EN ISO/IEC 15408-1:2026
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 1: Introduction and general model (ISO/IEC 15408-1:2026)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 1: Introduction and general model (ISO/IEC 15408-1:2026)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 150
- Дата публикации:
- 27 мая 2026 г.
- Издание:
- CEN/CENELEC EN 15408 edition 2 version 1
- ICS:
- 35.030
This document establishes the general concepts and principles of information technology (IT) security evaluation. It specifies the general model of evaluation given in this document, which in its entirety is intended to be used as the basis for evaluation of security properties of IT products. This document provides an overview of all parts of the ISO/IEC 15408 series. It describes the various parts of the ISO/IEC 15408 series i.e. defines the terms and abbreviations used in all parts of the series; establishes the core concept of a Target of Evaluation (TOE); describes the evaluation context; and describes the audience to which the evaluation criteria is addressed. Additionally, this document introduces the basic security concepts necessary for the evaluation of IT products.
Abstract
Overview
EN ISO/IEC 15408-1:2026 is an international standard published by CEN, titled "Information security, cybersecurity and privacy protection – Evaluation criteria for IT security – Part 1: Introduction and general model." This standard establishes the foundational concepts and principles for evaluating information technology (IT) security. As the introductory document in the ISO/IEC 15408 series, it outlines key terminology, core concepts such as the Target of Evaluation (TOE), and the general context for IT security evaluations.
The standard provides a comprehensive overview of the entire ISO/IEC 15408 family, often referred to as the Common Criteria (CC), which is widely recognized for structuring IT security assessment and certification practices globally. The main focus is to facilitate comparable, consistent, and reliable evaluation results for IT products, thereby enhancing trust in digital systems and helping organizations ensure robust cybersecurity and privacy protection.
Key Topics
- General Model for IT Security Evaluation
- Establishes the concept of a Target of Evaluation (TOE)
- Defines TOE boundaries, representations, and operational contexts
- Terminology and Abbreviations
- Standardizes language for effective communication across all ISO/IEC 15408 parts
- Evaluation Context and Audience
- Describes who uses the criteria (product developers, evaluators, and procurement bodies)
- Identifies suitable applications and stakeholders for the evaluation process
- Security Concepts Introduction
- Explains basic principles such as confidentiality, integrity, and availability
- Introduces methods for specifying and justifying security requirements
- Overview of Series Structure
- Summarizes links to further parts describing security functional requirements and assurance requirements
Applications
The EN ISO/IEC 15408-1:2026 standard is invaluable for:
- IT Product Developers: Guidance on designing products with strong, certifiable information security measures that meet international evaluation requirements.
- Security Evaluators: Provides the methodology and context to conduct systematic and repeatable evaluations of software, hardware, and integrated systems.
- Procurement Professionals and Risk Owners: Helps organizations define procurement criteria, select secure IT products, and interpret security evaluation results to ensure products align with organizational security policies and risk management strategies.
- Regulatory Bodies: Creates a harmonized framework for referencing in national or sectoral cybersecurity regulations.
By using this common framework, organizations can:
- Facilitate procurement of trustworthy IT products for sensitive applications
- Support compliance with international cybersecurity and privacy standards
- Foster interoperability and comparability of security evaluations across different jurisdictions
Related Standards
EN ISO/IEC 15408-1:2026 is the first in the family of ISO/IEC 15408 standards. Other closely related standards include:
- ISO/IEC 15408-2: Covers security functional requirements for IT products
- ISO/IEC 15408-3: Details security assurance requirements
- ISO/IEC 18045: Provides specific guidance for the evaluation process itself
- ISO/IEC 27001: Specifies requirements for information security management systems (ISMS)
- ISO/IEC 27002: Offers guidelines for information security controls
These standards collectively support a robust approach to IT security evaluation, helping organizations achieve greater confidence in their cyber-resilience strategies amidst evolving threats.
Keywords: ISO/IEC 15408-1:2026, IT security evaluation, information security, cybersecurity, privacy protection, Common Criteria, CEN standard, Target of Evaluation (TOE), security requirements, international standards.
Технические детали
- Технический комитет
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- SKU
- EN ISO/IEC 15408-1:2026
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO/IEC 15408-2:2008
ОтменёнInformation technology — Security techniques — Evaluation criteria for IT security — Part 2: Security functio…
BS EN ISO/IEC 15408-3:2026
ДействующийInformation security, cybersecurity and privacy protection. Evaluation criteria for IT security. Security ass…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…