ISO/IEC TR 20004:2015
Information technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045
Information technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 17
- Дата публикации:
- 8 декабря 2015 г.
- Издание:
- ISO/IEC TR 20004 edition 2 version 1
- ICS:
- 35.030
ISO/IEC TR 20004:2015 refines the AVA_VAN assurance family activities defined in ISO/IEC 18045 and provides more specific guidance on the identification, selection and assessment of relevant potential vulnerabilities in order to conduct an ISO/IEC 15408 evaluation of a software target of evaluation. This Technical Report leverages publicly available information security resources to support the method of scoping and implementing ISO/IEC 18045 vulnerability analysis activities. The Technical Report currently uses the common weakness enumeration (CWE) and the common attack pattern enumeration and classification (CAPEC), but does not preclude the use of any other appropriate resources. Furthermore, this Technical Report is not meant to address all possible vulnerability analysis methods, including those that fall outside the scope of the activities outlined in ISO/IEC 18045. ISO/IEC TR 20004:2015 does not define evaluator actions for certain high assurance ISO/IEC 15408 components, where there is as yet no generally agreed guidance.
Abstract
Overview
ISO/IEC TR 20004:2015 is a Technical Report that refines software vulnerability analysis activities defined in ISO/IEC 18045 to support evaluations under ISO/IEC 15408 (Common Criteria). It provides focused guidance for identifying, selecting and assessing potential vulnerabilities in a software Target of Evaluation (TOE). The report leverages public information-security resources (notably CWE, CAPEC and CVE) to define an objective, repeatable approach for scoping and implementing the AVA_VAN assurance-family activities used in Common Criteria evaluations.
Key topics and requirements
- Refinement of AVA_VAN activities: clarifies evaluator actions for “Potential vulnerability identification from public sources” and “Penetration testing” across AVA_VAN levels (AVA_VAN.1–AVA_VAN.5).
- Use of structured vulnerability resources: recommends employing the Common Weakness Enumeration (CWE) and Common Attack Pattern Enumeration and Classification (CAPEC) to identify relevant weaknesses and attack patterns; use of other appropriate resources is permitted.
- Public-source searches: defines focus and extensiveness of searches in public domain sources (product-specific CVE data, vendor advisories, known attack patterns) as part of the vulnerability survey.
- Assessment of TOE susceptibility: guidance on designing, specifying, executing and documenting security/penetration testing based on identified potential vulnerabilities and expected attack potential.
- Reporting and evidence: requirements to record candidate vulnerabilities, test results and judgments about exploitability and residual vulnerabilities in the Evaluation Technical Report (ETR).
- Scope limitations: does not cover all vulnerability-analysis methods and does not define evaluator actions for certain high-assurance components where no consensus guidance exists.
Practical applications and users
- Common Criteria evaluators and certifiers use the report to standardize vulnerability identification and penetration testing for software TOEs.
- Product developers and secure-development teams can apply the structured CWE/CAPEC-based approach during development to build TOE-specific weakness/attack-pattern templates and reduce evaluation effort.
- Protection Profile (PP) and Security Target (ST) authors and technical communities benefit from clearer guidance on what constitutes a minimal set of relevant weaknesses for AVA_VAN activities.
- Security architects and QA teams can adopt the methodology to prioritize testing based on CVE/CWE/CAPEC mappings and documented attack potential.
Related standards and resources
- ISO/IEC 15408 (Common Criteria) - security functional and assurance requirements
- ISO/IEC 18045 - methodology for vulnerability analysis
- CWE, CAPEC, CVE - public vulnerability and attack pattern repositories referenced by the Technical Report
Keywords: ISO/IEC TR 20004:2015, vulnerability analysis, AVA_VAN, ISO/IEC 15408, ISO/IEC 18045, CWE, CAPEC, CVE, penetration testing, Common Criteria.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC TR 20004:2015
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…