ISO/IEC 15408-5:2022 PDF
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 5: Pre-defined packages of security requirements
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 5: Pre-defined packages of security requirements
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 27
- Дата публикации:
- 9 августа 2022 г.
- Издание:
- ISO/IEC IS 15408 edition 1 version 1
- ICS:
- 35.030
This document provides packages of security assurance and security functional requirements that have been identified as useful in support of common usage by stakeholders. EXAMPLE Examples of provided packages include the evaluation assurance levels (EAL) and the composed assurance packages (CAPs). This document presents: — evaluation assurance level (EAL) family of packages that specify pre-defined sets of security assurance components that may be referenced in PPs and STs and which specify appropriate security assurances to be provided during an evaluation of a target of evaluation (TOE); — composition assurance (CAP) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during an evaluation of composed TOEs; — composite product (COMP) package that specifies a set of security assurance components used for specifying appropriate security assurances to be provided during an evaluation of a composite product TOEs; — protection profile assurance (PPA) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during a protection profile evaluation; — security target assurance (STA) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during a security target evaluation. The users of this document can include consumers, developers, and evaluators of secure IT products.
Abstract
Overview
ISO/IEC 15408-5:2022 is Part 5 of the Common Criteria family for information security, cybersecurity and privacy protection. It defines pre‑defined packages of security assurance and security functional requirements that stakeholders commonly use when specifying or evaluating IT products (Targets of Evaluation, TOEs). The standard supplies ready‑made assurance packages - including Evaluation Assurance Levels (EALs), Composed Assurance Packages (CAPs), a Composite Product (COMP) package, and assurance families for Protection Profiles (PPA) and Security Targets (STA) - to streamline, harmonize and make evaluations more predictable.
Key topics and requirements
- Evaluation Assurance Levels (EAL1–EAL7): a scale of assurance where each EAL specifies a pre‑defined set of assurance components.
- EAL1 - Functionally tested
- EAL2 - Structurally tested
- EAL3 - Methodically tested and checked
- EAL4 - Methodically designed, tested and reviewed
- EAL5 - Semi‑formally verified design and tested
- EAL6 - Semi‑formally verified design and tested (higher rigor)
- EAL7 - Formally verified design and tested
- Composed Assurance Packages (CAPs): packages tailored for systems composed of multiple components or subsystems. Examples in the standard:
- CAP A - Structurally composed
- CAP B - Methodically composed
- CAP C - Methodically composed, tested and reviewed
- Composite Product (COMP) package: defines assurance components for evaluating composite products made from independently evaluated parts.
- PPA & STA families: predefined assurance sets for Protection Profile and Security Target evaluations, including direct rationale and standard package variants.
- Normative links: aligns with ISO/IEC 15408‑1 (general model) and ISO/IEC 15408‑3 (assurance components).
Applications and who uses it
- Procurement officers / consumers: specify required EALs or CAPs in RFPs to ensure predictable assurance levels.
- Product developers: use packages to design evidence and processes that meet an intended assurance level, reducing development and evaluation effort.
- Evaluation labs / certifiers: apply the predefined packages to assess TOEs consistently against Common Criteria expectations.
- PP and ST authors: leverage PPA/STA packages to simplify and harmonize requirement sets for profiles and targets.
Related standards
- ISO/IEC 15408‑1:2022 - Introduction and general model (normative)
- ISO/IEC 15408‑3:2022 - Security assurance components (normative)
- Common Criteria (CC) material referenced by national certification schemes
Using ISO/IEC 15408-5:2022 helps organizations standardize assurance claims, reduce duplicated effort when creating Protection Profiles and Security Targets, and increase comparability of security evaluations across vendors and evaluators. Keywords: ISO/IEC 15408-5:2022, Common Criteria, EAL, CAP, composite product, protection profile, security target, cybersecurity, security assurance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-5:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
SIST EN ISO/IEC 15408-1:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 1: In…
Overview SIST EN ISO/IEC 15408-1:2024 (ISO/IEC 15408-1:2022) establishes the general model and foundational concepts for evaluating IT security, cybersecurity and privacy protection. Part 1 provides…
SIST EN ISO/IEC 15408-3:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 3: Se…
Overview EN ISO/IEC 15408-3:2023 (aligned with ISO/IEC 15408-3:2022) is the Part 3 specification of the ISO/IEC 15408 series-commonly known as the Common Criteria. This European adoption by CEN defin…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…