EN ISO/IEC 15408-2:2026
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components (ISO/IEC 15408-2:2026)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components (ISO/IEC 15408-2:2026)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 264
- Дата публикации:
- 27 мая 2026 г.
- Издание:
- CEN/CENELEC EN 15408 edition 2 version 1
- ICS:
- 35.030
This document specifies requirements for the required structure and content of security functional components for use during a security evaluation. It includes a catalogue of functional components that meet the common security functionality requirements of many IT products.
Abstract
Overview
EN ISO/IEC 15408-2:2026 is an essential international standard developed by CEN, specifically addressing information security, cybersecurity, and privacy protection in IT systems. This standard-titled Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components-defines the necessary structure and content of security functional components used in IT product security evaluations. Central to the widely adopted Common Criteria framework, EN ISO/IEC 15408-2:2026 provides a comprehensive catalogue of security functionalities applicable to various IT environments.
The document ensures that consistent, repeatable, and well-documented criteria are available for assessing the security features of IT products and systems, supporting vendors, evaluators, and users in achieving and maintaining high standards of cybersecurity.
Key Topics
EN ISO/IEC 15408-2:2026 covers a broad spectrum of topics crucial to the evaluation of IT security, including:
- Security Functional Components: Structured sets of requirements that define specific security functionalities an IT product should deliver.
- Functional Class and Family Structures: Organization of security components into classes and families for clarity and systematic evaluation.
- Security Audit: Guidelines for recording, analyzing, and reviewing security-relevant events to support accountability and incident response.
- Cryptographic Support: Criteria for secure cryptographic key management, cryptographic operations, and random number generation.
- User Data Protection: Comprehensive requirements for access control, data authentication, information flow control, and information retention.
- Communication Security: Functional requirements for ensuring non-repudiation and secure data exchange.
- Component Catalogue: A detailed listing enabling developers and evaluators to select appropriate functional components based on system needs.
Applications
EN ISO/IEC 15408-2:2026 brings practical value to a range of stakeholders in the IT security sector:
- Security Evaluations: Used as a reference for third-party evaluation of IT products to ensure compliance with common security criteria.
- Product Development: Assists developers in designing and implementing security features in hardware, software, and integrated IT systems.
- Procurement: Enables organizations to specify security requirements for IT solutions during procurement, promoting robust cybersecurity across supply chains.
- Certification: Forms the functional basis for IT security certification schemes, giving assurance to customers and regulators.
- Regulatory Compliance: Supports alignment with regional and international regulations on data protection and cybersecurity by providing recognized evaluation metrics.
By adopting this standard, organizations enhance their ability to manage information risks, protect sensitive data, and ensure business continuity in the face of escalating cyber threats.
Related Standards
To provide a holistic approach to IT security evaluation and management, the following standards are closely related to EN ISO/IEC 15408-2:2026:
- EN ISO/IEC 15408-1:2026: Introduction and general model for IT security evaluation criteria.
- EN ISO/IEC 15408-3:2026: Security assurance components, complementing the functional catalogue with criteria for assessing the confidence in security functionality.
- ISO/IEC 27001 Series: Standards for information security management systems (ISMS).
- ISO/IEC 18045: Guidelines for the evaluation of IT security using ISO/IEC 15408.
- National and Regional Profiles: Localized profiles and protection profiles developed using the Common Criteria framework.
IT professionals, product developers, and organizations seeking to strengthen their cybersecurity posture are encouraged to integrate EN ISO/IEC 15408-2:2026 and its related standards into their security processes. This integration ensures recognized, effective, and demonstrable controls are in place, aligned with global best practices.
Технические детали
- Технический комитет
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- SKU
- EN ISO/IEC 15408-2:2026
Похожие стандарты
Упомянутые в описании и другие стандарты EN
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
EN ISO 16994:2026
ДействующийSolid biofuels and pyrogenic biocarbon - Determination of sulfur and chlorine content (ISO 16994:2026)
Overview EN ISO 16994:2026 is an international standard developed by CEN and ISO for the determination of sulfur and chlorine content in solid biofuels and pyrogenic biocarbon. Sulfur and chlorine ar…
EN ISO 10325:2026
ДействующийFibre ropes - High modulus polyethylene - 8-strand braided ropes, 12-strand braided ropes and covered ropes (…
Overview EN ISO 10325:2026 sets out the standardized requirements for 8-strand braided ropes, 12-strand braided ropes, and covered ropes made from high modulus polyethylene (HMPE). These HMPE fibre r…
EN ISO 3630-8:2026
ДействующийDentistry - Endodontic instruments - Part 8: Accuracy of electronic apex locator (ISO 3630-8:2026)
Overview EN ISO 3630-8:2026 specifies the requirements and standardized test methods for assessing the accuracy of electronic apex locators used in endodontic dentistry. These devices play a critical…
EN ISO 8100-1:2026
ДействующийLifts for the transport of persons and goods - Part 1: Safety rules for the construction and installation of…
Overview EN ISO 8100-1:2026 outlines international safety requirements for lifts (elevators) designed to transport persons and goods. Developed by CEN, this standard details the essential safety rule…
EN ISO 20650:2026
ДействующийInland navigation vessels - Small floating working machines - Requirements and test methods (ISO 20650:2025)
Overview EN ISO 20650:2026 specifies the requirements and test methods for small floating working machines used in, on, or over inland waters. Prepared by CEN and aligned with ISO 20650:2025, this in…
EN ISO 22248:2026
ДействующийLasers and laser-related equipment - Test methods for laser-induced damage threshold - Classification of medi…
Overview EN ISO 22248:2026 (ISO 22248:2020) is an international standard published by CEN that defines test methods for determining the laser-induced damage threshold and provides a classification sy…