ISO/IEC 15408-2:2026
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 2: Security functional components
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 2: Security functional components
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 243
- Дата публикации:
- 19 мая 2026 г.
- Издание:
- ISO/IEC IS 15408 edition 5 version 1
- ICS:
- 35.030
This document specifies requirements for the required structure and content of security functional components for use during a security evaluation. It includes a catalogue of functional components that meet the common security functionality requirements of many IT products.
Abstract
Overview
ISO/IEC 15408-2:2026 is an international standard developed by ISO and IEC, forming Part 2 of the Common Criteria (CC) framework for information security, cybersecurity, and privacy protection. This document specifies the required structure and content of security functional components, essential during the security evaluation of IT products and systems. It serves as a catalogue of functional components that address common security functionality needs across diverse IT environments. By providing a uniform reference, this standard helps guide developers, evaluators, and procurement professionals in specifying and assessing IT security functions.
Key Topics
- Security Functional Components: A structured catalogue enabling consistent specification of security functions for IT products.
- Component Structure: Standardized templates for class, family, and component-level requirements, ensuring clarity and comparability.
- Functional Families and Classes: Grouping of requirements by function, such as audit, access control, communication, and cryptographic support.
- Component Management and Audit: Documentation and auditing guidance for each security function to support verification and evaluation.
- Application and Evaluator Notes: Advice and clarifications to assist those implementing or evaluating the selected components.
- Component Rationale and Relationships: Explanation of purpose and how components interact or build on one another.
Applications
ISO/IEC 15408-2:2026 is widely applied in multiple sectors for enhancing the security trustworthiness of IT products. Its practical applications include:
- Product Security Evaluation: Developers and evaluators use the standard’s functional components to demonstrate and assess security features of products such as operating systems, network devices, smart cards, and other IT solutions.
- Procurement Requirements: Organizations specify required security functions based on this catalogue when procuring secure IT products or services, ensuring compliance with recognized international benchmarks.
- Security Architecture Development: Architects and engineers reference these components when designing or upgrading IT systems to implement robust, consistent security controls.
- Certification and Accreditation: The standard forms part of evaluation schemes for product certifications, supporting internationally recognized security assurance.
- Regulatory Compliance: Governments and industries incorporate these requirements into laws, regulations, and best practices to safeguard sensitive data and maintain privacy protection.
Related Standards
To effectively address comprehensive IT security and privacy needs, ISO/IEC 15408-2:2026 is often used in conjunction with the following standards:
- ISO/IEC 15408-1: Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 1: Introduction and general model
- ISO/IEC 15408-3: Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 3: Security assurance components
- ISO/IEC 18045: Information technology - Security techniques - Methodology for IT security evaluation
- ISO/IEC 27001: Information security management systems - Requirements
- ISO/IEC 27002: Code of practice for information security controls
Practical Value
Adopting ISO/IEC 15408-2:2026 provides significant benefits:
- Consistency in specifying and verifying security requirements across IT products and environments.
- Transparency in security evaluation processes, increasing confidence for all stakeholders.
- Interoperability by harmonizing security expectations internationally.
- Reduced Risk of security gaps by applying internationally vetted security functional components.
By utilizing this standard, organizations and product developers ensure that essential security functions are clearly defined, properly implemented, and rigorously evaluated to support robust information security, cybersecurity, and privacy protection.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-2:2026
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO/IEC 15408-1:2026
ДействующийInformation security, cybersecurity and privacy protection. Evaluation criteria for IT security. Introduction…
BS EN ISO/IEC 15408-3:2026
ДействующийInformation security, cybersecurity and privacy protection. Evaluation criteria for IT security. Security ass…
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…