A regional bank is procuring a new hardware security module to protect customer signing keys for an internet banking platform. The procurement team has shortlisted two vendors that both advertise FIPS 140-3 Level 3 validation, but one product also carries a Common Criteria EAL4+ certification against a published protection profile and the other carries no Common Criteria evaluation. The CISO must justify the selection to the board on a security-requirements basis. What should be the PRIMARY driver of the control selection decision?
- AMap the bank's documented signing-key protection requirements to the security functional requirements in the protection profile that each product was evaluated against, and select the product whose evaluated scope matches. Correct
- BChoose the EAL4+ product because a higher assurance label generally indicates a more secure device against modern threats.
- CChoose whichever product has the longer FIPS 140-3 validation certificate history, since regulators tend to favour mature cryptographic modules.
- DDefer the decision to the vendor risk team and pick the product with the better contractual indemnity for cryptographic key compromise.
Why A is correct: Control selection under a requirements-led approach starts from the organisation's security requirements, then chooses a control whose evaluated security functions cover those requirements, which is exactly how Common Criteria protection profiles are intended to be used in procurement.
Why B is wrong: Tempting because candidates often equate higher EAL numbers with better security, but Common Criteria assurance levels describe the rigour of evaluation against a specific protection profile, not absolute security strength, so picking on label alone ignores whether the evaluated functionality actually matches the bank's signing-key threat model.
Why C is wrong: Plausible because regulators do scrutinise cryptographic module validation, yet validation age is a weak proxy for fit, and ignoring the protection profile means the bank cannot demonstrate that the evaluated functions cover its actual signing-key requirements.
Why D is wrong: Indemnity matters for residual risk transfer, but it is a commercial control rather than a technical control, and selecting a security control primarily on contractual recourse rather than evaluated security functionality inverts the requirements-driven model the CISSP expects.