Overview
EN ISO/IEC 15408-1:2026 is an international standard published by CEN, titled "Information security, cybersecurity and privacy protection – Evaluation criteria for IT security – Part 1: Introduction and general model." This standard establishes the foundational concepts and principles for evaluating information technology (IT) security. As the introductory document in the ISO/IEC 15408 series, it outlines key terminology, core concepts such as the Target of Evaluation (TOE), and the general context for IT security evaluations.
The standard provides a comprehensive overview of the entire ISO/IEC 15408 family, often referred to as the Common Criteria (CC), which is widely recognized for structuring IT security assessment and certification practices globally. The main focus is to facilitate comparable, consistent, and reliable evaluation results for IT products, thereby enhancing trust in digital systems and helping organizations ensure robust cybersecurity and privacy protection.
Key Topics
- General Model for IT Security Evaluation
- Establishes the concept of a Target of Evaluation (TOE)
- Defines TOE boundaries, representations, and operational contexts
- Terminology and Abbreviations
- Standardizes language for effective communication across all ISO/IEC 15408 parts
- Evaluation Context and Audience
- Describes who uses the criteria (product developers, evaluators, and procurement bodies)
- Identifies suitable applications and stakeholders for the evaluation process
- Security Concepts Introduction
- Explains basic principles such as confidentiality, integrity, and availability
- Introduces methods for specifying and justifying security requirements
- Overview of Series Structure
- Summarizes links to further parts describing security functional requirements and assurance requirements
Applications
The EN ISO/IEC 15408-1:2026 standard is invaluable for:
- IT Product Developers: Guidance on designing products with strong, certifiable information security measures that meet international evaluation requirements.
- Security Evaluators: Provides the methodology and context to conduct systematic and repeatable evaluations of software, hardware, and integrated systems.
- Procurement Professionals and Risk Owners: Helps organizations define procurement criteria, select secure IT products, and interpret security evaluation results to ensure products align with organizational security policies and risk management strategies.
- Regulatory Bodies: Creates a harmonized framework for referencing in national or sectoral cybersecurity regulations.
By using this common framework, organizations can:
- Facilitate procurement of trustworthy IT products for sensitive applications
- Support compliance with international cybersecurity and privacy standards
- Foster interoperability and comparability of security evaluations across different jurisdictions
Related Standards
EN ISO/IEC 15408-1:2026 is the first in the family of ISO/IEC 15408 standards. Other closely related standards include:
- ISO/IEC 15408-2: Covers security functional requirements for IT products
- ISO/IEC 15408-3: Details security assurance requirements
- ISO/IEC 18045: Provides specific guidance for the evaluation process itself
- ISO/IEC 27001: Specifies requirements for information security management systems (ISMS)
- ISO/IEC 27002: Offers guidelines for information security controls
These standards collectively support a robust approach to IT security evaluation, helping organizations achieve greater confidence in their cyber-resilience strategies amidst evolving threats.
Keywords: ISO/IEC 15408-1:2026, IT security evaluation, information security, cybersecurity, privacy protection, Common Criteria, CEN standard, Target of Evaluation (TOE), security requirements, international standards.