The following services and/or processes provided by Giesecke & Devrient Ibérica are in the scope of the site evaluation process:
- Secure reception, storage and delivery of Smart Card modules and Smart Cards (these different types of Smart Card related products are referred to as 'Smart Cards' throughout the rest of this document). Delivery includes delivery for secure destruction.
- Secure reception and storage of initialisation data for Smart Card Production
- Secure reception and storage of cryptographic keys, derivation of card specific personalisation keys.
- Smart Card Production comprising completion (i.e. finishing the Smart Card OS), and initialisation of contact (incl. dual interface) cards and contactless cards or modules
- Secure inlay manufacturing
The assurance components are chosen in order to re-use the results in evaluations up to EAL5. Therefore, it has been assumed that the security measures are resistant to attacks performed by attackers with a High attack potential.