detailed setup and procedure such that the results could be
reproduced.
4. Results on the search for potential vulnerabilities in the public domain,
including the list of search terms.
5. Test cases and results of the penetration testing. The test cases could
be described in high level. Recording of detailed setup and procedures
are required only for test cases which succeeded in exploiting the DUT.
6.5.2 The testing laboratory shall also arrange for a meeting with CCC to present
the results.
6.5.3 The testing laboratory may be required to perform additional testing if CCC
deems the testing performed to be inadequate.
6.5.4 During the course of testing, if the testing laboratory discovers any
discrepancies or false declarations in the developer’s declaration of
conformance to the Security Baseline Requirements or Lifecycle
requirements, the testing laboratory is to provide the information to CCC,
CCC reserves the full rights to enforce actions as described in Chapter 8.7
of CLS Publication #1 – Overview of the Scheme [3].
CLS Publication #2 | Page 19 of 49