EN ISO/IEC 18045:2026
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Requirements and methodology for IT security evaluation (ISO/IEC 18045:2026)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Requirements and methodology for IT security evaluation (ISO/IEC 18045:2026)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 440
- Дата публикации:
- 27 мая 2026 г.
- Издание:
- CEN/CENELEC EN 18045 edition 2 version 1
- ICS:
- 35.030
This document specifies requirements and the minimum actions performed by an evaluator in order to conduct an evaluation using the criteria and evaluation evidence defined in the ISO/IEC 15408 series evaluation.
Abstract
Overview
EN ISO/IEC 18045:2026 is an international standard developed by CEN, focused on information security, cybersecurity, and privacy protection. This standard specifies requirements and methodology for the evaluation of IT security, building on the evaluation criteria established in the ISO/IEC 15408 series (commonly known as Common Criteria). It provides detailed guidance for evaluators to ensure a consistent, robust, and systematic approach to assessing the security of IT products and systems.
EN ISO/IEC 18045:2026 is essential for ensuring that IT systems and products meet rigorous security standards, supporting organizations in demonstrating compliance with global best practices in cybersecurity and privacy protection.
Key Topics
This standard outlines comprehensive evaluation methodologies, including:
- Evaluation Process: Defines structured methodologies, tasks, and responsibilities for conducting IT security evaluations.
- Evaluation Evidence: Details types of documentation and evidence required for assessment based on ISO/IEC 15408.
- Protection Profile (PP) Evaluation: Guidance on evaluating security targets and claims in product protection profiles.
- Configuration and Consistency Checks: Ensures PP-Configurations and module consistency are addressed.
- Security Target (ST) Evaluation: Describes procedures for validating individual product security objectives and requirements.
- Development & Life-Cycle Support: Processes for assessing support measures through the product life cycle, including development, configuration management, flaw remediation, and delivery.
- Test and Vulnerability Assessment: Standards for functional testing, coverage analysis, independent testing, and identifying vulnerabilities.
Applications
EN ISO/IEC 18045:2026 is highly relevant for organizations involved in:
- IT Product and System Certification: Supporting evaluation facilities, developers, and certification bodies in assessing compliance with Common Criteria methodologies.
- Procurement and Vendor Assessment: Enabling buyers, especially in regulated sectors, to identify products evaluated under recognized, structured security criteria.
- Regulatory Compliance: Helping organizations align with legal and regulatory requirements related to cybersecurity and privacy.
- Product Development: Assisting IT solution developers in designing, implementing, and documenting security features in accordance with international standards.
Typical sectors that benefit include government, finance, healthcare, telecommunications, and critical infrastructure where IT security and privacy are paramount.
Related Standards
- ISO/IEC 15408 Series: Foundational evaluation criteria for IT security, commonly known as Common Criteria.
- ISO/IEC 27001: Information security management systems requirements.
- ISO/IEC 27002: Code of practice for information security controls.
- ISO/IEC 19790: Security requirements for cryptographic modules.
- EN ISO/IEC 29100: Privacy framework for IT systems.
- ISO/IEC 27036: Guidelines for securing supply chains.
For organizations seeking robust, internationally recognized IT security evaluation criteria, EN ISO/IEC 18045:2026 and its related standards deliver a vital framework to manage, assess, and assure cybersecurity and privacy in their products and services.
Keywords: EN ISO/IEC 18045:2026, IT security evaluation, cybersecurity standards, privacy protection, Common Criteria, ISO/IEC 15408, security certification, CEN standards, information security methodology, IT product compliance
Технические детали
- Технический комитет
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- SKU
- EN ISO/IEC 18045:2026
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…