ISO/IEC 15408-1:2022
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 1: Introduction and general model
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 1: Introduction and general model
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 142
- Дата публикации:
- 9 августа 2022 г.
- Издание:
- ISO/IEC IS 15408 edition 4 version 1
- ICS:
- 35.030
This document establishes the general concepts and principles of IT security evaluation and specifies the general model of evaluation given by various parts of the standard which in its entirety is meant to be used as the basis for evaluation of security properties of IT products. This document provides an overview of all parts of the ISO/IEC 15408 series. It describes the various parts of the ISO/IEC 15408 series; defines the terms and abbreviations to be used in all parts of the standard; establishes the core concept of a Target of Evaluation (TOE); describes the evaluation context and describes the audience to which the evaluation criteria is addressed. An introduction to the basic security concepts necessary for evaluation of IT products is given. This document introduces: — the key concepts of Protection Profiles (PP), PP-Modules, PP-Configurations, packages, Security Targets (ST), and conformance types; — a description of the organization of security components throughout the model; — the various operations by which the functional and assurance components given in ISO/IEC 15408‑2 and ISO/IEC 15408‑3 can be tailored through the use of permitted operations; — general information about the evaluation methods given in ISO/IEC 18045; — guidance for the application of ISO/IEC 15408‑4 in order to develop evaluation methods (EM) and evaluation activities (EA) derived from ISO/IEC 18045; — general information about the pre-defined Evaluation Assurance Levels (EALs) defined in ISO/IEC 15408‑5; — information in regard to the scope of evaluation schemes.
Abstract
Overview
ISO/IEC 15408-1:2022 defines the foundational concepts and general model for evaluating the security, cybersecurity and privacy protection properties of IT products. Part 1 of the ISO/IEC 15408 series establishes common terminology, the core construct of a Target of Evaluation (TOE), the evaluation context and the audience for evaluation criteria. It provides an overview of the whole ISO/IEC 15408 framework and introduces key constructs used across the series to express, tailor and assess security requirements.
Key topics and technical content
- General model and terminology: definitions, abbreviated terms and the TOE concept, including boundaries, representations, configurations and operational environment.
- Security problem definition (SPD): describing threats, organizational security policies (OSPs) and assumptions that drive requirements.
- Security objectives and tracing: objectives for the TOE and its environment and traceability back to the SPD.
- Security requirements:
- Security Functional Requirements (SFRs) - functional capabilities expected of the TOE.
- Security Assurance Requirements (SARs) - evidence and assurance needed to support claimed functions.
- Security components and operations: hierarchical structure (class, family, component, element) and permitted operations for tailoring (assignment, selection, refinement, iteration).
- Packages and modular construction: functional and assurance packages, dependencies and predefined package structures to simplify requirement composition.
- Protection Profiles (PP), PP‑Modules and PP‑Configurations: reusable requirement specifications and modular building blocks to express common consumer needs.
- Security Targets (ST) and conformance types: how products claim conformance to PPs or STs and the different conformance modes.
- Evaluation methods and activities: overview of evaluation approaches (see ISO/IEC 18045) and guidance for developing EM/EA under ISO/IEC 15408‑4.
- Evaluation Assurance Levels (EALs): pre-defined assurance levels (referenced from ISO/IEC 15408‑5) and scope considerations for evaluation schemes.
Practical applications and users
ISO/IEC 15408-1:2022 is used to:
- Define and document security requirements for IT products and systems.
- Build Protection Profiles for classes of products (e.g., firewalls, smart cards).
- Prepare Security Targets used during product evaluation and certification.
- Guide testing labs, evaluation bodies and certification schemes on evaluation context and methods.
- Support procurement, risk owners and security architects in specifying and assessing product security claims.
Primary users include product vendors, independent evaluators, certification bodies, security architects, procurement teams and compliance officers.
Related standards
- ISO/IEC 15408-2 and ISO/IEC 15408-3 (functional and assurance components)
- ISO/IEC 15408-4 (evaluation methods guidance)
- ISO/IEC 15408-5 (EALs)
- ISO/IEC 18045 (detailed evaluation methods and activities)
Keywords: ISO/IEC 15408-1:2022, information security evaluation, IT security evaluation, Target of Evaluation, Protection Profiles, Security Target, SFRs, SARs, Evaluation Assurance Levels, PP-Modules, PP-Configurations, ISO/IEC 18045.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-1:2022
Похожие стандарты
Стандарты, упомянутые в описании