[redhat-lspp] LSPP requirements

Casey Schaufler casey at schaufler-ca.com
Tue Dec 19 16:57:37 UTC 2006


--- Valdis.Kletnieks at vt.edu wrote:

> ... And since
> I'm an idiot, can anybody hand me a pointer to the
> CC/EAL equivalent of the
> old NCSC 'Rating Maintenance Phase' document
> (NCSC-TG-013 - the horribly pink
> part of the old Rainbow Series)?

And don't go saying bad things about the Pink Book.
There is no better tutorial about Software Process
on the planet. Even if you use it to decide what
you are going to avoid doing, or to clarify in
your mind why you hate Software Process it is an
irreplaceable reference. I was able to rescue a
major OS from collapse simply by threatening to
implement a Pink Book Process unless people got
their acts together. That OS released quarterly,
on time, for over 7 years after that.

Besides, the cover has faded over the years
and while still pink, is no longer Alarming
Pink.


Casey Schaufler
casey at schaufler-ca.com




More information about the redhat-lspp mailing list