Overview
EN ISO/IEC 15408-5:2026 - Information Security, Cybersecurity and Privacy Protection – Evaluation Criteria for IT Security – Part 5: Pre-defined Packages of Security Requirements defines sets of pre-defined security assurance and functional requirements for IT products. These packages are designed to support common use cases among stakeholders such as consumers, developers, and evaluators, streamlining security specification and assessment processes aligned with international best practices.
This standard is part of the ISO/IEC 15408 series, which is widely recognized as the Common Criteria for Information Technology Security Evaluation. EN ISO/IEC 15408-5:2026 specifically focuses on providing ready-to-use collections of requirements, known as packages, to promote consistency, efficiency, and comparability in IT product security evaluations.
Key Topics
- Pre-defined Security Requirement Packages: Offers readily assembled sets of assurance and functional requirements that can be integrated into security specifications.
- Evaluation Assurance Levels (EAL): Describes a hierarchy of assurance packages, each corresponding to a different rigor and depth of evaluation, from basic functionally tested (EAL1) up to formally verified design and tested (EAL7).
- Composed Assurance Packages (CAP): Details packages meant for evaluating composed or integrated Target of Evaluations (TOEs), facilitating modular and layered security assessments.
- Composite Product Packages (COMP): Specifies security requirements relevant for complex, integrated products.
- Assurances for Protection Profiles (PPA) and Security Targets (STA): Outlines pre-defined packages for use in the development and evaluation of Protection Profiles and Security Targets, which are foundational elements in the Common Criteria framework.
- Stakeholder Support: Meets the needs of IT product consumers, developers, and third-party evaluators by offering standardized, reusable requirement sets.
Applications
The practical value of EN ISO/IEC 15408-5:2026 is evident in a variety of IT security and privacy domains:
- Product Development: Developers can reuse standardized security requirement packages during design, reducing time and effort in creating secure IT products and documentation.
- Security Evaluation: Evaluators benefit from consistent, internationally recognized reference packages, making it simpler to assess compliance and compare products.
- Purchase and Procurement: Consumers and organizations can reference recognized requirement sets when specifying security criteria in tenders, ensuring products meet accepted security benchmarks.
- Regulatory Alignment: Facilitates compliance with national and international regulations by referencing globally recognized security assurance packages.
- Component Integration: Supports assessment of complex or composed IT systems, making it easier to evaluate security across integrated solutions.
Using EN ISO/IEC 15408-5:2026 helps streamline procurement, improves efficiency in evaluation and certification, and reduces duplication of effort across IT security lifecycle stages.
Related Standards
For a comprehensive approach to IT product security, consider these related parts and standards:
- EN ISO/IEC 15408-1: Introduction and general model for IT security evaluation criteria.
- EN ISO/IEC 15408-3: Specifies the security assurance components and their use.
- ISO/IEC 18045: Provides guidelines for evaluation of IT security and interpretation of the ISO/IEC 15408 standards.
- Common Criteria Recognition Arrangement (CCRA): International recognition of security evaluations performed under ISO/IEC 15408.
- Other ISO/IEC 27000 series standards: Complementary standards for information security management and risk assessment.
These international standards collectively enable robust and harmonized security evaluation and assurance for IT products and solutions, emphasizing interoperability and confidence in cybersecurity and privacy protection.
Keywords: EN ISO/IEC 15408-5:2026, information security, cybersecurity, privacy protection, evaluation criteria, IT security, security assurance, security functional requirements, EAL, Common Criteria, composed assurance package, Protection Profile, Security Target, CEN, standardization, IT product evaluation.