Protection Profile

A Protection Profile (PP) is a document used as part of the certification process according to ISO/IEC 15408 and the Common Criteria (CC).

A PP specifies generic security evaluation criteria to substantiate vendors' claims of a given family of information system products.

Among others, it typically specifies the Evaluation Assurance Level (EAL), a number 1 through 7, indicating the depth and rigor of the security evaluation, usually in the form of supporting documentation and testing, that a product meets the security requirements specified in the PP.

Although the EAL is easiest for laymen to compare, its simplicity is deceptive because this number is rather meaningless without an understanding the security implications of the PP(s) and ST used for the evaluation.

Loss of this application technology seems to have been an unintended consequence of the superseding of the Orange Book by the Common Criteria.