ISO/IEC TR 22216:2022
Information security, cybersecurity and privacy protection — New concepts and changes in ISO/IEC 15408:2022 and ISO/IEC 18045:2022
Information security, cybersecurity and privacy protection — New concepts and changes in ISO/IEC 15408:2022 and ISO/IEC 18045:2022
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 46
- Дата публикации:
- 17 мая 2022 г.
- Издание:
- ISO/IEC TR 22216 edition 1 version 1
- ICS:
- 35.030
This document: — introduces the break down between the former ISO/IEC 15408 series (ISO/IEC 15408-1:2009, ISO/IEC 15408-2:2008) and ISO/IEC 15408-3:2008) and ISO/IEC 18045:2008 and the new parts introduced in the ISO/IEC 15408:2022 series and ISO/IEC 18045:2022; — presents the concepts newly introduced as well as the rationale for their inclusion; — proposes an evolution path and information on how to move from CC 3.1 and CEM 3.1 to the ISO/IEC 15408:2022 series and ISO/IEC 18045:2022, respectively; — maps the evolutions between the CC 3.1 and CEM 3.1 and the ISO/IEC 15408:2022 series and ISO/IEC 18045:2022, respectively.
Abstract
Overview
ISO/IEC TR 22216:2022 is a technical report from ISO/IEC JTC 1/SC 27 that explains the new concepts and changes introduced in the revised evaluation standards ISO/IEC 15408:2022 and ISO/IEC 18045:2022. The report summarizes how the earlier Common Criteria (CC 3.1) and Common Evaluation Methodology (CEM 3.1) maps to the new document structure, presents the rationale for newly introduced concepts, and proposes an evolution path for organizations and evaluators migrating from CC 3.1/CEM 3.1 to the 2022 series.
Key Topics
- Structure and mapping: Clarifies the break-down of the former ISO/IEC 15408 series and ISO/IEC 18045:2008 into the new parts of ISO/IEC 15408:2022 and ISO/IEC 18045:2022, and provides transition guidance.
- New evaluation approaches: Describes the two primary approaches - attack-based and specification-based evaluation - and their application to security and privacy assessments.
- Modularity and composition: Introduces modular concepts such as composition mechanisms, packages, PP‑Modules (modular Protection Profiles) and PP‑Configurations, enabling reuse and scalable assurance for complex products and systems.
- Multi‑assurance evaluations: Covers evaluation by composition, multi-assurance TOEs, and methods to support multiple assurance needs across components.
- Refinement and derivation: Guidance on refining and deriving security requirements and evaluation methods (refinements, application notes, extended requirements).
- Transitional mapping: Detailed tables and figures mapping CC 3.1/CEM 3.1 constructs (PP, ST, TOE) to the ISO/IEC 15408:2022 series equivalents to support a smooth migration.
Applications
ISO/IEC TR 22216:2022 is practical for:
- Evaluators and certification labs preparing to assess products under the ISO/IEC 15408:2022 and ISO/IEC 18045:2022 frameworks.
- Security vendors and product developers designing TOEs, Protection Profiles, or modular components intended for evaluation and mutual recognition.
- Procurement and risk owners who need to specify assurance requirements and understand evaluation scope for complex systems (IoT gateways, mobile devices, composite TOEs).
- Standards bodies and accreditation organizations coordinating transition from CC 3.1/CEM 3.1 to the updated series.
Who should use it
- Security architects, evaluation authorities, conformity assessment bodies, product developers, and procurement specialists involved in information security, cybersecurity, and privacy protection assurance and certification.
Related standards
- ISO/IEC 15408:2022 (new Common Criteria series)
- ISO/IEC 18045:2022 (evaluation methodology)
- CC 3.1 and CEM 3.1 (previous Common Criteria and CEM editions)
- Common Criteria Recognition Arrangement (CCRA) and SOG‑IS MRA (context for mutual recognition)
Keywords: ISO/IEC TR 22216:2022, ISO/IEC 15408:2022, ISO/IEC 18045:2022, Common Criteria, cybersecurity, information security, protection profiles, attack-based evaluation, specification-based evaluation, modularity, multi-assurance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC TR 22216:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…