CONTENTS 1 INTRODUCTION ...................................................................................4 2 OVERVIEW...........................................................................................6 2.1 Cybersecurity Labeling Scheme (CLS) ...............................................6 3 3.1 3.2 3.3 3.4 ASSESSMENT TIER #1 – SECURITY BASELINE REQUIREMENTS ......6 Objective ..........................................................................................6 Requirements ...................................................................................6 Declaration of Conformance...............................................................7 Acceptance Criteria ...........................................................................7 4 ASSESSMENT TIER #2 – LIFECYCLE REQUIREMENTS ......................8 4.1 Objective ..........................................................................................8 4.2 Requirements ...................................................................................8 4.3 Declaration of Conformance...............................................................8 4.4 Acceptance Criteria ...........................................................................8 5 ASSESSMENT TIER #3 – SOFTWARE BINARY ANALYSIS ................. 10 5.1 Objective ........................................................................................ 10 5.2 Requirements ................................................................................. 10 5.3 Process .......................................................................................... 10 5.4 Scope............................................................................................. 11 5.5 Pass Criteria ................................................................................... 13 5.6 Testing Laboratory Deliverables ....................................................... 13 6 6.1 6.2 6.3 6.4 6.5 ASSESSMENT TIER #4 – BLACK BOX PENETRATION TESTING ....... 15 Objective ........................................................................................ 15 Pre-requisites.................................................................................. 15 Scope............................................................................................. 15 Pass Criteria ................................................................................... 18 Deliverables .................................................................................... 18 7 CONFORMANCE CHECKLIST ............................................................ 20 8 REFERENCES.................................................................................... 49 9 ACRONYMS ....................................................................................... 49 NOTICE The Cyber Security Agency of Singapore makes no warranty of any kind with regard to this material and shall not be liable for errors contained herein or for incidental or consequential damages in connection with the use of this material. CLS Publication #2 | Page 3 of 49

Select target paragraph3