ISO/IEC 15408-2:2022
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 2: Security functional components
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 2: Security functional components
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 273
- Дата публикации:
- 9 августа 2022 г.
- Издание:
- ISO/IEC IS 15408 edition 4 version 1
- ICS:
- 35.030
This document defines the required structure and content of security functional components for the purpose of security evaluation. It includes a catalogue of functional components that meets the common security functionality requirements of many IT products.
Abstract
Overview
ISO/IEC 15408-2:2022 defines the required structure and content of security functional components used for IT security evaluation. Part 2 of the ISO/IEC 15408 evaluation criteria series provides a standardized catalogue of functional components that address common security functionality across a wide range of IT products. The fourth edition (2022) organizes components into classes, families and component levels to support consistent evaluation and specification of security capabilities.
Key topics and technical requirements
- Functional requirements paradigm - defines how functional components are structured, specified and combined for evaluation.
- Class, family and component structure - hierarchical organization allowing precise selection of security functional components for a product or security target.
- Component catalogue - a comprehensive list of predefined functional components (e.g., audit, communication, cryptographic support) that evaluators and vendors can reference.
- Representative classes and families (examples referenced in the document):
- FAU (Security audit) - audit generation, storage, analysis, review and selection (FAU_GEN, FAU_STG, FAU_SAA, FAU_SAR, FAU_SEL, FAU_ARP).
- FCO (Communication) - non-repudiation of origin and receipt (FCO_NRO, FCO_NRR).
- FCS (Cryptographic support) - cryptographic key management and related cryptographic functions (FCS_CKM and related components).
- Management and audit expectations - component-level descriptions include management requirements and what must be auditable during evaluation.
- Leveling of components - components may be defined at multiple assurance/functional levels to match risk and product capability.
Practical applications - who uses this standard
- Security evaluators and certification bodies - to map product behaviour to standardized functional components during formal evaluation.
- Product developers and architects - to define, design and document security features that meet recognized evaluation criteria.
- Procurement and risk managers - to specify required security functionality in contracts and vendor assessments.
- Security testers and auditors - to verify that implemented features comply with the functional requirements and to plan test coverage.
Using ISO/IEC 15408-2 helps align product security claims with a recognized catalogue of functional requirements, simplifying certification, procurement and interoperability assessments.
Related standards
- Other parts of the ISO/IEC 15408 series (e.g., Part 1 - general model/introduction; Part 3 - security assurance components) and complementary IT security standards are commonly used alongside ISO/IEC 15408-2 for comprehensive security evaluation and compliance.
Keywords: ISO/IEC 15408-2:2022, security functional components, evaluation criteria for IT security, security audit, cryptographic key management, IT security evaluation.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-2:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO/IEC 15408-2:2008
ОтменёнInformation technology — Security techniques — Evaluation criteria for IT security — Part 2: Security functio…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…