ISO/IEC 18045:2022
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Methodology for IT security evaluation
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Methodology for IT security evaluation
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 423
- Дата публикации:
- 9 августа 2022 г.
- Издание:
- ISO/IEC IS 18045 edition 3 version 1
- ICS:
- 35.030
This document defines the minimum actions to be performed by an evaluator in order to conduct an ISO/IEC 15408 series evaluation, using the criteria and evaluation evidence defined in the ISO/IEC 15408 series.
Abstract
Overview
ISO/IEC 18045:2022 - Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Methodology for IT security evaluation - defines the minimum actions an evaluator must perform to conduct evaluations against the ISO/IEC 15408 series (Common Criteria). It provides a structured methodology for assessing security functionality and assurance, detailing the evaluation process, required evidence, evaluator roles, and expected outputs such as evaluation verdicts and the Evaluation Technical Report (ETR).
Keywords: ISO/IEC 18045:2022, IT security evaluation, Common Criteria, evaluation methodology, ISO/IEC 15408.
Key topics and technical requirements
- Evaluation process and tasks: describes input, sub‑activities, and output tasks; role responsibilities; and the general evaluation model.
- Evaluator actions and evidence management: minimum required actions for collecting, managing and re‑using evaluation evidence in accordance with ISO/IEC 15408 criteria.
- Evaluator deliverables: guidance on preparing evaluation outputs including the ETR and other reports (e.g., write OR sub‑task, write ETR sub‑task).
- Protection Profile (PP) evaluation (Class APE): requirements for evaluating full PPs, including conformance claims, security problem definition, objectives, extended components, and security requirements.
- Protection Profile Configuration (Class ACE): evaluation of PP‑module content, consistency and configuration conformance.
- Security Target (ST) evaluation (Class ASE): criteria for assessing ST introduction, conformance claims, security problem definitions, objectives, extended components, security requirements, and TOE summary specification.
- Development class (Class ADV): sections addressing security architecture and development‑related evaluation activities.
- Evaluator verdicts and consistency checks: standardized verdicts and methods to determine conformity with ISO/IEC 15408 evidence and criteria.
Keywords: security target evaluation, protection profile, TOE, evaluation evidence, evaluator verdicts.
Practical applications and target users
- Independent evaluators and testing laboratories - to apply a standardized methodology when conducting Common Criteria evaluations.
- Certification bodies and accreditation authorities - to ensure consistent evaluation practices and to verify evaluator outputs (ETRs).
- Product vendors and developers - to understand evaluator expectations when seeking Common Criteria certification for a TOE (Target of Evaluation).
- Procurement teams and security architects - to interpret evaluation reports and select products with verified security claims.
- Government and regulated sectors - for acquiring assurance‑rated IT products in compliance with national or international certification schemes.
Keywords: cybersecurity, information security, privacy protection, assurance, Common Criteria evaluation.
Related standards
- ISO/IEC 15408 (Common Criteria) - primary set of security functional and assurance requirements that ISO/IEC 18045 operationalizes.
- ISO/IEC 18045 complements the ISO/IEC 15408 series by providing the evaluation methodology and minimum evaluator actions required for consistent, reproducible security evaluations.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 18045:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…