Essential Guide

Enterprise firewall protection: Where it stands, where it's headed

A comprehensive collection of articles, videos and more, hand-picked by our editors

Is EAL4 certification necessary for enterprise firewall products?

EAL4 certification ensures integrity in security products, but is it a must when buying enterprise firewall products? Expert Brad Casey explains.

I'm using Gartner's recent Magic Quadrant report on firewalls to help choose a firewall for my company. For one...

of the products, Gartner cautions that it doesn't have EAL4+ level certification for the Common Criteria for Information Technology Security Evaluation. What exactly does that mean, and should it be a deal breaker in certain situations?

Ask the Expert

Have a question about network security for expert Brad Casey? Send them via email today! (All questions are anonymous)

The Evaluation Assurance Level (EAL) is the grade assigned to a product or system after completing a Common Criteria security evaluation. For those who aren't familiar with it, Common Criteria (CC) is a set of security product evaluation specifications used internationally for evaluating information security products. The levels range from EAL1 to EAL7; EAL1 being the most basic -- and therefore cheapest -- to accomplish, and EAL7 the most in-depth -- and expensive -- level of evaluation. 

Many large organizations wish to leverage network devices certified at EAL4 due to the prestige associated with achieving the level. It is also commonly accepted that EAL4 is the highest level of certification any device that is backwards compatible to an existing product line can possibly achieve.

According to research and consulting firm Gartner Inc., achievement of EAL4 means that a device has been methodically designed, tested, and reviewed by an independent third party.  So, lack of EAL4 certification does not necessarily mean that your chosen firewall is insecure, it simply means that your firewall may not have been tested in accordance with Gartner's Magic Quadrant methodology. 

The lack of an EAL4 rating should never be a deal breaker in and of itself.  Many vendors use other security consulting firms to test their network devices, and they work just fine.  No less than Gartner, Inc. itself states that they don’t research every vendor in every market.  This would be infeasible.  So if a vendor product that your organization is considering purchasing has not achieved EAL4 status, this simply means that a little more research is necessary on your part.

This was last published in December 2013



Find more PRO+ content and other member only offers, here.

Essential Guide

Enterprise firewall protection: Where it stands, where it's headed

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.
Related Discussions

Brad Casey, Contributor asks:

When purchasing an enterprise firewall, is Common Criteria EAL4 certification important? Why or why not?

0  Responses So Far

Join the Discussion

1 comment


Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: