
| Version | Date | Comment |
|---|---|---|
| 1.0 | 2000-08-08 | Initial Version |
| 1.1 | 2007-07-25 | Update to conform with CC V3.1 |
| 1.2 | 2008-08-21 | Update to conform with additional parts of CC V3.1 r3 |
| 2.0 | 2010-06-01 | Updates to assumptions, threats, and objectives |
| 2.1 | 2010-09-07 | Update to replace ROM requirement |
| 3.0 | 2015-02-13 | Update to conform with CC V3.1 r4 and substantial additional functionality |
| 4.0 | 2019-07-19 | Update to conform with CC V3.1 r5 and includes separation of security functionality into base Protection Profile and Protection Profile Modules based on interface type |
| 5.0 | 2025-07-11 | First draft of version 1.0 for comment |
Assurance | Grounds for confidence that a TOE meets the SFRs [CC]. |
Base Protection Profile (Base-PP) | Protection Profile used as a basis to build a PP-Configuration. |
Collaborative Protection Profile (cPP) | A Protection Profile developed by international technical communities and approved by multiple schemes. |
Common Criteria (CC) | Common Criteria for Information Technology Security Evaluation (International Standard ISO/IEC 15408). |
Common Criteria Testing Laboratory | Within the context of the Common Criteria Evaluation and Validation Scheme (CCEVS), an IT security evaluation facility accredited by the National Voluntary Laboratory Accreditation Program (NVLAP) and approved by the NIAP Validation Body to conduct Common Criteria-based evaluations. |
Common Evaluation Methodology (CEM) | Common Evaluation Methodology for Information Technology Security Evaluation. |
Direct Rationale | A type of Protection Profile, PP-Module, or Security Target in which the security problem definition (SPD) elements are mapped directly to the SFRs and possibly to the security objectives for the operational environment. There are no security objectives for the TOE. |
Distributed TOE | A TOE composed of multiple components operating as a logical whole. |
Extended Package (EP) | A deprecated document form for collecting SFRs that implement a particular protocol, technology, or functionality. See Functional Packages. |
Functional Package (FP) | A document that collects SFRs for a particular protocol, technology, or functionality. |
Operational Environment (OE) | Hardware and software that are outside the TOE boundary that support the TOE functionality and security policy. |
Protection Profile (PP) | An implementation-independent set of security requirements for a category of products. |
Protection Profile Configuration (PP-Configuration) | A comprehensive set of security requirements for a product type that consists of at least one Base-PP and at least one PP-Module. |
Protection Profile Module (PP-Module) | An implementation-independent statement of security needs for a TOE type complementary to one or more Base-PPs. |
Security Assurance Requirement (SAR) | A requirement to assure the security of the TOE. |
Security Functional Requirement (SFR) | A requirement for security enforcement by the TOE. |
Security Target (ST) | A set of implementation-dependent security requirements for a specific product. |
Target of Evaluation (TOE) | The product under evaluation. |
TOE Security Functionality (TSF) | The security functionality of the product under evaluation. |
TOE Summary Specification (TSS) | A description of how a TOE satisfies the SFRs in an ST. |
Active Interface and Connection | An interface between a PSD and device that currently has user data flowing through it. |
Administrator | A person who administers (e.g., installs, configures, updates, audits, maintains) a PSD, connected peripherals, and connections. |
Authorized Peripheral | A peripheral device that is both technically supported and administratively permitted to have an active interface with the PSD. |
Combiner (multi-viewer) | A PSD with video integration functionality. Used to simultaneously display output from multiple personal computers (PCs). |
Computer Interface | The PSD's physical receptacle or port for connecting to a computer. |
Configurable Device Filtration (CDF) | A PSD function that filters traffic based on properties of a connected peripheral device and criteria that are configurable by an Administrator. |
Connected Computer | A computing device connected to a PSD. May be a personal computer, server, tablet, or any other computing device. |
Connected Peripheral | A peripheral that is connected to a PSD. |
Connection | A physical or logical conduit that enables devices to interact through respective interfaces. May consist of one or more physical (e.g., a cable) or logical (e.g., a protocol) components. |
Connector | The plug on a connection that attaches to a computer or peripheral interface. |
Device | An information technology product. In the context of this PP, a device is a PSD, a connected computer, or a connected peripheral. |
Display | A device that visually outputs user data, such as a monitor |
Guard | A PSD function that requires multiple express user actions in order to switch between connected computers using connected peripherals. |
Interface | A shared boundary across which two or more devices exchange information through a Connection. |
Isolator or Filter | A PSD with a single connected computer. |
Keyboard, Mouse (KM) | A type of PSD that shares a keyboard and pointing device between connected computers. A KM may optionally include an analog audio device. |
Keyboard, Video, Mouse (KVM) | A type of PSD that shares a keyboard, video, and pointing device between connected computers. A KVM may optionally include an analog audio device and user authentication device. |
Letter of Volatility | A letter issued by the manufacturer outlining whether on-board memory can store data when the device is powered off (non‐volatile) or not (volatile). |
Monitoring | The ability of a user to receive an indicator of the current active interface. |
Non-Selected Computer | A connected computer that has no active interfaces with the PSD. |
Peripheral Interface | The PSD's physical receptacle or port for connecting to a peripheral device. |
Peripheral or Peripheral Device | A device with access that can be shared or filtered by a PSD. |
Remote Controller | Remote component of the PSD that extends the controls and indications through a cable. |
Secure State | An operating condition in which the PSD disables all connected peripheral and connected computer interfaces when the correctness of its functions cannot be ensured. |
Selected Computer | A connected computer that has active interfaces with the PSD. |
Supported Peripheral | A peripheral device that is technically supported by the PSD |
Touch Screen | A pointing peripheral device that enable users to touch one or more objects on the screen or to point the cursor device to specific locations. |
User | A person that interacts with a PSD (or a process or mechanism acting on behalf of a person). |
User Authentication Device | A peripheral device that is used to affirm the identity of a user attempting to authenticate to a computer (e.g., smart card reader, biometric authentication device, proximity card reader). |
User Data | Information that the user inputs to the connected computer or is output to the user from the connected computer (and including user authentication and credential information) |
Video Wall | A tiled set of displays that allow the video output from a single selected computer to be spanned across multiple individual displays. |




If this feature is implemented by the TOE, the following requirements must be claimed in the ST:
If this feature is implemented by the TOE, the following requirements must be claimed in the ST:
| Assumption or OSP | Security Objectives | Rationale |
| A.NO_TEMPEST | OE.NO_TEMPEST | If the TOE’s operational environment does not include TEMPEST approved equipment, then the assumption is satisfied. |
| A.NO_WIRELESS_DEVICES | OE.NO_WIRELESS_DEVICES | If the TOE’s operational environment does not include wireless peripherals, then the assumption is satisfied. |
| A.PHYSICAL | OE.PHYSICAL | If the TOE’s operational environment provides physical security, then the assumption is satisfied. |
| A.TRUSTED_ADMIN | OE.TRUSTED_ADMIN | If the TOE’s operational environment ensures that only trusted administrators will manage the TSF, then the assumption is satisfied. |
| A.TRUSTED_CONFIG | OE.TRUSTED_CONFIG | If TOE administrators follow the provided security configuration guidance, then the assumption is satisfied. |
| A.USER_ALLOWED_ACCESS | OE.PHYSICAL | If the TOE’s operational environment provides physical access to connected computers, then the assumption is satisfied. |
| Requirement | Auditable Events | Additional Audit Record Contents |
|---|---|---|
| FDP_APC_EXT.1 | ||
| No events specified | N/A | |
| FDP_PDC_EXT.1 | ||
| Self-test failures | None | |
| FDP_RIP_EXT.1 | ||
| No events specified | N/A | |
| FDP_SWI_EXT.1 | ||
| No events specified | N/A | |
| FPT_FLS_EXT.1 | ||
| No events specified | N/A | |
| FPT_NTA_EXT.1 | ||
| No events specified | N/A | |
| FPT_PHP.1 | ||
| Detection of intrusion. | None | |
| FPT_TST.1 | ||
| Execution of the TSF self-tests | Results of the tests | |
| FPT_TST_EXT.1 | ||
| Execution of self-tests. | None. |
The following rationale provides justification for each SFR for the TOE,
showing that the SFRs are suitable to address the specified threats:
| Threat | Addressed by | Rationale |
|---|---|---|
| T.DATA_LEAK | FDP_APC_EXT.1 | Mitigates this SFR by preventing unauthorized data flow. |
| FDP_PDC_EXT.1 | Mitigates this SFR by rejecting connection with unauthorized devices, including external and wireless interfaces. | |
| T.FAILED | FPT_FLS_EXT.1 | Mitigates this SFR by preserving a secure state during failures. |
| FPT_TST.1 | Mitigates this SFR by running self-tests to verify integrity. | |
| FPT_TST_EXT.1 | Mitigates this SFR by providing indication of a failure and shutting down normal functions. | |
| T.LOGICAL_TAMPER | FPT_NTA_EXT.1 | Mitigates this SFR by preventing access to firmware, software, and memory except under specified exceptions. |
| T.PHYSICAL_TAMPER | FPT_PHP.1 | Mitigates this SFR by requiring detection of physical tampering. |
| FPT_PHP.3 (implementation-dependent) | Mitigates this SFR by permanently disabling during a physical attack. | |
| T.REPLACEMENT | FPT_PHP.1 | Mitigates this SFR by ensuring physical tampering does not occur. |
| T.RESIDUAL_LEAK | FDP_RIP_EXT.1 | Mitigates this SFR by ensuring not data is transferred to non-volatile memory or storage. |
| FDP_RIP_EXT.2 (implementation-dependent) | Mitigates this SFR by ensuring there is a purge memory to restore to the factory default functions. | |
| T.SIGNAL_LEAK | FDP_APC_EXT.1 | Mitigates this SFR by ensuring data is only transferred to user-selected interfaces. |
| FDP_PDC_EXT.1 | Mitigates this SFR by rejecting unauthorized connections. | |
| FDP_SWI_EXT.1 | Mitigates this SFR by ensuring there is only one connected computer unless a switch is authorized by user action. | |
| FDP_SWI_EXT.2 (selection-based) | Mitigates this SFR by ensuring only authorized users are able to initiate a switch. | |
| T.UNAUTHORIZED_DEVICES | FDP_PDC_EXT.1 | Mitigates this SFR by rejecting connections with unauthorized devices. |
| T.UNINTENDED_USE | FDP_SWI_EXT.1 | Mitigates this SFR by ensuring there is only one connected computer unless a switch is authorized by user action. |
| FDP_SWI_EXT.2 (selection-based) | Mitigates this SFR by ensuring only authorized users are able to initiate a switch. | |
| FTA_CIN_EXT.1 (selection-based) | Mitigates this SFR by requiring a visible indicator or the connection status. | |
| FAU_GEN.1 (implementation-dependent) | Mitigates this SFR by requiring the collection of audit data and peripheral device acceptance and rejection. | |
| FIA_UAU.2 (implementation-dependent) | Mitigates this SFR by requiring administrator-authentication. | |
| FIA_UID.2 (implementation-dependent) | Mitigates this SFR by requiring administrator-identification. | |
| FMT_MOF.1 (implementation-dependent) | Mitigates this SFR by restricting behavior modification of specified instructions to only the authorized administrator. | |
| FMT_SMF.1 (implementation-dependent) | Mitigates this SFR by requiring a list of management functions for the TSF. | |
| FMT_SMR.1 (implementation-dependent) | Mitigates this SFR by maintaining and associating roles, including administrators and users. | |
| FPT_STM.1 (implementation-dependent) | Mitigates this SFR by requiring reliable time stamp use. |
| Assurance Class | Assurance Components |
| Security Target (ST) (ASE) |
Conformance Claims (ASE_CCL.1) Extended Components Definition (ASE_ECD.1) ST Introduction (ASE_INT.1) Security Objectives (ASE_OBJ.2) Derived Security Requirements (ASE_REQ.2) Security Problem Definition (ASE_SPD.1) TOE Summary Specification (ASE_TSS.1) |
| Development (ADV) | Basic Functional Specification (ADV_FSP.1) |
| Guidance Documents (AGD) | Operational User Guidance (AGD_OPE.1) Preparative Procedures (AGD_PRE.1) |
| Life-Cycle Support (ALC) | Labeling of the TOE (ALC_CMC.1) TOE CM Coverage (ALC_CMS.1) |
| Tests (ATE) | Independent Testing - Conformance (ATE_IND.1) |
| Vulnerability Assessment (AVA) | Vulnerability Survey (AVA_VAN.1) |
This PP does not define any Objective requirements.
| Requirement | Auditable Events | Additional Audit Record Contents |
|---|---|---|
| FAU_GEN.1 | ||
| No events specified | N/A | |
| FDP_RIP_EXT.2 | ||
| No events specified | N/A | |
| FIA_UAU.2 | ||
| Use of the authentication mechanism | None | |
| FIA_UID.2 | ||
| Use of the user identification mechanism | None | |
| FMT_MOF.1 | ||
| Modifications in the behaviour of functions | None | |
| FMT_SMF.1 | ||
| Use of management functions | None | |
| FMT_SMR.1 | ||
| Modifications to the group of users | None | |
| Unsuccessful attempts to use a role | Due to the given conditions on the roles | |
| FPT_PHP.3 | ||
| No events specified | N/A | |
| FPT_STM.1 | ||
| Changes to the time | None |
As indicated in the introduction to this PP, the baseline requirements (those that must be performed by the TOE or its underlying platform) are contained in the body of this PP. There are additional requirements based on selections in the body of the PP: if certain selections are made, then additional requirements below must be included.
| Requirement | Auditable Events | Additional Audit Record Contents |
|---|---|---|
| FDP_SWI_EXT.2 | ||
| No events specified | N/A | |
| FTA_CIN_EXT.1 | ||
| No events specified | N/A |
| Functional Class | Functional Components |
|---|---|
| Class FDP: User Data Protection | FDP_APC_EXT Active PSD Connections FDP_PDC_EXT Peripheral Device Connection FDP_RIP_EXT Residual Information Protection FDP_SWI_EXT PSD Switching |
| Class FPT: Protection of the TSF | FPT_FLS_EXT Failure with Preservation of Secure State FPT_NTA_EXT No Access to TOE FPT_TST_EXT TSF Testing |
| Class FTA: TOE Access | FTA_CIN_EXT Continuous Indications |
FDP_APC_EXT.1, Active PSD Connections, restricts the flow of data through the TSF.
No specific management functions are identified.
There are no auditable events foreseen.
| Hierarchical to: | No other components. |
| Dependencies to: | No dependencies |
FDP_PDC_EXT.1, Peripheral Device Connection, requires the TSF to limit external connections to only authorized devices.
No specific management functions are identified.
The following actions should be auditable if FAU_GEN.1 Audit Data Generation is included in the PP/ST:
| Hierarchical to: | No other components. |
| Dependencies to: | No dependencies |
FDP_RIP_EXT.1, Residual Information Protection, requires the TSF to prevent the writing of user data to non‐volatile memory.
FDP_RIP_EXT.2, Purge of Residual Information, requires the TSF to have a purge function to clear its memory of all stored non‐audit data.
The following actions could be considered for the management functions in FMT:
There are no auditable events foreseen.
| Hierarchical to: | No other components. |
| Dependencies to: | No dependencies |
The following actions could be considered for the management functions in FMT:
The following actions should be auditable if FAU_GEN.1 Audit Data Generation is included in the PP/ST:
FDP_SWI_EXT.1, PSD Switching, requires action on the part of a user in order for the TSF’s switching mechanisms to be activated.
FDP_SWI_EXT.2, PSD Switching Methods, places restrictions on how the TSF’s switching mechanisms can be controlled.
No specific management functions are identified.
There are no auditable events foreseen.
| Hierarchical to: | No other components. |
| Dependencies to: | No dependencies |
No specific management functions are identified.
There are no auditable events foreseen.
| Hierarchical to: | No other components. |
| Dependencies to: | FDP_SWI_EXT.1 PSD Switching |
FPT_FLS_EXT.1, Failure with Preservation of Secure State, requires the TSF to go into a secure state upon the detection of selected failures.
No specific management functions are identified.
There are no auditable events foreseen.
| Hierarchical to: | No other components. |
| Dependencies to: |
FPT_TST.1 TSF Testing FPT_PHP.3 Resistance to Physical Attack |
FPT_NTA_EXT.1, No Access to TOE, requires the TSF to block access to non‐authorized TSF data via external ports.
No specific management functions are identified.
There are no auditable events foreseen.
| Hierarchical to: | No other components. |
| Dependencies to: | No dependencies |
FPT_TST_EXT.1, TSF Testing, requires the TSF to shutdown normal functions and provide a visual or auditory indication that a self‐test has failed.
No specific management functions are identified.
The following actions should be auditable if FAU_GEN.1 Audit Data Generation is included in the PP/ST:
FTA_CIN_EXT.1, Continuous Indications, requires the TSF to display a visual indication of what computers are selected.
No specific management functions are identified.
There are no auditable events foreseen.
| Hierarchical to: | No other components. |
| Dependencies to: | FDP_APC_EXT.1 Active PSD Connections |
| Acronym | Meaning |
|---|---|
| Base-PP | Base Protection Profile |
| CC | Common Criteria |
| CDF | Configurable Device Filtration |
| CEM | Common Evaluation Methodology |
| CMC | Certificate Management over CMS |
| CMS | Cryptographic Message Syntax |
| cPP | Collaborative Protection Profile |
| EP | Extended Package |
| FP | Functional Package |
| KM | Keyboard, Mouse |
| KVM | Keyboard, Video, Mouse |
| OE | Operational Environment |
| PP | Protection Profile |
| PP-Configuration | Protection Profile Configuration |
| PP-Module | Protection Profile Module |
| SAR | Security Assurance Requirement |
| SFR | Security Functional Requirement |
| ST | Security Target |
| TOE | Target of Evaluation |
| TSF | TOE Security Functionality |
| TSFI | TSF Interface |
| TSS | TOE Summary Specification |
| USB | Universal Serial Bus |
| Identifier | Title |
|---|---|
| [CC] | Common Criteria for Information Technology Security Evaluation -
|
| [CEM] | Common Methodology for Information Technology Security Evaluation -
|
| [CESG] | CESG - End User Devices Security and Configuration Guidance |
| [CSA] | Computer Security Act of 1987, H.R. 145, June 11, 1987. |
| [OMB] | Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology Investments, OMB M-06-19, July 12, 2006. |