ISO/IEC 15408-4:2022
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 4: Framework for the specification of evaluation methods and activities
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 4: Framework for the specification of evaluation methods and activities
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 16
- Дата публикации:
- 9 августа 2022 г.
- Издание:
- ISO/IEC IS 15408 edition 1 version 1
- ICS:
- 35.030
This document provides a standardized framework for specifying objective, repeatable and reproducible evaluation methods and evaluation activities. This document does not specify how to evaluate, adopt, or maintain evaluation methods and evaluation activities. These aspects are a matter for those originating the evaluation methods and evaluation activities in their particular area of interest.
Abstract
Overview
ISO/IEC 15408-4:2022 - part of the Common Criteria family - defines a framework for specifying evaluation methods and evaluation activities used in IT security, cybersecurity and privacy protection assessments. The standard focuses on how to describe objective, repeatable and reproducible evaluation methods and activities (EMs/EAs). It does not prescribe how to perform, adopt or maintain those methods - that responsibility lies with the originators in each domain.
Key topics and technical requirements
This part of ISO/IEC 15408 provides a structured model and clear specification elements for EMs and EAs, including:
- General model and derivation: mapping evaluator action elements and ISO/IEC 18045 work units to technology- or TOE-specific evaluation activities.
- Verb usage and conventions: standardized language to ensure clarity and consistent interpretation of activities.
- Structure of an evaluation method: required metadata such as identification, responsible entity, scope, dependencies, required developer inputs, required tool types, evaluator competences, reporting requirements and rationale.
- Structure of evaluation activities: unique ID, objective, links to SFRs (Security Functional Requirements) / SARs (Security Assurance Requirements) and other activities, inputs, tools, evaluator competences, assessment strategy, pass/fail criteria, reporting and rationale.
- Traceability: linking EAs to ISO/IEC 15408-3 SARs and ISO/IEC 18045 work units to ensure alignment with the Common Criteria model.
Applications and practical value
ISO/IEC 15408-4:2022 is practical for:
- Evaluation authorities and testing laboratories that must document and apply repeatable evaluation activities when assessing products.
- Protection Profile (PP) and Security Target (ST) authors who want to mandate or reference specific EMs/EAs for a TOE type (e.g., network device, cryptographic module).
- Vendors and developers preparing evidence and tool requirements specified by the EM/EA (required inputs, reporting format).
- Certification bodies and program managers requiring consistent, auditable evaluation outputs and evaluator competence definitions.
Benefits include improved comparability of evaluation results, clearer assessment strategies, standardized pass/fail criteria, and better alignment with ISO/IEC 18045 and other Common Criteria parts.
Related standards
- ISO/IEC 15408-1 - Introduction and general model (Common Criteria core)
- ISO/IEC 15408-2 - Security functional components (SFRs)
- ISO/IEC 15408-3 - Security assurance components (SARs)
- ISO/IEC 18045 - Methodology for IT security evaluation (work units mapped to EAs)
Keywords: ISO/IEC 15408-4:2022, evaluation methods, evaluation activities, Common Criteria, IT security evaluation, ISO/IEC 18045, SFRs, SARs, Protection Profile, Security Target, evaluator competences.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-4:2022
Похожие стандарты
Стандарты, упомянутые в описании