CONTENTS
1
INTRODUCTION ...................................................................................4
2
OVERVIEW...........................................................................................6
2.1 Cybersecurity Labeling Scheme (CLS) ...............................................6
3
3.1
3.2
3.3
3.4
ASSESSMENT TIER #1 – SECURITY BASELINE REQUIREMENTS ......6
Objective ..........................................................................................6
Requirements ...................................................................................6
Declaration of Conformance...............................................................7
Acceptance Criteria ...........................................................................7
4
ASSESSMENT TIER #2 – LIFECYCLE REQUIREMENTS ......................8
4.1 Objective ..........................................................................................8
4.2 Requirements ...................................................................................8
4.3 Declaration of Conformance...............................................................8
4.4 Acceptance Criteria ...........................................................................8
5
ASSESSMENT TIER #3 – SOFTWARE BINARY ANALYSIS ................. 10
5.1 Objective ........................................................................................ 10
5.2 Requirements ................................................................................. 10
5.3 Process .......................................................................................... 10
5.4 Scope............................................................................................. 11
5.5 Pass Criteria ................................................................................... 13
5.6 Testing Laboratory Deliverables ....................................................... 13
6
6.1
6.2
6.3
6.4
6.5
ASSESSMENT TIER #4 – BLACK BOX PENETRATION TESTING ....... 15
Objective ........................................................................................ 15
Pre-requisites.................................................................................. 15
Scope............................................................................................. 15
Pass Criteria ................................................................................... 18
Deliverables .................................................................................... 18
7
CONFORMANCE CHECKLIST ............................................................ 20
8
REFERENCES.................................................................................... 49
9
ACRONYMS ....................................................................................... 49
NOTICE
The Cyber Security Agency of Singapore makes no warranty of any kind with
regard to this material and shall not be liable for errors contained herein or
for incidental or consequential damages in connection with the use of this
material.
CLS Publication #2 | Page 3 of 49