Technology Security Assurance (TSA)

Technology Security Assurance (TSA) is a national scheme initiated by CyberSecurity Malaysia (CSM). It is an assurance where ICT products are evaluated based on Mandatory Security Functional Requirements (MSFRs) developed by the Information Security Certification Body (ISCB). Malaysia Security Evaluation Facility (MySEF) will perform Security Functionality Testing and Penetration Testing on the ICT products in identifying vulnerabilities and assist organizations in understanding and improving the security requirement of their ICT products.


Background

The ICT product that will be evaluated need to fulfil the requirement as stated in the Mandatory Security Function Requirement (MSFR). This form consist of 6 sections that need to fill in as follows:

  1. Section 1: Applicant’s Claims – the information in this section shall be filled in by the Applicant. The completeness and accuracy of the information is important in order to ensure that the application is accepted. Sub-section D in this section shall also be filled in by the evaluation team and certification team that summarises the evaluation findings for each claimed MSFR of the product.
  2. Section 2: SEF(s) Information – the information in this section shall be filled in by the SEF(s) assigned to conduct the security evaluation for this project. The information in this section is important to TSA Scheme Certification Body (TSACB) in order to ensure that the evaluation is conducted by the competent licensed SEF(s), and to ensure that each evaluation has a sound base and that the evaluation has a reasonable chance of completion.
  3. Section 3: Evaluation & Certification Summary Report – the information in this section shall be filled in by the SEF(s) assigned to conduct the evaluation and certification team for this project. This section provides the summary report of the evaluation and certification project conducted.
  4. Section 4: SEF(s) Recommendations – the information in this section shall be filled in by the SEF(s) assigned to conduct the evaluation. This section provides the Lead Evaluator(s) recommendations.
  5. Section 5: TSACB Review, Recommendations and Approval – the information in this section shall be filled in by the TSACB. This section provides the Lead Certifier recommendations and record the summary findings of the internal ISCB review.
  6. Section 6: Scheme Head Decision – the information in this section shall be filled in by the Scheme Head. This section provides the Scheme Head recommendations and record the decision whether to certify the product or not.


Objective

The objectives of TSA are as follows:

  1. To increase local developers’ competitiveness in quality assurance for information security
  2. To build consumers’ confidence and trust towards Malaysian ICT security products
  3. To provide a product certification that will be a faster in term of evaluation and certification processes.
  4. To provide a competitive product certification costs and pricing.


Certification Benefits

The certified ICT product and developers’ company names will be listed at CyberSecurity Malaysia website.


Personal Data Protection Act 2010 (PDPA)

In no event will CyberSecurity Malaysia be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from loss of data or profits resulting from the use or in any way connected with which may arise in connection with the provisions of the Services by CyberSecurity Malaysia.




How To Apply


Certification Guideline

ICT Developer Eligibility Criteria & Requirement
All potential ICT product developers who wish to have their product for certification must be:

  1. Registered with CyberSecurity Collaborative Program (CCP) under CyberSecurity Malaysian; and
  2. ICT products developed in Malaysia

The ICT developers are required to adhere to the following requirements:

  1. To complete the developers’ Mandatory Security Functional Requirement (MSFR) form and to attend the kick-off meeting.
  2. Resources: To have sufficient dedicated technical staff to ensure the evaluation process to be completed within the stipulated time frame;
  3. Commitment:
    • The ICT product developer is to provide full commitment towards the TSA Evaluation process with email response within 2 working days;
    • The ICT developer will need to queue again for the TSA Evaluation process if the evaluation failed.
    • The ICT product developer is to clearly understand the Terms and Conditions for TSA Evaluation process and sign the MSFR.


Certification Process

  1. Below is the flow of the certification process. Starts with acceptance process and ends with certification.
  2. The certified product will enter certification maintenance for second and third year. Any certified product that has more than to go for another evaluation and certification process again.
  3. During the maintenance process, if the product found to has major update, the product has to go for another evaluation and certification process again.
  4. However, if the product found to has minor update, an addendum will be issued.



Certification Fee

RM6,250.00


Contact

For any enquiry please contact:
enquiry@cybersecurity.my

logo
CyberSecurity Malaysia is the national cyber security specialist agency under the purview of the Ministry of Digital (KD)
 
Contact Us

  • CyberSecurity Malaysia,
    Level 7 Tower 1, Menara Cyber Axis, Jalan Impact,
    63000 Cyberjaya, Selangor Darul Ehsan, Malaysia.

  • enquiry@cybersecurity.my

  • +603 - 8800 7999

  • +603 - 8008 7000

TOP