<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Webinar Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/category/webinar/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/category/webinar/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Fri, 21 Nov 2025 16:04:06 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Webinar Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/category/webinar/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>DoDIN APL Planning Leads to Smooth Sailing &#8211; Webinar Recap</title>
		<link>https://www.corsec.com/smooth-sailing-in-uc-apl/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 26 Sep 2013 13:18:26 +0000</pubDate>
				<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[webinar]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6478</guid>

					<description><![CDATA[<p>Getting your product listed on the DoD UC APL can seem like a Herculean task. We’ve talked before about the ins and outs of the entire listing process, but anyone who has considered any type of IT security validation knows that making the process as efficient as possible is as key as paying attention to the details. Last week, Corsec Co-Founder...</p>
<p>The post <a href="https://www.corsec.com/smooth-sailing-in-uc-apl/">DoDIN APL Planning Leads to Smooth Sailing &#8211; Webinar Recap</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Getting your product listed on the DoDIN APL can seem like a Herculean task. We’ve talked before about the <a href="http://www.corsec.com/about-us/webinars/dod-uc-apl-solutions/" target="_blank" rel="noopener noreferrer">ins and outs of the entire listing process</a>, but anyone who has considered any type of IT security validation knows that making the process as efficient as possible is as key as paying attention to the details. Last week, Corsec Co-Founder and President John Morris addressed just that issue in our webinar “Planning for Efficient DoDIN APL Listing.”</p>
<p>As we heard from many of you during and after the webinar, efficiency during the DoDIN APL listing process is a common concern for those who want to have their products added to the DoDIN APL, a requirement for anyone wishing to sell to the Department of Defense (DoD). In today’s post, we’ll share some nuggets from our webinar about the best ways to build efficiencies into your own DoDIN APL process during the planning stages. For more information, watch the entire webinar on demand.<span id="more-2041"></span></p>
<p><strong>Why is efficient planning so important?<br />
</strong>There’s so much planning and decision making involved both in performing the Self Assessment Reviews (SARs) and during the actual testing phase itself. Efficient planning is important because it helps you save time, costs and resources, and helps you reach your ultimate goal of getting your product listed.</p>
<p><strong><i>1. Reducing Costs Through Similarity Arguments<br />
</i></strong></p>
<p><strong><i>2. Solid planning</i></strong></p>
<p><i><strong>3. Choose the most efficient product category</strong></i></p>
<p><strong><i>4. Obtain Testing Center Buy-in Early</i></strong></p>
<p><strong><i>5. Have Well-Prepared Documentation</i></strong></p>
<p><strong><i>6. Engage in Conversation</i></strong></p>
<p><strong><i>7. Find an alternate sponsor</i></strong></p>
<p>Corsec often helps our clients identify a potential alternate sponsor, and we usually recommend that they look at someone in the DoD to be a technical sponsor. There are people in the DoD who have sponsored many DoDIN APL listings; they are effective because they know DoD personnel and can operate within the Department in a politically correct manner.</p>
<p>We’ve seen organizations that have been stuck for a year or more in the DoDIN APL testing process. Execution can be a big stumbling point because there tends to be an enormous inertia factor involved in testing due to red tape, lack of communication and poor planning. Knowing how to push the process forward and avoiding the retiring of your tracking number is so important.</p>
<p>Although there are many potential traps inherent in DoDIN APL testing, the process itself is predictable. The more you plan, the more efficient your testing experience will be, and the more successful your outcome.</p>
<p>Corsec has helped many organizations navigate DoDIN APL testing, improve efficiencies, and save time, resources, and money. For more detail, review our entire “<a href="http://corsec.com/insights/webinars/" target="_blank" rel="noopener noreferrer">Planning for Efficient DoDIN APL Listing</a>” webinar. Then <a href="http://www.corsec.com/contact-us/" target="_blank" rel="noopener noreferrer">let us know</a> how we can help you.</p>
<p>The post <a href="https://www.corsec.com/smooth-sailing-in-uc-apl/">DoDIN APL Planning Leads to Smooth Sailing &#8211; Webinar Recap</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Webinar Recap: Revalidation &#8211; When Is the Right Time?</title>
		<link>https://www.corsec.com/webinar-recap-should-you-revalidate-or-recertify/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 06 Jun 2013 14:43:54 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6498</guid>

					<description><![CDATA[<p>If you have been through the certification or validation process for your security product, I don’t need to tell you that it’s a substantial investment in time, resources and cost. Or that it’s worth that investment when you consider the benefits you’ll realize from your ability to sell into the lucrative government market. We discussed...</p>
<p>The post <a href="https://www.corsec.com/webinar-recap-should-you-revalidate-or-recertify/">Webinar Recap: Revalidation &#8211; When Is the Right Time?</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If you have been through the certification or validation process for your security product, I don’t need to tell you that it’s a substantial investment in time, resources and cost. Or that it’s worth that investment when you <a href="http://www.corsec.com/2013/03/is-there-value-in-maintaining-your-security-validation/">consider the benefits</a> you’ll realize from your ability to sell into the lucrative government market.</p>
<p>We discussed the details of maximizing your certification investment in our recent webinar. You can watch the whole thing <a title="Maximizing Your Certification Investment" href="http://corsec.com/insights/webinars/">here</a>, but in this two-part blog post series, we’ll give you some of the details.</p>
<p>Technology doesn’t stand still for a nanosecond, and neither do your clients or your competition. Almost as soon as you attain certification, your development team is hard at work making tweaks and preparing for the next release. Sometimes these changes are significant, such as adding features or utilizing newer technology; or maybe they’re minor such as edits to the product documentation or new comments added to the code.<span id="more-1704"></span></p>
<p>If you’re worried about whether refinements could mean you’ll require a new certification or validation, you’re right to be concerned. The last thing you want is to jeopardize your federal market potential by not having the proper validation or certification for your product. Should you invest the time and effort on revalidation, and how do you know whether it’s wise to do so?</p>
<p>That depends on many factors, which are different for Common Criteria versus FIPS 140-2.</p>
<p><strong>Let’s look at Common Criteria first.</strong></p>
<p>Assurance Continuity is a process that helps you determine whether to go down the path to recertification, whereby you must undergo reevaluation and present evidence to a lab; or if you can perform assurance maintenance, which is an addendum to your existing certification listing and only requires a maintenance report. Assurance Continuity is based on the scope of changes to your product.</p>
<p>Minor changes include editorial changes to the documentation, comments added to the code, changes to the development environment that don’t affect how the product was developed, changing the product name, security target ID or Target of Evaluation (TOE) identifier.</p>
<p>Major changes that necessitate reevaluation for Common Criteria are those that affect security, such as changes to assurance requirements. For example, if your product was certified for EAL 2 and you want to attain EAL 4 (or vice versa), you must undergo a new evaluation. Other major changes would include revising the product’s functional requirements, the use of procedures or processes not assessed in the original evaluation, and making sets of minor changes that together have a major impact upon the security of the product.</p>
<p>If you’re unsure of whether your product requires recertification now or will require reevaluation after changes you’ve planned, don’t take chances; Corsec can help you determine the right course of action.</p>
<p>Unlike Common Criteria, <strong>FIPS 140-2</strong> outlines five change scenarios to determine whether your product requires revalidation or whether you can submit a letter of rationale to the lab that basically explains why the changes don’t affect the FIPS security posture of the module. Examples of changes that don’t affect any FIPS-relevant security items are a change to the GUI, or changes to the physical enclosure of the module.</p>
<p>Changes that require FIPS revalidation include changes you make to more than 30 percent of FIPS-relevant security items.</p>
<p>Your Corsec engineer can help you determine if your product meets the 30 percent threshold, and can review each FIPS change scenario with you in detail. We are also able to assess the scope of your changes where Common Criteria Assurance Continuity is concerned. <a href="http://corsec.com/company/contact-us/" target="_blank" rel="noopener">Contact us</a> for details.</p>
<p>Assuming you’ve determined that you must pursue a next step to keep your security product certification current and applicable, it’s important to understand timing and cost implications so you can allocate your resources and budget accordingly.<span id="more-1715"></span></p>
<p><strong>Common Criteria</strong></p>
<p>If your product has undergone any changes, you must perform Assurance Continuity (the process that helps you determine whether you need <a href="http://www.corsec.com/common-criteria-services/common-criteria-faq/">Common Criteria</a> recertification or if assurance maintenance is sufficient). If you determine that your product changes are classified as minor, you can move forward with assurance maintenance.</p>
<p>To get started, you or your certification consultant must first update your existing Common Criteria documentation to reflect the changes to your product. Next, you must engage with a lab to re-execute the testing against the new product version and provide the test results to the appropriate scheme. Then, an Impact Analysis Report (IAR) that defines the changes must be produced, either by you, the lab or your certification consultant; and be sent to the scheme.</p>
<p>You can significantly reduce the timeline and maintain costs by working with a highly qualified consultant who manages the entire process for you. Because a qualified consultant will be very familiar with all the testing labs and schemes, they will understand what each looks for in documentation and testing. Consulting engineers can streamline communications with the lab and other entities, which shortens the time it takes to produce complete and proper documentation and anticipate any potential issues before they become problems.</p>
<p><strong>FIPS 140-2</strong></p>
<p>A <a href="http://www.corsec.com/fips-services/fips-140-2-faq/">FIPS 140-2</a> revalidation can range from $5,000 to the original cost of your validation dependent upon which change category applies to your situation and how well you’ve planned your documentation. Again, a consultant can manage the process so that team members can remain on other revenue generating projects.</p>
<p>Can you afford <i>not</i> to maintain your validation/certification?</p>
<p>If the thought of assurance maintenance, change categories and re-evaluation makes you uneasy, consider the money you leave on the table every day that you <i>don’t </i>revalidate or recertify. Without <a href="http://www.corsec.com/2013/03/is-there-value-in-maintaining-your-security-validation/">up-to-date validation</a>, you can’t maximize the <a href="http://www.corsec.com/2013/05/you-have-your-validation-now-use-it-to-sell/">investment in your product</a>, and you could fall significantly short of revenue goals if product changes are made and the validation was not maintained for the newer version.</p>
<p>If your security product validation/certification is out of date and you decide to pursue an evaluation on your own, be prepared for what could be a long and frustrating road ahead. Every day that you spend tied up at the lab, writing documentation or trying to ascertain where bottlenecks are coming from is another day of revenue you won’t see and another day that other revenue-bearing projects don’t get your attention.</p>
<p>Using a consultant for these processes may seem like an additional expense but often makes the most financial sense because internal resources are not taxed and your revalidation or recertification occurs faster and more efficiently than if you attempt to do it yourself. Your consultant helps you develop and manage a maintenance strategy and schedule, determines which requirements apply to your product and product changes, ensures that all lab and scheme requirements are satisfied, prepares and revises all documentation, and manages all communications work with the lab and scheme from day one through to completion.</p>
<p>Keeping your validations and certifications up to date is not only good for your ROI, but it demonstrates your commitment to your customers’ security and the security of your products.</p>
<p>Corsec has assisted with hundreds of recertifications and revalidations over the past 15 years. <a href="http://corsec.com/company/contact-us/">Contact us</a> to find out how we can help you.</p>
<p>The post <a href="https://www.corsec.com/webinar-recap-should-you-revalidate-or-recertify/">Webinar Recap: Revalidation &#8211; When Is the Right Time?</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Webinar: Moving Through DoDIN APL Testing Efficiently</title>
		<link>https://www.corsec.com/webinar-moving-through-dod-uc-apl-testing-efficiently/</link>
					<comments>https://www.corsec.com/webinar-moving-through-dod-uc-apl-testing-efficiently/#respond</comments>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Mon, 12 Mar 2012 13:42:11 +0000</pubDate>
				<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[webinar]]></category>
		<guid isPermaLink="false">http://www.corsec.com/?p=1339</guid>

					<description><![CDATA[<p>If you’ve heard of DoDIN APL, you probably have a list of questions. DoDIN APL (which stands for The Department of Defense Information Network Approved Products List) is a directory of IT security products that ... </p>
<p class="read-more-container"><a title="Webinar: Moving Through DoDIN APL Testing Efficiently" class="read-more button" href="https://www.corsec.com/webinar-moving-through-dod-uc-apl-testing-efficiently/#more-1339" aria-label="More on Webinar: Moving Through DoDIN APL Testing Efficiently">Read more</a></p>
<p>The post <a href="https://www.corsec.com/webinar-moving-through-dod-uc-apl-testing-efficiently/">Webinar: Moving Through DoDIN APL Testing Efficiently</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If you’ve heard of DoDIN APL, you probably have a list of questions. DoDIN APL (which stands for The Department of Defense Information Network Approved Products List) is a directory of IT security products that have completed both Information Assurance (IA) and Interoperability (IO) testing and certification. Attaining inclusion in the APL can be an avenue to new revenue opportunities, but like anything involving federal approval, it’s not an easy road.<span id="more-1339"></span></p>
<p>The process for being added to the DoDIN APL is complex, with no fewer than 36 distinct steps to complete. There’s the preparation, documentation, and the testing; then you have to coordinate all of your testing activities and logistics, both with UCCO and with government sponsors.</p>
<p>The process can drag on if you don’t meet DoD deadlines for processing, testing, and mitigations. It’s possible to waste many months (or even years!) on unsuccessful approval efforts if you don’t have the right information and the best resources managing everything. There are also defined, stiff penalties for missing deadlines or steps.</p>
<p>How can you move through DoDIN APL testing efficiently?</p>
<p>If you’re wondering whether you should pursue DoDIN APL testing for your products and how you can avoid a drawn-out approval process, mark your calendar for next Wednesday, March 20th at 11:45am (EST) for our <a href="http://corsec.com/insights/webinars/" target="_blank" rel="noopener noreferrer">webinar</a>, <em>DoDIN APL Solutions: Dealing with UCCO, STIGS, JITC, The TIC, Army, and DoD Requirements</em>.</p>
<p>Presented by John Morris, Corsec president and co-founder, our webinar will offer the full scope of what you need to know about DoDIN APL. John will review the testing process, documentation, guidelines, rules and costs, as well as the types of DoDIN APL assessments. He’ll also cover the common pitfalls that many organizations encounter during the process, and will show you how to avoid them.</p>
<p>You can <a href="http://corsec.com/insights/webinars/" target="_blank" rel="noopener noreferrer"><strong>download this webinar </strong></a>here.</p>
<p>If you want immediate information about how Corsec’s DoDIN APL services streamline every aspect of your DoDIN APL certification, call us at (703) 267-6050 or email jnelson@corsec.com</p>
<p>The post <a href="https://www.corsec.com/webinar-moving-through-dod-uc-apl-testing-efficiently/">Webinar: Moving Through DoDIN APL Testing Efficiently</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.corsec.com/webinar-moving-through-dod-uc-apl-testing-efficiently/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
