ISO/IEC 15408-5:2026 PDF
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 5: Pre-defined packages of security requirements
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 5: Pre-defined packages of security requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 27
- Дата публикации:
- 28 апреля 2026 г.
- Издание:
- ISO/IEC IS 15408 edition 2 version 1
- ICS:
- 35.030
This document provides packages of security assurance and security functional requirements that are intended to be useful in support of common usage by stakeholders. The users of this document can include consumers, developers and evaluators of secure IT products.
Abstract
Overview
ISO/IEC 15408-5:2026 is an international standard published by ISO and IEC focused on information security, cybersecurity, and privacy protection within IT environments. Officially titled "Evaluation criteria for IT security - Part 5: Pre-defined packages of security requirements," this standard provides structured packages of security assurance and functional requirements. These packages are specifically designed to support common use by stakeholders such as consumers, developers, and evaluators of secure IT products.
By establishing pre-defined sets of requirements, ISO/IEC 15408-5 facilitates consistency in IT security evaluations and streamlines the process of developing Protection Profiles (PPs) and Security Targets (STs). This helps ensure that products meet recognized levels of trust and allows for more efficient and comparable security assessments across the industry.
Key Topics
-
Pre-defined Security Packages: The standard introduces several families of assurance packages, including:
- Evaluation Assurance Levels (EAL): Structured sets of assurance requirements covering different levels of rigour and depth in evaluation, from basic (EAL1) to high assurance (EAL7).
- Composed Assurance Packages (CAP): Packages focused on evaluating composite systems, supporting composed IT environments.
- Composite Product Packages (COMP): Requirement sets for composite products, guaranteeing integrated and coherent assurance.
- Protection Profile Assurances (PPA): Packages for evaluating Protection Profiles themselves.
- Security Target Assurances (STA): Packages used to evaluate Security Targets.
-
Objective of Assurance Packages: Each pre-defined package combines assurance components to meet specific assurance objectives, balancing the degree of confidence in IT product security with cost and feasibility.
-
Augmentation: Packages, especially EALs, can be augmented with additional assurance components to tailor evaluations to particular security needs.
-
Terminology and Structure: The standard uses precise terminology as defined in foundational parts of the ISO/IEC 15408 series and maintains alignment with international evaluation criteria.
Applications
ISO/IEC 15408-5:2026 is used extensively in the field of IT product evaluation, providing practical value for multiple stakeholder groups:
- Product Developers: Can reference pre-defined packages to streamline design, documentation, and testing processes, ensuring their products meet specific industry-recognized assurance levels.
- Consumers and Procurement Specialists: Use the standard to specify security requirements during acquisition, ensuring chosen IT products deliver the required level of trust and protection.
- Evaluators and Certification Bodies: Leverage the standardized packages to guide objective, repeatable, and internationally recognized evaluation processes.
Common Use Cases:
- Development of Protection Profiles and Security Targets using standardized assurance packages.
- Selection of suitable Evaluation Assurance Levels (EAL1–EAL7) for government or industry procurement policies.
- Assessment of composite or integrated IT solutions, using composed and composite product packages to reflect complex security needs.
- Validation or audit of security claims in regulatory compliance and conformance schemes.
Related Standards
ISO/IEC 15408-5:2026 is part of the broader ISO/IEC 15408 series on IT security evaluation criteria. Related standards include:
- ISO/IEC 15408-1:2026 - Introduction and general model
- ISO/IEC 15408-3:2026 - Security assurance components
These standards collectively establish the Common Criteria framework, which is fundamental to international IT product security evaluation and certification.
Conclusion
By providing clear, pre-defined security requirement packages, ISO/IEC 15408-5:2026 greatly enhances the efficiency, comparability, and reliability of information security, cybersecurity, and privacy protection evaluations. Its practical guidance helps organizations achieve more consistent security evaluations, supports compliance needs, and fosters greater confidence in IT product security on a global scale.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 15408-5:2026
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO/IEC 15408-5:2026-TC
ДействующийTracked Changes. Information security, cybersecurity and privacy protection. Evaluation criteria for IT secur…
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…