ISO/IEC 19896-3:2018
IT security techniques — Competence requirements for information security testers and evaluators — Part 3: Knowledge, skills and effectiveness requirements for ISO/IEC 15408 evaluators
IT security techniques — Competence requirements for information security testers and evaluators — Part 3: Knowledge, skills and effectiveness requirements for ISO/IEC 15408 evaluators
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 33
- Дата публикации:
- 24 августа 2018 г.
- Издание:
- ISO/IEC IS 19896 edition 1 version 1
- ICS:
- 35.030
This document provides the specialized requirements to demonstrate competence of individuals in performing IT product security evaluations in accordance with ISO/IEC 15408 (all parts) and ISO/IEC 18045.
Abstract
Overview
ISO/IEC 19896-3:2018 - “IT security techniques - Competence requirements for information security testers and evaluators - Part 3” - defines the specialized knowledge, skills and effectiveness requirements for individuals performing IT product security evaluations in accordance with ISO/IEC 15408 (the Common Criteria) and ISO/IEC 18045 (evaluation methodology). The standard establishes a baseline for demonstrable competence to support comparability, repeatability and mutual recognition of security evaluation results.
Key technical topics and requirements
The standard focuses on evaluator competence across the following areas:
-
Knowledge
- Mastery of ISO/IEC 15408 (all parts) and ISO/IEC 18045 terminology, framework and processes.
- Understanding the assurance paradigm, evaluation authorities and evaluation schemes.
- Information security principles, threats, vulnerabilities and architectural considerations.
- Technology-specific knowledge (product architectures, protection profiles, packages).
- Knowledge aligned to assurance classes (e.g., development, guidance, lifecycle, tests, vulnerability assessment) and functional requirement classes (e.g., cryptographic support).
-
Skills
- Basic and core evaluation skills: evaluation methods, use of evaluation tools, test planning and execution.
- Class-specific skills tied to ADV, AGD, ALC, ASE/APE, ATE, AVA, ACO and other assurance activities.
- Test design, test management and application of ISO/IEC 18045 evaluation methods.
-
Experience & Education
- Requirements for demonstrable experience and appropriate education to support competence (aligned with ISO/IEC 19896-1 and ISO/IEC 17025 principles).
-
Effectiveness
- Metrics and expectations for timely, accurate, and well-reported evaluations.
- Roles and responsibilities of evaluation schemes and authorities in ensuring evaluator effectiveness.
The standard includes informative annexes with technology-type guidance and examples of required knowledge for assurance and functional requirement classes.
Practical applications and users
ISO/IEC 19896-3:2018 is used to:
- Define minimum competence criteria for hiring and training information security evaluators.
- Support evaluation schemes, certification and accreditation bodies in setting evaluator credentialing policies.
- Guide testing laboratories and evaluation authorities in implementing consistent assessor competency programs.
- Help organizations and product vendors understand the competencies applied during Common Criteria evaluations to improve product preparedness.
Target users include evaluation authorities, certification/validation bodies, accreditation agencies, testing laboratories, evaluator professionals and organizations offering professional credentials.
Related standards
- ISO/IEC 15408 (Common Criteria) - Evaluation criteria for IT security
- ISO/IEC 18045 - Methodology for IT security evaluation
- ISO/IEC 19896-1 - General competence concepts and requirements
- ISO/IEC 17025 - Competence of testing and calibration laboratories
Keywords: ISO/IEC 19896-3:2018, ISO/IEC 15408, ISO/IEC 18045, information security evaluator, competence requirements, security evaluation, testing laboratories, evaluation schemes, Common Criteria.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19896-3:2018
Похожие стандарты
Стандарты, упомянутые в описании