabilities and weaknesses, attackers might exploit its inherent vulnerabilities and tamper with mission critical systems or exfiltrate sensitive information. In order to mitigate this risk and ensure that software is dependable and trustworthy, certification and accreditation activities have traditionally been integrated into the software lifecycle. Software assurance through certification and accreditation suffers from the fact that these processes are extremely resource and time consuming. A structured and to a large extent automated/agile approach that takes into account software updates must therefore be developed. The ARCOS initiative shows that US Defence is rapidly evolving towards higher levels of cybersecurity maturity, which implies a more thorough assessment of all the software and systems that are approved to operate inside one of the classified or unclassified networks within military organisations.


AMC3’s Partners

1 coordinator & 3 partners

Pôle en ingénierie informatique

Axel Legay

Coordinator
Business Research Alignment

Philippe Massonnet

Partner
Communication Information Systems and Sensors (CISS)

Mees Wim

Partner
FN Herstal Business Development
Yves Roska
Partner

AMC3’s researchers

A growing community of researchers

Axel Legay

UCLOUVAIN

Philippe Massonnet

CETIC

Mees Wim

RMA

Yves Roska

FN HERSTAL

Annie Todd

Creative Director

Rebecca Martinez

Creative Director

Maud Rogers

Creative Director

Mason Wilson

Creative Director

Step by step

AMC3 will be divided into three phases that cover all the issues related to automatic certification

methodology

Development of a methodology for automatic certification accompanied by adequate efficient validation techniques

incrementality

Consideration of incrementality and updating to identify new requirements and evidence to be produced

runtime certification monitoring

Automating runtime certification monitoring, and technical/cost analysis.

AMC3’s calendar

Laisser un commentaire

Votre adresse de messagerie ne sera pas publiée. Les champs obligatoires sont indiqués avec *