SIST EN ISO/IEC 15408-5:2026
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 5: Pre-defined packages of security requirements (ISO/IEC 15408-5:2026)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 5: Pre-defined packages of security requirements (ISO/IEC 15408-5:2026)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 37
- Дата публикации:
- 18 июня 2026 г.
- Издание:
- ISO/IEC 15408-5:2026
- ICS:
- 35.030
This document provides packages of security assurance and security functional requirements that are intended to be useful in support of common usage by stakeholders. The users of this document can include consumers, developers and evaluators of secure IT products.
Abstract
Overview
SIST EN ISO/IEC 15408-5:2026 defines standardized packages of security assurance and security functional requirements for information security, cybersecurity, and privacy protection in IT systems. As Part 5 of the widely recognized ISO/IEC 15408 (Common Criteria) series, this standard is designed to streamline and harmonize the evaluation of IT security by providing pre-defined packages that can be directly referenced by stakeholders. These packages are crafted to support common usage in Protection Profiles (PPs), Security Targets (STs), and other evaluation contexts, simplifying the complex task of specifying and assessing security requirements.
The standard is highly relevant for a broad range of users, including:
- Consumers seeking to compare and select secure IT products,
- Developers aiming to meet established security requirements,
- Evaluators performing systematic security assessments.
Key Topics
SIST EN ISO/IEC 15408-5:2026 organizes security requirements into logical families of packages for ease of reference and application:
- Evaluation Assurance Levels (EAL): A set of ascending assurance levels that reflect increasing rigor in IT security evaluation, from functionally tested (EAL1) up to formally verified and tested (EAL7).
- Composed Assurance Packages (CAP): Packages designed for evaluating the security of systems composed of multiple elements or products.
- Composite Product Packages (COMP): Requirements packages supporting assessment of composite IT products.
- Protection Profile Assurances (PPA): Packages that standardize the evaluation process for Protection Profiles, ensuring repeatability and consistency.
- Security Target Assurances (STA): Packages for Security Target evaluation, guiding the requirements for security claims in IT products.
These pre-defined packages help stakeholders align with recognized international best practices, promoting interoperability, transparency, and uniform assurance in IT security evaluation.
Applications
The practical applications of SIST EN ISO/IEC 15408-5:2026 span multiple domains within IT security management and product development:
- Security Specification: Developers can efficiently specify the security functionality and assurance of their products using pre-defined packages, reducing time and uncertainty.
- Procurement and Vendor Assessment: Consumers and organizations can reference standardized packages when procuring secure IT solutions, ensuring baseline compliance and facilitating clear comparisons between offerings.
- Regulatory Compliance: Evaluators and regulators can rely on pre-defined packages to ensure consistent, transparent, and repeatable security assessments.
- Protection Profile and Security Target Development: Organizations developing PPs and STs benefit from the structured approach, minimizing effort and errors in defining appropriate security requirements.
- Product Certification: IT products evaluated and certified against the requirements in this standard can offer stronger assurance to end-users, supporting market confidence and global acceptance.
Related Standards
SIST EN ISO/IEC 15408-5:2026 is part of the ISO/IEC 15408 (Common Criteria) series, which collectively underpin IT security evaluation worldwide. Related standards include:
- ISO/IEC 15408-1: Introduction and general model for IT security evaluation criteria.
- ISO/IEC 15408-2: Security functional components specification.
- ISO/IEC 15408-3: Security assurance components and detailed assurance requirements.
These standards offer a comprehensive framework for developing, evaluating, and procuring secure IT products, with Part 5 delivering structured packages that support efficiency and global harmonization in the application of security evaluation criteria.
Keywords: Information security, cybersecurity, privacy protection, evaluation criteria, IT security, assurance packages, Common Criteria, security requirements, standardized packages, ISO/IEC 15408-5.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO/IEC 15408-5:2026
Похожие стандарты
Стандарты, упомянутые в описании