ISO/IEC 15408-2:2022 PDF
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 2: Security functional components
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 2: Security functional components
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 273
- Дата публикации:
- 9 августа 2022 г.
- Издание:
- ISO/IEC IS 15408 edition 4 version 1
- ICS:
- 35.030
This document defines the required structure and content of security functional components for the purpose of security evaluation. It includes a catalogue of functional components that meets the common security functionality requirements of many IT products.
Abstract
Overview
ISO/IEC 15408-2:2022 defines the required structure and content of security functional components used for IT security evaluation. Part 2 of the ISO/IEC 15408 evaluation criteria series provides a standardized catalogue of functional components that address common security functionality across a wide range of IT products. The fourth edition (2022) organizes components into classes, families and component levels to support consistent evaluation and specification of security capabilities.
Key topics and technical requirements
- Functional requirements paradigm - defines how functional components are structured, specified and combined for evaluation.
- Class, family and component structure - hierarchical organization allowing precise selection of security functional components for a product or security target.
- Component catalogue - a comprehensive list of predefined functional components (e.g., audit, communication, cryptographic support) that evaluators and vendors can reference.
- Representative classes and families (examples referenced in the document):
- FAU (Security audit) - audit generation, storage, analysis, review and selection (FAU_GEN, FAU_STG, FAU_SAA, FAU_SAR, FAU_SEL, FAU_ARP).
- FCO (Communication) - non-repudiation of origin and receipt (FCO_NRO, FCO_NRR).
- FCS (Cryptographic support) - cryptographic key management and related cryptographic functions (FCS_CKM and related components).
- Management and audit expectations - component-level descriptions include management requirements and what must be auditable during evaluation.
- Leveling of components - components may be defined at multiple assurance/functional levels to match risk and product capability.
Practical applications - who uses this standard
- Security evaluators and certification bodies - to map product behaviour to standardized functional components during formal evaluation.
- Product developers and architects - to define, design and document security features that meet recognized evaluation criteria.
- Procurement and risk managers - to specify required security functionality in contracts and vendor assessments.
- Security testers and auditors - to verify that implemented features comply with the functional requirements and to plan test coverage.
Using ISO/IEC 15408-2 helps align product security claims with a recognized catalogue of functional requirements, simplifying certification, procurement and interoperability assessments.
Related standards
- Other parts of the ISO/IEC 15408 series (e.g., Part 1 - general model/introduction; Part 3 - security assurance components) and complementary IT security standards are commonly used alongside ISO/IEC 15408-2 for comprehensive security evaluation and compliance.
Keywords: ISO/IEC 15408-2:2022, security functional components, evaluation criteria for IT security, security audit, cryptographic key management, IT security evaluation.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-2:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…
SIST EN ISO/IEC 15408-2:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 2: Se…
Overview SIST EN ISO/IEC 15408-2:2024 (Information security, cybersecurity, and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components) is an internationall…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…