Overview
ISO/IEC TR 15446:2017 - "Information technology - Security techniques - Guidance for the production of protection profiles and security targets" - is a technical report that provides practical guidance for producing Protection Profiles (PPs) and Security Targets (STs) intended to conform to the third edition of ISO/IEC 15408 (Common Criteria). It is also applicable to Common Criteria v3.1 Revision 4. The document explains structure, content and best-practice methods for specifying the security problem, objectives, and requirements for a Target of Evaluation (TOE). NOTE: it is not an introduction to evaluation; readers seeking that should consult ISO/IEC 15408‑1. The report does not cover PP registration or intellectual‑property handling.
Key topics and technical requirements
ISO/IEC TR 15446:2017 focuses on the practical production of PPs and STs and covers:
- Scope and audience: guidance for PP/ST authors, evaluators and procurement specialists.
- Structure and content: recommended organization of introductions, conformance claims, and the TOE overview.
- Security problem definition: methods for identifying and documenting threats, organizational policies, assumptions, and informal security requirements.
- Security objectives: defining objectives for the TOE and its operational environment and producing an objectives rationale.
- Security requirements:
- Guidance on selecting and tailoring Security Functional Requirements (SFRs) from ISO/IEC 15408-2.
- Guidance on selecting and tailoring Security Assurance Requirements (SARs) from ISO/IEC 15408-3.
- Advice on refinements, operations (assignment, selection, iteration), and rationales for SFRs/SARs.
- TOE summary specification: how to map requirements to TOE functionality.
- Composed and component TOEs: special guidance for composite systems and modular evaluations.
- Special cases: low-assurance PPs/STs, national interpretations, and optional/conditional requirement constructs.
- Practical tools: use of automated tools and example annexes for extended components and refinements.
Applications and users
This guidance is valuable for:
- PP and ST authors creating Common Criteria–compliant specifications.
- Security evaluators and testing laboratories preparing or reviewing evaluation documentation.
- Vendors and product teams preparing certification deliverables.
- Procurement officers and system integrators using PPs/STs in specification‑based and selection‑based purchasing.
- Certification bodies and government security agencies aligning evaluation artefacts with ISO/IEC 15408.
Practical benefits include improved clarity of security claims, consistent SFR/SAR selection, and reduced rework during evaluation and certification.
Related standards
- ISO/IEC 15408 (all parts) - Common Criteria for IT security evaluation
- Common Criteria v3.1 Revision 4 (technically identical to ISO/IEC 15408 third edition)
Keywords: ISO/IEC TR 15446:2017, Protection Profiles, Security Targets, Common Criteria, ISO/IEC 15408, security functional requirements, security assurance requirements, TOE, threat analysis, evaluation guidance.