Common Criteria Compliance

SQL Server 2005 SP2 includes a new, advanced configuration option called Common Criteria Compliance enabled. Government, military, financial, and other entities with serious security needs may require Common Criteria certification and implementation. Although Common Criteria superseded C2 in the security world, it doesn’t subsume all the C2 audit-mode–option functionality. Common Criteria Compliance includes the following features:

  • Residual Information Protection (RIP.2) implementation
  • login statistics displayed in sys.dm_exec_sessions dynamic management view
  • Table DENY to override column GRANT

 Microsoft formally submitted SQL Server 2005 for Common Criteria certification in January 2006. SQL Server 2005 SP1 was evaluated against the Common Criteria evaluation assurance level 1 (EAL1). SQL Server 2005 SP2 is currently being evaluated against the Common Criteria evaluation assurance level 4 (EAL4+) in Germany by Bundesamt für Sicherheit in der Informationstechnik (BSI)—the German government's Federal Office for Information Security. You can find the official posting on the BSI Web site (www.bsi.bund.de/english/index.htm). For more information about these evaluations and how to enable compliance for SQL Server 2005, see the Microsoft SQL Server Common Criteria Web site at technet.microsoft.com/en-us/library/bb153837.aspx.

Please or Register to post comments.

IT/Dev Connections

Las Vegas
September 30th - October 4th

Paul ThurottOur Experts will show you:
• Common SQL Server
Problems
• Best Practices for T-SQL
• SQL Server Integration
Services
• Database Development

Come See Michael Otey & Tim Ford in Person!

Early Registration Now Open

From the Blogs
May 21, 2013
blog

A Common Misconception about MAXDOP

Out of the box, SQL Server is (and has been) able to take advantage of multiple processors/cores without any effort on behalf of administrators....More
May 9, 2013
blog

My ISO 8601-Compliant Signature 2

My family recently just "officially" announced that we're in the process of adopting a child from South Africa. We're quite excited, of course, but there's a ton of paperwork to do—along with the need for gobs of signatures....More
May 8, 2013
blog

Use SSIS for ETL from Hadoop

In this blog post, Mark Kromer walks you through using SSIS as a way to use ETL techniques using Microsoft's Hadoop on Windows (HDInsight) as a source using Hive connectors...More
SQL Server Pro Forums

Get answers to questions, share tips, and engage with the SQL Server community in our Forums.