ISO/IEC 15408-3:2022
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 3: Security assurance components
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 3: Security assurance components
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 189
- Дата публикации:
- 9 августа 2022 г.
- Издание:
- ISO/IEC IS 15408 edition 4 version 1
- ICS:
- 35.030
This document defines the assurance requirements of the ISO/IEC 15408 series. It includes the individual assurance components from which the evaluation assurance levels and other packages contained in ISO/IEC 15408-5 are composed, and the criteria for evaluation of Protection Profiles (PPs), PP-Configurations, PP-Modules, and Security Targets (STs).
Abstract
Overview
ISO/IEC 15408-3:2022 - part of the Common Criteria family - defines the security assurance components used to evaluate IT products and systems for information security, cybersecurity and privacy protection. This fourth edition specifies the assurance requirements from which evaluation assurance levels (EALs) and other assurance packages (referenced in ISO/IEC 15408-5) are composed. It also sets criteria for evaluating Protection Profiles (PPs), PP‑Configurations, PP‑Modules and Security Targets (STs).
Keywords: ISO/IEC 15408-3:2022, Common Criteria, security assurance components, evaluation assurance levels, Protection Profile, Security Target, IT security evaluation, cybersecurity assurance, privacy protection.
Key topics and requirements
- Assurance paradigm and approach: explains the assurance model, significance and causes of vulnerabilities, and how assurance is provided through evaluation.
- Evaluation assurance scale: establishes the framework used to map components into EALs and assurance packages.
- Assurance class structure: organizes components into classes and families with clear naming, introductions and application notes.
- Assurance family and component structure: defines family objectives, component levelling, dependencies, application guidance and component identification.
- Assurance elements: the low‑level building blocks that form components and support consistent evaluation evidence.
- Component taxonomy and levelling: provides a consistent taxonomy and levels for tailoring assurance requirements to different evaluation scopes.
- Evaluation criteria for PPs, PP‑Modules, PP‑Configurations and STs: includes classes such as APE (Protection Profile evaluation), ACE (PP‑Module/Configuration evaluation) and ASE (Security Target evaluation) with specific component objectives (e.g., introductions, conformance claims, problem definitions, objectives, requirements and consistency checks).
Applications
- Developing and writing Protection Profiles (PPs), PP‑Modules and Security Targets (STs) that meet internationally recognized assurance criteria.
- Structuring product or system evaluations for certification against Common Criteria and demonstrating appropriate assurance to customers or regulators.
- Designing security assurance packages and mapping assurance evidence to evaluation assurance levels (EALs) for procurement or compliance.
- Informing secure product development lifecycle practices where formal assurance evidence is required.
Who uses this standard
- Certification bodies and evaluation laboratories performing Common Criteria evaluations
- Product vendors and system integrators preparing PPs or STs
- Security architects, assurance engineers and QA teams producing evaluation evidence
- Procurement officers and compliance teams specifying assurance requirements
- Regulators and auditors assessing security claims
Related standards
- ISO/IEC 15408 series (Common Criteria) - Parts 1, 2 and 5 are directly related
- ISO/IEC 15408-5 (assurance packages and EAL composition) - referenced by this part
ISO/IEC 15408-3:2022 is essential for anyone involved in formal IT security evaluation, providing the detailed assurance component definitions needed to achieve repeatable, auditable cybersecurity and privacy assurance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-3:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO/IEC 15408-5:2026
ДействующийInformation security, cybersecurity and privacy protection. Evaluation criteria for IT security. Pre-defined…
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…