Standards and Publications
Much of cybersecurity is shaped long before a product enters an evaluation lab or a regulation takes effect. It happens in the standards, frameworks and technical guidance that define what security means in practice.
Over the course of my career, I've helped develop that foundation — leading industry and government technical communities, authoring guidance, and contributing to standards and Protection Profiles used in security evaluation and certification.
The work below represents some of those efforts.
STANDARDS LEADERSHIP
Common Criteria in the Cloud
Common Criteria was written for products you ship in a box, not services you operate and update continuously. This work addresses what happens when you try to apply it to cloud-delivered software: where the evaluation boundary sits, how continuous updates are handled, and what "the evaluated configuration" means when it changes every week.
Common Criteria in the Cloud –Chair and lead author
Enterprise Security Management Protection Profiles
I founded and chaired the Enterprise Security Management Technical Community, which brought together vendors, government representatives, laboratories and other stakeholders to develop a family of Protection Profiles for enterprise security management products.
A Protection Profile defines the security requirements an entire class of product can be evaluated against the Common Criteria. The ESM community developed profiles covering technologies organizations use to manage access, security policy, identity and credentials.
STANDARDS CONTRIBUTIONS
collaborative Protection Profile for Database Management Systems
A collaborative Protection Profile is written by an international technical community rather than a single national scheme, so that one evaluation is recognized across all of them. This one covers database management systems. I was a contributor to the project.
Open Trusted Technology Provider™ Standard (O-TTPS)
Addresses the supply chain rather than the product: how a technology provider demonstrates that what it ships is what it built, and that nothing was substituted or tampered with along the way. It was later adopted as ISO/IEC 20243. I was a co-author and contributor to the original framework and first publication of the standard.