ISO/IEC TS 9569:2023
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Patch Management Extension for the ISO/IEC 15408 series and ISO/IEC 18045
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Patch Management Extension for the ISO/IEC 15408 series and ISO/IEC 18045
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 36
- Дата публикации:
- 28 ноября 2023 г.
- Издание:
- ISO/IEC TS 9569 edition 1 version 1
- ICS:
- 35.030
This document specifies patch management (PAM) security assurance requirements and is intended to be used as an extension of the ISO/IEC 15408 series and ISO/IEC 18045. The security assurance requirements specified in this document do not include evaluation or test activities on the final target of evaluation (TOE), but focus on the initial TOE and on the life cycle processes used by manufacturers. Additionally, this document gives guidance to facilitate the evaluation of the TOE, including the patch and development processes which support the patch management. This document lists options for evaluation authorities (or mutual recognition agreements) on how to utilize the additional assurance and additional evidence in their processes to enable the developer to consistently re-certify their updated or patched TOEs to the benefit of the users. The implementation of these options using an evaluation scheme is out of the scope of this document.
Abstract
Overview
ISO/IEC TS 9569:2023 - "Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Patch Management Extension for the ISO/IEC 15408 series and ISO/IEC 18045" - is a technical specification that extends Common Criteria evaluation practices to cover patch management (PAM). It provides security assurance requirements focused on the initial target of evaluation (TOE) and the product life‑cycle processes used by manufacturers, and gives evaluators guidance to assess patch and development processes that support ongoing patching. The document does not prescribe test activities on the final, patched TOE; instead it enables assurance through lifecycle evidence and process evaluation.
Key topics and requirements
- Definition of a new patch management assurance family (ALC_PAM) aligned with the ISO/IEC 15408 structure, including objectives, component levelling and application notes.
- Evaluation work units for patch management (e.g., ALC_PAM.1 and associated actions) to guide how evidence and assurance are collected during initial evaluation.
- Guidance for evaluators across assurance classes (ASE, ADV, AGD, ALC, ATE, AVA) to incorporate patch‑related evidence into existing Common Criteria assessments.
- Practical artifacts and aids contained in annexes:
- Annex A: options for evaluation authorities and scheme implementation approaches.
- Annex B: template for a security relevance report.
- Annex C / D: examples of patch management documentation and a functional package.
- Terminology and lifecycle concepts such as activation, final TOE, end‑of‑support, and how assurance continuity can be maintained when patches are issued.
Applications and who should use it
ISO/IEC TS 9569:2023 is intended for:
- Evaluation authorities and certification bodies looking to adopt standardized methods for assessing vendor patch processes and enabling more efficient re‑certification of patched products.
- Product developers and manufacturers who need to demonstrate robust patch management processes (design, distribution, activation, and lifecycle support) to support assurance continuity.
- Security architects, vulnerability management teams and procurement officers who require standardized assurance evidence when acquiring or operating IT products.
- Mutual recognition arrangements (e.g., Common Criteria Recognition) seeking options to harmonize how patched TOEs are handled across schemes.
Practical benefits include reducing re‑certification effort for patched products, improving transparency of vendor processes, and strengthening assurance that lifecycle patching preserves security properties.
Related standards
- ISO/IEC 15408 (Common Criteria for IT security evaluation) - baseline evaluation framework extended by this TS.
- ISO/IEC 18045 - evaluation methodology referenced and complemented by this technical specification.
Keywords: ISO/IEC TS 9569:2023, patch management, ALC_PAM, Common Criteria, ISO/IEC 15408, ISO/IEC 18045, TOE evaluation, security assurance, patch lifecycle.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC TS 9569:2023
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…