EN ISO/IEC 15408-5:2026 PDF
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 5: Pre-defined packages of security requirements (ISO/IEC 15408-5:2026)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 5: Pre-defined packages of security requirements (ISO/IEC 15408-5:2026)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 37
- Дата публикации:
- 6 мая 2026 г.
- Издание:
- CEN/CENELEC EN 15408 edition 2 version 1
- ICS:
- 35.030
This document provides packages of security assurance and security functional requirements that are intended to be useful in support of common usage by stakeholders. The users of this document can include consumers, developers and evaluators of secure IT products.
Abstract
Overview
EN ISO/IEC 15408-5:2026 - Information Security, Cybersecurity and Privacy Protection – Evaluation Criteria for IT Security – Part 5: Pre-defined Packages of Security Requirements defines sets of pre-defined security assurance and functional requirements for IT products. These packages are designed to support common use cases among stakeholders such as consumers, developers, and evaluators, streamlining security specification and assessment processes aligned with international best practices.
This standard is part of the ISO/IEC 15408 series, which is widely recognized as the Common Criteria for Information Technology Security Evaluation. EN ISO/IEC 15408-5:2026 specifically focuses on providing ready-to-use collections of requirements, known as packages, to promote consistency, efficiency, and comparability in IT product security evaluations.
Key Topics
- Pre-defined Security Requirement Packages: Offers readily assembled sets of assurance and functional requirements that can be integrated into security specifications.
- Evaluation Assurance Levels (EAL): Describes a hierarchy of assurance packages, each corresponding to a different rigor and depth of evaluation, from basic functionally tested (EAL1) up to formally verified design and tested (EAL7).
- Composed Assurance Packages (CAP): Details packages meant for evaluating composed or integrated Target of Evaluations (TOEs), facilitating modular and layered security assessments.
- Composite Product Packages (COMP): Specifies security requirements relevant for complex, integrated products.
- Assurances for Protection Profiles (PPA) and Security Targets (STA): Outlines pre-defined packages for use in the development and evaluation of Protection Profiles and Security Targets, which are foundational elements in the Common Criteria framework.
- Stakeholder Support: Meets the needs of IT product consumers, developers, and third-party evaluators by offering standardized, reusable requirement sets.
Applications
The practical value of EN ISO/IEC 15408-5:2026 is evident in a variety of IT security and privacy domains:
- Product Development: Developers can reuse standardized security requirement packages during design, reducing time and effort in creating secure IT products and documentation.
- Security Evaluation: Evaluators benefit from consistent, internationally recognized reference packages, making it simpler to assess compliance and compare products.
- Purchase and Procurement: Consumers and organizations can reference recognized requirement sets when specifying security criteria in tenders, ensuring products meet accepted security benchmarks.
- Regulatory Alignment: Facilitates compliance with national and international regulations by referencing globally recognized security assurance packages.
- Component Integration: Supports assessment of complex or composed IT systems, making it easier to evaluate security across integrated solutions.
Using EN ISO/IEC 15408-5:2026 helps streamline procurement, improves efficiency in evaluation and certification, and reduces duplication of effort across IT security lifecycle stages.
Related Standards
For a comprehensive approach to IT product security, consider these related parts and standards:
- EN ISO/IEC 15408-1: Introduction and general model for IT security evaluation criteria.
- EN ISO/IEC 15408-3: Specifies the security assurance components and their use.
- ISO/IEC 18045: Provides guidelines for evaluation of IT security and interpretation of the ISO/IEC 15408 standards.
- Common Criteria Recognition Arrangement (CCRA): International recognition of security evaluations performed under ISO/IEC 15408.
- Other ISO/IEC 27000 series standards: Complementary standards for information security management and risk assessment.
These international standards collectively enable robust and harmonized security evaluation and assurance for IT products and solutions, emphasizing interoperability and confidence in cybersecurity and privacy protection.
Keywords: EN ISO/IEC 15408-5:2026, information security, cybersecurity, privacy protection, evaluation criteria, IT security, security assurance, security functional requirements, EAL, Common Criteria, composed assurance package, Protection Profile, Security Target, CEN, standardization, IT product evaluation.
Технические детали
- Технический комитет
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- SKU
- EN ISO/IEC 15408-5:2026
Похожие стандарты
Стандарты, упомянутые в описании
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…
SIST EN ISO/IEC 15408-1:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 1: In…
Overview SIST EN ISO/IEC 15408-1:2024 (ISO/IEC 15408-1:2022) establishes the general model and foundational concepts for evaluating IT security, cybersecurity and privacy protection. Part 1 provides…
SIST EN ISO/IEC 15408-3:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 3: Se…
Overview EN ISO/IEC 15408-3:2023 (aligned with ISO/IEC 15408-3:2022) is the Part 3 specification of the ISO/IEC 15408 series-commonly known as the Common Criteria. This European adoption by CEN defin…
BS EN ISO/IEC 27000:2020
ОтменёнInformation technology. Security techniques. Information security management systems. Overview and vocabulary
1 Scope This document provides the overview of information security management systems (ISMS). It also provides terms and definitions commonly used in the ISMS family of standards. This document is a…