ISO/IEC 15408-3:2026 PDF
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 3: Security assurance components
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 3: Security assurance components
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 176
- Дата публикации:
- 19 мая 2026 г.
- Издание:
- ISO/IEC IS 15408 edition 5 version 1
- ICS:
- 35.030
This document specifies the security assurance requirements of the ISO/IEC 15408 series. It includes the individual assurance components from which the evaluation assurance levels and other packages contained in ISO/IEC 15408-5 are composed, and the criteria for evaluation of Protection Profiles (PPs), PP-Configurations, PP-Modules and Security Targets (STs).
Abstract
Overview
ISO/IEC 15408-3:2026 is an international standard published by ISO, providing essential criteria for evaluating the security assurance of information technology (IT) products and systems. As part of the ISO/IEC 15408 series, also known as the Common Criteria, Part 3 focuses specifically on the structure and definition of security assurance components. These components form the basis for constructing and evaluating evaluation assurance levels (EALs), Protection Profiles (PPs), PP-Configurations, PP-Modules, and Security Targets (STs).
This standard plays a crucial role in information security, cybersecurity, and privacy protection frameworks, ensuring that IT products are evaluated consistently and robustly for security assurance.
Key Topics
- Security Assurance Paradigm: Defines the key concepts behind security assurance, including the evaluation approach, significance and causes of vulnerabilities, and the tiered evaluation assurance scale.
- Assurance Components Structure: Details the taxonomy and structure for assurance classes, families, and components, and outlines their naming, objectives, application notes, and dependencies.
- Protection Profile (PP) Evaluation: Specifies criteria for the evaluation of PPs, including their introduction, conformance claims, security problem definition, security objectives, extended components, and security requirements rationale.
- PP-Configuration & Module Evaluation: Covers the evaluation approach for PP-Configurations and PP-Modules, including consistency checks and security objectives for modular or composite security targets.
- Security Target (ST) Evaluation: Provides the framework for assessing security targets, including conformance claims, security problem definition, objectives, and component taxonomy.
- Development, Guidance, and Life Cycle Support: Includes criteria for evaluating development processes (e.g., architecture, functional specification), user and operational guidance, and life cycle security (e.g., configuration management, production support).
Applications
ISO/IEC 15408-3:2026 is widely applied in various sectors to:
- Certify IT Products for Security Assurance: Aid evaluators, developers, and regulators in assessing products for information security, cybersecurity, and privacy protection based on internationally recognized criteria.
- Develop Protection Profiles and Security Targets: Provide structured frameworks for vendors creating, documenting, and supporting security claims for their IT products or systems.
- Enhance Procurement Decisions: Support governments, enterprises, and organizations in selecting IT solutions that meet rigorous security assurance requirements.
- Support Regulatory and Compliance Initiatives: Serve as a reference for compliance with national and international security regulations and procurement standards.
- Facilitate Mutual Recognition: Promote interoperability and mutual recognition of security evaluations across countries, enhancing global cybersecurity.
Related Standards
- ISO/IEC 15408-1 - Introduction and general model, setting out the foundation for the entire Common Criteria series.
- ISO/IEC 15408-2 - Security functional components, detailing the functional requirements to be addressed in IT product evaluations.
- ISO/IEC 15408-5 - Providing additional packages, including predefined sets of security assurance and functional requirements.
- ISO/IEC 18045 - Methodology for IT security evaluation, complementing ISO/IEC 15408 by outlining practical evaluation processes.
- ISO/IEC 27001 - Information security management systems, often referenced in broader organizational risk frameworks.
ISO/IEC 15408-3:2026 is an indispensable resource for those responsible for developing, evaluating, procuring, or certifying IT security solutions, providing a clear pathway toward robust and harmonized assurance in cybersecurity and privacy protection.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-3:2026
Похожие стандарты
Стандарты, упомянутые в описании
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…
SIST EN ISO/IEC 15408-1:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 1: In…
Overview SIST EN ISO/IEC 15408-1:2024 (ISO/IEC 15408-1:2022) establishes the general model and foundational concepts for evaluating IT security, cybersecurity and privacy protection. Part 1 provides…
SIST EN ISO/IEC 15408-2:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 2: Se…
Overview SIST EN ISO/IEC 15408-2:2024 (Information security, cybersecurity, and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components) is an internationall…
BS EN ISO/IEC 15408-5:2026-TC
ДействующийTracked Changes. Information security, cybersecurity and privacy protection. Evaluation criteria for IT secur…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…