Overview
ISO/IEC 15408-5:2026 is an international standard published by ISO and IEC focused on information security, cybersecurity, and privacy protection within IT environments. Officially titled "Evaluation criteria for IT security - Part 5: Pre-defined packages of security requirements," this standard provides structured packages of security assurance and functional requirements. These packages are specifically designed to support common use by stakeholders such as consumers, developers, and evaluators of secure IT products.
By establishing pre-defined sets of requirements, ISO/IEC 15408-5 facilitates consistency in IT security evaluations and streamlines the process of developing Protection Profiles (PPs) and Security Targets (STs). This helps ensure that products meet recognized levels of trust and allows for more efficient and comparable security assessments across the industry.
Key Topics
-
Pre-defined Security Packages: The standard introduces several families of assurance packages, including:
- Evaluation Assurance Levels (EAL): Structured sets of assurance requirements covering different levels of rigour and depth in evaluation, from basic (EAL1) to high assurance (EAL7).
- Composed Assurance Packages (CAP): Packages focused on evaluating composite systems, supporting composed IT environments.
- Composite Product Packages (COMP): Requirement sets for composite products, guaranteeing integrated and coherent assurance.
- Protection Profile Assurances (PPA): Packages for evaluating Protection Profiles themselves.
- Security Target Assurances (STA): Packages used to evaluate Security Targets.
-
Objective of Assurance Packages: Each pre-defined package combines assurance components to meet specific assurance objectives, balancing the degree of confidence in IT product security with cost and feasibility.
-
Augmentation: Packages, especially EALs, can be augmented with additional assurance components to tailor evaluations to particular security needs.
-
Terminology and Structure: The standard uses precise terminology as defined in foundational parts of the ISO/IEC 15408 series and maintains alignment with international evaluation criteria.
Applications
ISO/IEC 15408-5:2026 is used extensively in the field of IT product evaluation, providing practical value for multiple stakeholder groups:
- Product Developers: Can reference pre-defined packages to streamline design, documentation, and testing processes, ensuring their products meet specific industry-recognized assurance levels.
- Consumers and Procurement Specialists: Use the standard to specify security requirements during acquisition, ensuring chosen IT products deliver the required level of trust and protection.
- Evaluators and Certification Bodies: Leverage the standardized packages to guide objective, repeatable, and internationally recognized evaluation processes.
Common Use Cases:
- Development of Protection Profiles and Security Targets using standardized assurance packages.
- Selection of suitable Evaluation Assurance Levels (EAL1–EAL7) for government or industry procurement policies.
- Assessment of composite or integrated IT solutions, using composed and composite product packages to reflect complex security needs.
- Validation or audit of security claims in regulatory compliance and conformance schemes.
Related Standards
ISO/IEC 15408-5:2026 is part of the broader ISO/IEC 15408 series on IT security evaluation criteria. Related standards include:
These standards collectively establish the Common Criteria framework, which is fundamental to international IT product security evaluation and certification.
Conclusion
By providing clear, pre-defined security requirement packages, ISO/IEC 15408-5:2026 greatly enhances the efficiency, comparability, and reliability of information security, cybersecurity, and privacy protection evaluations. Its practical guidance helps organizations achieve more consistent security evaluations, supports compliance needs, and fosters greater confidence in IT product security on a global scale.