ISO/IEC 19896-1:2025
Information security, cybersecurity and privacy protection — Requirements for the competence of IT security conformance assessment body personnel — Part 1: Overview and concepts
Information security, cybersecurity and privacy protection — Requirements for the competence of IT security conformance assessment body personnel — Part 1: Overview and concepts
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 12
- Дата публикации:
- 19 ноября 2025 г.
- Издание:
- ISO/IEC IS 19896 edition 2 version 1
- ICS:
- 35.030
This document establishes an organized set of concepts and relationships to understand the competency requirements for information security conformance-testing and evaluation specialists, thereby establishing a basis for shared understanding of the concepts and principles central to the ISO/IEC 19896 series across its user communities.
Abstract
Overview
ISO/IEC 19896-1:2025 - Information security, cybersecurity and privacy protection - Requirements for the competence of IT security conformance assessment body personnel - Part 1: Overview and concepts - defines the foundational concepts and relationships needed to understand competency requirements for personnel involved in IT security conformance testing, evaluation, validation and review. This second edition (2025) reorganizes and updates the framework used across the ISO/IEC 19896 series to establish a shared vocabulary and conceptual basis for assessing information security competence.
Key topics and requirements
- Scope and purpose: Sets an organized set of concepts to support consistent interpretation of competence requirements across the ISO/IEC 19896 series.
- Terms and definitions: Standardized definitions for roles and concepts such as competence, conformance‑tester, evaluator, validator, reviewer, evaluation laboratory, knowledge, and skill.
- Conceptual framework: Relationships among competence elements and how competence supports conformity in testing and evaluation processes.
- Elements of competence: Focus on knowledge and skills as measurable elements (experience and education clauses were removed or revised in this edition).
- Competency levels: Defined competency levels (1–3) for testers and evaluators and for validators and reviewers, with level descriptions to support personnel classification.
- Measurement and recording: Guidance on measuring knowledge and skills and on recording elements of competence; includes example records and a framework for describing requirements (Annex A and Annex B).
- Informative annexes: Annex A - framework for describing competence requirements; Annex B - example records of experience and competence.
Applications and users
ISO/IEC 19896-1:2025 is intended for organizations and professionals involved in IT product security assessment and conformance activities, including:
- Evaluation laboratories and testing laboratories (e.g., ITSEFs, CCTLs)
- Validation authorities and review bodies that issue validation certificates or review evaluation results
- Conformance testers, evaluators, validators, and reviewers seeking to align skills and knowledge with international practice
- Vendors and technology providers preparing products for conformance testing or evaluation
- Organizations offering professional credentials for cybersecurity assessment personnel
Practical uses include defining job profiles, structuring training and certification programs, establishing personnel competency matrices, and harmonizing assessment practices across jurisdictions.
Related standards
- ISO/IEC 19896 series (Parts 2 and 3) - role-specific minimum competence requirements
- ISO/IEC 19790 and ISO/IEC 24759 - conformance-testing examples referenced for validators/testers
- ISO/IEC 15408 and ISO/IEC 18045 - evaluation and review contexts referenced for evaluators/reviewers
- Cross-references: ISO/IEC 17024, ISO/IEC TS 17027, ISO/IEC TS 23532-1
Keywords: ISO/IEC 19896-1:2025, information security competence, IT security conformance, cybersecurity personnel competence, evaluation laboratory, competency levels, validators and reviewers.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19896-1:2025
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO/IEC 19896-1:2025
ДействующийInformation security, cybersecurity and privacy protection — Requirements for the competence of IT security c…
BS EN ISO/IEC 19790:2020
ДействующийInformation technology. Security techniques. Security requirements for cryptographic modules.
BS ISO/IEC 24759:2025
ДействующийInformation security, cybersecurity and privacy protection. Test requirements for cryptographic modules.
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO/IEC 17024:2012
ОтменёнConformity assessment — General requirements for bodies operating certification of persons
Overview ISO/IEC 17024:2012 - "Conformity assessment - General requirements for bodies operating certification of persons" - defines principles and requirements for organizations that certify people…