Microsoft has supported and embraced the Common Criteria from the beginning. Microsoft submitted Exchange Server 2003 for evaluation by the TÜV Informationstechnik GmbH (TUViT), an independent, accredited evaluator for evaluation under the Common Criteria. Microsoft and TUViT have worked together before: TUViT performed the respective EAL 2 and EAL 4+ evaluations of Microsoft Internet Security and Acceleration (ISA) Server 2000, and ISA Server 2004.
To better understand where EAL 4 fits within the seven levels, it is helpful to know that, according to the Common Criteria drafters, EAL levels 5-7 are targeted toward the evaluation of products built with specialized security engineering techniques. As such, these levels are generally less applicable to products built with commercial distribution in mind. EAL 4, then, represents the highest level at which products not built specifically to meet the requirements of EAL 5-7 ought to be evaluated. To meet the Flaw Remediation requirement over and above EAL 4, as Exchange Server 2003 did, the developer/vendor must establish flaw remediation procedures that describe the tracking of security vulnerabilities, the identification of corrective actions, and the distribution of corrective action information to customers. The Microsoft Security Response Center fulfills these roles for Exchange Server 2003.
According to TUViT, "The evaluation of Exchange Server 2003 according to Common Criteria EAL 4 opens a new dimension, since Exchange Server 2003 is the first product of this kind awarded this assurance level. TUViT is proud to have met this exciting challenge."