A framework for independent assessment, analysis, and testing of IT products to a set of security requirements.