ISO/IEC 19896-1:2018
IT security techniques — Competence requirements for information security testers and evaluators — Part 1: Introduction, concepts and general requirements
IT security techniques — Competence requirements for information security testers and evaluators — Part 1: Introduction, concepts and general requirements
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 11
- Дата публикации:
- 1 марта 2018 г.
- Издание:
- ISO/IEC IS 19896 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 19896-1:2018 defines terms and establishes an organized set of concepts and relationships to understand the competency requirements for information security assurance conformance-testing and evaluation specialists, thereby establishing a basis for shared understanding of the concepts and principles central to the ISO/IEC 19896 series across its user communities. It provides fundamental information to users of the ISO/IEC 19896 series.
Abstract
Overview
ISO/IEC 19896-1:2018 - part of the ISO/IEC 19896 series - provides the foundational concepts, terms and general requirements for defining competence requirements for information security testers and evaluators. It establishes a common framework and vocabulary to describe the knowledge, skills, experience, education and effectiveness needed by professionals who perform IT product security conformance testing and evaluations. The standard is intended to support consistent, repeatable assessment outcomes and mutual recognition of security assurance results across laboratories and approval authorities.
Key Topics and Requirements
- Terms and definitions: Clarifies essential vocabulary (competence, conformance-tester, evaluator, knowledge, skill, experience, effectiveness, laboratory).
- Concepts: Explains why minimum competence matters for conformity, repeatability and mutual recognition in IT security testing and evaluation.
- Elements of competence: Defines the components used to assess competence:
- Knowledge (e.g., relevant assurance standards, testing/evaluation methods, policies, IT product architecture)
- Skills (task-specific abilities)
- Experience (practical project involvement)
- Education (formal instruction)
- Effectiveness (behavioural attributes such as communication, initiative, teamwork, leadership)
- Competency levels: Describes a structured progression of competence (Level 1 Associate, Level 2 Professional, Level 3 Manager, Level 4 Principal) to align responsibilities and expected capabilities.
- Measurement and records: Guidance for assessing and recording elements of competence (knowledge, skills, experience, education, effectiveness) to support laboratory personnel management and accreditation.
- Supporting annexes: Informative frameworks and example records to help implement competence descriptions and evidence.
Applications and Users
ISO/IEC 19896-1:2018 is practical for organizations and professionals involved in IT security assurance and conformance testing:
- Information security testers and evaluators seeking a baseline for professional competence.
- Testing and evaluation laboratories (ITSEFs, CCTLs, CLEFs) developing personnel competence policies and records.
- Approval authorities and accreditation bodies that assess laboratory personnel competence and conformity.
- Vendors and technology providers preparing products for security evaluation and wanting to understand tester qualifications.
- Credentialing organizations designing recognition schemes for security-testing professionals.
Adopting this standard helps organizations align personnel qualifications with recognized competence levels, improve repeatability of test results, and strengthen trust in IT product security assurance.
Related Standards
- ISO/IEC 17025 (competence of testing laboratories) - referenced as a basis for laboratory competence requirements.
- ISO/IEC 19790 and ISO/IEC 24759 - related to conformance testing covered in subsequent parts of the 19896 series.
- ISO/IEC 15408 and ISO/IEC 18045 - evaluation standards referenced in later parts for evaluators.
Keywords: ISO/IEC 19896-1:2018, competence requirements, information security testers, information security evaluators, conformance testing, IT security techniques, competency levels, laboratory accreditation.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19896-1:2018
Похожие стандарты
Стандарты, упомянутые в описании