ISO/IEC 19896-3:2025
Information security, cybersecurity and privacy protection — Requirements for the competence of IT security conformance assessment body personnel — Part 3: Knowledge and skills requirements for evaluators and reviewers according to the ISO/IEC 15408 series and ISO/IEC 18045
Information security, cybersecurity and privacy protection — Requirements for the competence of IT security conformance assessment body personnel — Part 3: Knowledge and skills requirements for evaluators and reviewers according to the ISO/IEC 15408 series and ISO/IEC 18045
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 46
- Дата публикации:
- 19 ноября 2025 г.
- Издание:
- ISO/IEC IS 19896 edition 2 version 1
- ICS:
- 35.030
This document provides the specialized requirements for individuals to demonstrate competence in performing IT product security evaluations and reviews according to the ISO/IEC 15408 series and ISO/IEC 18045. NOTE It is possible that evaluators and testers belong to bodies operating under ISO/IEC 17025 and reviewers belong to bodies operating under ISO/IEC 17065.
Abstract
Overview - ISO/IEC 19896-3:2025 (Knowledge & Skills for Evaluators and Reviewers)
ISO/IEC 19896-3:2025 defines the knowledge and skills requirements for personnel who perform IT product security evaluations and reviews according to the ISO/IEC 15408 series (Common Criteria) and ISO/IEC 18045 (CEM). This part of the ISO/IEC 19896 series establishes a baseline competence profile to promote comparable, repeatable evaluation results and support mutual recognition among evaluation schemes. It covers specialist requirements for both evaluators and reviewers, and complements broader competence concepts in ISO/IEC 19896-1.
Key technical topics and requirements
- Scope of competence: Detailed knowledge and practical skills that evaluators and reviewers must demonstrate to assess Targets of Evaluation (TOEs) against Common Criteria criteria.
- Knowledge areas:
- The ISO/IEC 15408 series and ISO/IEC 18045 framework and terminology.
- The assurance paradigm, security assurance classes and functional components.
- Information security principles: threats, vulnerabilities, security properties.
- Technology-specific knowledge relevant to the evaluated product (technical domains).
- Information security testing techniques and test types.
- Skill areas:
- Basic and core evaluation/review skills (planning, interpreting security targets, assessment activities).
- Designing and executing TOE-specific tests and test plans.
- Skills for evaluating specific security assurance classes and security functional requirement classes.
- Review competencies for independent assessment of evaluation work products.
- Supporting materials and annexes: Informative annexes describe technology types, example knowledge/skills for assurance and functional requirement classes, and bibliography for further guidance.
- Conformity context: Recognizes that evaluators/testers may operate under ISO/IEC 17025 and reviewers may operate under ISO/IEC 17065.
Practical applications and who uses this standard
- Testing laboratory accreditation bodies - to define personnel competence criteria for accreditation of IT security evaluation labs.
- Evaluation scheme developers and conformity assessment bodies - to harmonize training and qualification programs for Common Criteria-based evaluations.
- Security evaluation laboratories and reviewers - to benchmark required knowledge, build job profiles, and design internal training.
- Professional credentialing organizations - to map certification schemes to internationally recognized competence requirements.
- Vendors and procurement teams - to understand the competence expected from independent evaluators who validate product security claims.
Related standards and references
- ISO/IEC 15408 series (Common Criteria) - Parts 1–5 (framework, functional & assurance components)
- ISO/IEC 18045 (Common Evaluation Methodology, CEM)
- ISO/IEC 19896-1 (Introduction and concepts for competence of assessment body personnel)
- ISO/IEC 17025 and ISO/IEC 17065 (relevant conformity assessment body frameworks)
Keywords: ISO/IEC 19896-3:2025, Common Criteria, ISO/IEC 15408, ISO/IEC 18045, evaluator competence, IT product security evaluation, security assurance, information security testing.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19896-3:2025
Похожие стандарты
Стандарты, упомянутые в описании