ISO/IEC 15408-5:2022
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 5: Pre-defined packages of security requirements
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 5: Pre-defined packages of security requirements
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 27
- Дата публикации:
- 9 августа 2022 г.
- Издание:
- ISO/IEC IS 15408 edition 1 version 1
- ICS:
- 35.030
This document provides packages of security assurance and security functional requirements that have been identified as useful in support of common usage by stakeholders. EXAMPLE Examples of provided packages include the evaluation assurance levels (EAL) and the composed assurance packages (CAPs). This document presents: — evaluation assurance level (EAL) family of packages that specify pre-defined sets of security assurance components that may be referenced in PPs and STs and which specify appropriate security assurances to be provided during an evaluation of a target of evaluation (TOE); — composition assurance (CAP) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during an evaluation of composed TOEs; — composite product (COMP) package that specifies a set of security assurance components used for specifying appropriate security assurances to be provided during an evaluation of a composite product TOEs; — protection profile assurance (PPA) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during a protection profile evaluation; — security target assurance (STA) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during a security target evaluation. The users of this document can include consumers, developers, and evaluators of secure IT products.
Abstract
Overview
ISO/IEC 15408-5:2022 is Part 5 of the Common Criteria family for information security, cybersecurity and privacy protection. It defines pre‑defined packages of security assurance and security functional requirements that stakeholders commonly use when specifying or evaluating IT products (Targets of Evaluation, TOEs). The standard supplies ready‑made assurance packages - including Evaluation Assurance Levels (EALs), Composed Assurance Packages (CAPs), a Composite Product (COMP) package, and assurance families for Protection Profiles (PPA) and Security Targets (STA) - to streamline, harmonize and make evaluations more predictable.
Key topics and requirements
- Evaluation Assurance Levels (EAL1–EAL7): a scale of assurance where each EAL specifies a pre‑defined set of assurance components.
- EAL1 - Functionally tested
- EAL2 - Structurally tested
- EAL3 - Methodically tested and checked
- EAL4 - Methodically designed, tested and reviewed
- EAL5 - Semi‑formally verified design and tested
- EAL6 - Semi‑formally verified design and tested (higher rigor)
- EAL7 - Formally verified design and tested
- Composed Assurance Packages (CAPs): packages tailored for systems composed of multiple components or subsystems. Examples in the standard:
- CAP A - Structurally composed
- CAP B - Methodically composed
- CAP C - Methodically composed, tested and reviewed
- Composite Product (COMP) package: defines assurance components for evaluating composite products made from independently evaluated parts.
- PPA & STA families: predefined assurance sets for Protection Profile and Security Target evaluations, including direct rationale and standard package variants.
- Normative links: aligns with ISO/IEC 15408‑1 (general model) and ISO/IEC 15408‑3 (assurance components).
Applications and who uses it
- Procurement officers / consumers: specify required EALs or CAPs in RFPs to ensure predictable assurance levels.
- Product developers: use packages to design evidence and processes that meet an intended assurance level, reducing development and evaluation effort.
- Evaluation labs / certifiers: apply the predefined packages to assess TOEs consistently against Common Criteria expectations.
- PP and ST authors: leverage PPA/STA packages to simplify and harmonize requirement sets for profiles and targets.
Related standards
- ISO/IEC 15408‑1:2022 - Introduction and general model (normative)
- ISO/IEC 15408‑3:2022 - Security assurance components (normative)
- Common Criteria (CC) material referenced by national certification schemes
Using ISO/IEC 15408-5:2022 helps organizations standardize assurance claims, reduce duplicated effort when creating Protection Profiles and Security Targets, and increase comparability of security evaluations across vendors and evaluators. Keywords: ISO/IEC 15408-5:2022, Common Criteria, EAL, CAP, composite product, protection profile, security target, cybersecurity, security assurance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-5:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO/IEC 15408-1:2026
ДействующийInformation security, cybersecurity and privacy protection. Evaluation criteria for IT security. Introduction…
BS EN ISO/IEC 15408-3:2026
ДействующийInformation security, cybersecurity and privacy protection. Evaluation criteria for IT security. Security ass…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…