Acknowledgements

This PP-Configuration was developed by the iTC for Application Software international Technical Community (iTC) also known as AppSW-iTC with representatives from Industry, Government agencies, Common Criteria Test Laboratories, and members of academia.

Revision History

Table 1. Revision history
Version Date Description

1.0

2022-04-06

Initial Release

1.0e

2024-02-15

Incorporated feedback received following initial release.

2.0

2026-07-21

Draft-review updates.

1. Introduction

1.1. PP-Configuration Overview

The purpose of a PP-Configuration is to combine Protection Profiles (PPs) and PP-Modules for various technology types into a single configuration that can be evaluated as a whole.

This PP-Configuration is for enterprise server applications.

A TOE with separately deployed instances of multiple distinct TOE Components that collectively provide the TOE security functionality shall use the PP-Configuration for Enterprise Server Applications and Agent/Application Component(s) when its component relationships satisfy the Agent Module’s registration, enablement, disablement, and protected-communication model. Multiple deployed instances of the same TOE Component are Runtime Replicas when they meet the base cPP definition and do not, by themselves, trigger this requirement. This Server-only PP-Configuration does not define an alternative distributed-TOE allocation path; a distributed product that does not fit the Agent Module control model requires another approved PP-Configuration or iTC guidance.

Base cPP terminology used in Figures 1 and 2
  • A TOE Component is a named, logical, separately deployable portion of the TOE that is identified in the ST and mapped to the base cPP, applicable PP-Modules, and relevant SFRs (Section 1.2.2, Technical Terms, and Section 1.5, Distributed and Microservices TOE Architectures).

  • TOE Component Instance, Runtime Replica, and Communication Relationship Type are defined in Section 1.2.2, Technical Terms.

  • In Figure 2, each S-1 through S-n or A-1 through A-n box is a TOE Component Instance; its connected TOE Component box identifies the logical TOE Component; qualifying instances of the same TOE Component are Runtime Replicas; and R1 denotes a Communication Relationship Type.

The following figures illustrate this applicability rule. They are explanatory; the conformance text and the requirements in the claimed PP-Configuration components control.

Decision flow for selecting the Server-only or Server and Agent PP-Configuration
Figure 1. PP-Configuration selection for TOE Components and deployed instances
Examples contrasting one TOE Component with multiple Runtime Replicas and distinct Server and Agent TOE Components
Figure 2. TOE Components compared with their deployed instances
Note
Only TOE Components inside the TOE boundary count toward this applicability decision. Server and Agent are PP-Configuration roles; they do not imply communication direction, hosting relationship, or privilege. One relationship line in the topology figure represents a Communication Relationship Type rather than every runtime connection between replicas.

A Server Application payload executing in a Linux container remains subject to the base cPP and Supporting Document guidance for Linux Running-Payload Activities, including separate artifact, update-lifecycle, runtime or orchestrator dependency, and external-interface or channel coverage at the layer stated by each EA.

1.2. PP-Configuration Reference

This PP-Configuration is identified as follows:

  • PP-Configuration for Enterprise Server Applications, Version 2.0, 2026-07-21

  • As a shorthand reference, it can be identified as "CFG_APP-Server_V2.0"

1.3. PP-Configuration Components

This PP-Configuration includes the following components:

Table 2. PP-Configuration Components

[base PP]

cPP_APP_SW_V2.0

[PP-Module 1]

MOD_Server_v2.0

2. Conformance Claims

2.1. CC Statement

To be conformant to this PP-Configuration, an ST must demonstrate Exact Conformance as defined by CC:2022.

2.2. CC Conformance Claims

This PP-Configuration, and its components specified in section 1.3, are conformant to Parts 2 (extended) and 3 (conformant) of Common Criteria CC:2022, Revision 1 [CC].

3. SAR Statement

The set of SARs specified for this PP-Configuration are taken from, and identical to, those specified in the base PP.

Common Criteria[1]

Table 3. Common Criteria References

[CC1]

Common Criteria for Information Technology Security Evaluation,
Part 1: Introduction and General Model,
CCMB-2022-11-001, CC:2022, Revision 1, November 2022.

[CC2]

Common Criteria for Information Technology Security Evaluation,
Part 2: Security Functional Components,
CCMB-2022-11-002, CC:2022, Revision 1, November 2022.

[CC3]

Common Criteria for Information Technology Security Evaluation,
Part 3: Security Assurance Components,
CCMB-2022-11-003, CC:2022, Revision 1, November 2022.

[CEM]

Common Methodology for Information Technology Security Evaluation,
Evaluation Methodology,
CCMB-2022-11-006, CC:2022, Revision 1, November 2022.

[ERR]

Errata and Interpretation for CC:2022 (Release 1) and CEM:2022 (Release 1),
CCMB-2024-02-001, Version 1.0, 1 February 2024.


1. For details see http://www.commoncriteriaportal.org/