Understanding the Trust Services Criteria (TSC)
Security (Common Criteria)
Foundational requirements that apply to all other criteria: risk, policies, access, change, monitoring, incidents.
Availability
System uptime and performance aligned with commitments (e.g., SLAs), including capacity and continuity planning.
Processing Integrity
Complete, valid, accurate, timely, and authorized processing of data.
Confidentiality & Privacy
Proper classification, access, retention/disposal (Confidentiality) and personal data lifecycle (Privacy).