ISO/IEC 15408-1:2026
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 1: Introduction and general model
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 1: Introduction and general model
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 138
- Дата публикации:
- 19 мая 2026 г.
- Издание:
- ISO/IEC IS 15408 edition 5 version 1
- ICS:
- 35.030
This document establishes the general concepts and principles of information technology (IT) security evaluation. It specifies the general model of evaluation given in this document, which in its entirety is intended to be used as the basis for evaluation of security properties of IT products. This document provides an overview of all parts of the ISO/IEC 15408 series. It describes the various parts of the ISO/IEC 15408 series i.e. defines the terms and abbreviations used in all parts of the series; establishes the core concept of a Target of Evaluation (TOE); describes the evaluation context; and describes the audience to which the evaluation criteria is addressed. Additionally, this document introduces the basic security concepts necessary for the evaluation of IT products.
Abstract
Overview
ISO/IEC 15408-1:2026 is an internationally recognized standard from ISO and IEC that establishes the fundamental concepts and principles for IT security evaluation. As the introductory part of the ISO/IEC 15408 series, this standard provides a common framework and terminology for evaluating the security properties of information technology (IT) products and systems, including software, hardware, and firmware. ISO/IEC 15408-1 is essential for organizations seeking a structured approach to information security, cybersecurity, and privacy protection through standardization of evaluation criteria.
This part outlines the general evaluation model, introduces the core concept of the Target of Evaluation (TOE), and defines the context, audience, and necessary security fundamentals for effective IT product evaluation. It serves as a comprehensive starting point for providers, evaluators, and users engaging with security evaluation processes.
Key Topics
- General Model of Evaluation: Defines a structured approach to assessing security properties of IT products, focusing on the confidentiality, integrity, and availability of assets.
- Target of Evaluation (TOE): Clarifies boundaries, configurations, and operational environments of IT products subject to evaluation.
- Security Problem Definition (SPD): Provides a methodology for identifying threats, organizational security policies, and environmental assumptions relevant to a product’s security.
- Security Requirements: Outlines the process for specifying security functional requirements (SFRs) and security assurance requirements (SARs).
- Protection Profiles (PP) and Security Targets (ST): Explains standardized templates for specifying and evaluating security claims of IT products.
- Evaluation Context and Results: Details how evaluations are performed, the context in which results are produced, and how these results help stakeholders make informed IT procurement and deployment decisions.
- Terminology and Core Concepts: Establishes unified definitions and abbreviations critical for consistent application across the ISO/IEC 15408 series.
Applications
ISO/IEC 15408-1:2026 is highly applicable in diverse sectors where IT security and privacy are paramount, including:
- Product Development: Enables IT product developers to define and structure the security properties and assurances for their products using globally recognized criteria.
- Procurement and Acquisition: Assists organizations in performing informed risk assessments and security evaluations when purchasing IT products or systems.
- Compliance and Certification: Serves as a reference for compliance with international security requirements and as a basis for third-party certification schemes.
- Security Evaluation Laboratories: Provides a common basis for evaluators and certification authorities to assess and compare the security properties of various IT products.
- Risk Management: Assists risk owners and IT managers in understanding the scope and context of security evaluations, leading to better-informed security decisions.
Related Standards
- ISO/IEC 15408-2: Specifies security functional components and templates (SFRs) used for defining what security functions a TOE must provide.
- ISO/IEC 15408-3: Describes security assurance components and templates (SARs) for verifying the effectiveness of security measures.
- ISO/IEC 15408-4: Framework for specifying evaluation methods and activities, closely linked with ISO/IEC 18045.
- ISO/IEC 15408-5: Provides reusable security requirements packages, including commonly used assurance and functional packages.
- ISO/IEC 18045: Establishes the baseline methodology for IT security evaluations in accordance with ISO/IEC 15408.
Practical Value
Adopting ISO/IEC 15408-1:2026 fosters a standardized, high-confidence approach to IT security assessments in an era of increasing cyber threats. By using this framework, organizations can:
- Achieve comparability across different security evaluations.
- Streamline product development to meet internationally accepted criteria.
- Reduce risks associated with unauthorized access, data breaches, and loss of availability.
- Meet procurement, compliance, and regulatory security requirements efficiently.
This standard empowers organizations and stakeholders to build, select, and utilize IT systems and products with enhanced assurance and trust in their security capabilities.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-1:2026
Похожие стандарты
Стандарты, упомянутые в описании