SIST EN ISO/IEC 15408-2:2024 PDF
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components (ISO/IEC 15408-2:2022)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components (ISO/IEC 15408-2:2022)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 293
- Дата публикации:
- 12 апреля 2024 г.
- Издание:
- (ISO/IEC 15408-2:2022)
- ICS:
- 35.030
This document defines the required structure and content of security functional components for the purpose of security evaluation. It includes a catalogue of functional components that will meet the common security functionality requirements of many IT products.
Abstract
Overview
SIST EN ISO/IEC 15408-2:2024 (Information security, cybersecurity, and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components) is an internationally recognized European standard developed by CEN under the ISO/IEC 15408 series. This standard delineates the structure and requirements for security functional components in IT security evaluation, supporting consistent, systematic assessments of IT products and systems. It is a cornerstone for organizations aiming to achieve robust information security, cybersecurity, and privacy protection compliance.
Key Topics
SIST EN ISO/IEC 15408-2:2024 provides a comprehensive framework for defining and cataloguing security functional requirements (SFRs) applicable to the evaluation of IT products (referred to as Targets of Evaluation). Key features include:
- Standardized Structure: The document details a well-structured organization of security functional components to facilitate uniformity in security evaluations.
- Component Catalogue: It includes a detailed catalogue of functional components addressing common requirements across information security, cybersecurity, and privacy contexts.
- Functional Classes: Functional components are organized into classes such as:
- Security audit
- Communication
- Cryptographic support
- User data protection
- Component Consistency: Ensures consistent application and interpretation of security functionality requirements for IT products.
- Evaluation Basis: Supports formulation of Security Targets and Protection Profiles, which are essential documents in the IT security certification process.
Applications
SIST EN ISO/IEC 15408-2:2024 is valuable across many sectors where robust information security, cybersecurity, and privacy enforcement are critical. Practical applications include:
- Product Evaluation: Used by certification bodies, evaluators, and developers to assess whether IT products meet international security requirements.
- Security Target Development: Helps organizations specify precisely which security functionalities their IT system or product will offer and under which conditions.
- Procurement and Compliance: Enables governments, corporations, and other stakeholders to select products that have been evaluated according to recognized international security standards.
- Protection Profile Authoring: Provides a modular approach for creating Protection Profiles, supporting reusable security requirement sets for product categories.
- Regulatory Adherence: Assists organizations in meeting data protection and privacy regulations by ensuring IT systems incorporate essential security functionalities.
Related Standards
SIST EN ISO/IEC 15408-2:2024 forms part of the broader ISO/IEC 15408 (Common Criteria) series and is closely integrated with the following standards:
- EN ISO/IEC 15408-1: Introduction and general model - Provides the foundational models and terms for IT security evaluation.
- EN ISO/IEC 15408-3: Security assurance components - Specifies the assurance requirements to complement the functional requirements of Part 2.
- ISO/IEC 18045: Evaluation methodology for IT security - Outlines how to apply evaluation criteria in practice.
- Related European and international standards for IT security, risk management, and privacy protection.
By following SIST EN ISO/IEC 15408-2:2024, organizations benefit from globally accepted practices for defining, assessing, and verifying security functionalities in IT products. This standard is essential for building trust in technology through certified assurance of information security, cybersecurity, and privacy protection.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO/IEC 15408-2:2024
Похожие стандарты
Стандарты, упомянутые в описании
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…
SIST EN ISO/IEC 15408-1:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 1: In…
Overview SIST EN ISO/IEC 15408-1:2024 (ISO/IEC 15408-1:2022) establishes the general model and foundational concepts for evaluating IT security, cybersecurity and privacy protection. Part 1 provides…
SIST EN ISO/IEC 15408-3:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 3: Se…
Overview EN ISO/IEC 15408-3:2023 (aligned with ISO/IEC 15408-3:2022) is the Part 3 specification of the ISO/IEC 15408 series-commonly known as the Common Criteria. This European adoption by CEN defin…