SIST EN ISO/IEC 15408-4:2024 PDF
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 4: Framework for the specification of evaluation methods and activities (ISO/IEC 15408-4:2022)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 4: Framework for the specification of evaluation methods and activities (ISO/IEC 15408-4:2022)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 25
- Дата публикации:
- 12 апреля 2024 г.
- Издание:
- (ISO/IEC 15408-4:2022)
- ICS:
- 35.030
The ISO/IEC 15408 series permits comparability between the results of independent security evaluations. The ISO/IEC 15408 series does so by providing a common set of requirements for the security functionality of IT products and for assurance measures applied to these IT products during a security evaluation. ISO/IEC 18045 provides a companion methodology for some of the assurance requirements specified in the ISO/IEC 15408 series, ISO/IEC 15408-1 and ISO/IEC 18045 also allow that more specific Evaluation Activities (EAs) may be derived for use in particular evaluation contexts. Specification of such Evaluation Activities is already occurring amongst practitioners and this creates a need for a specification for defining such Evaluation Activities. This document, ISO/IEC 15408-4, provides a standardised framework for specifying objective, repeatable and reproducible Evaluation Methods (EMs), and Evaluation Activities.
Abstract
Overview
EN ISO/IEC 15408-4:2023 - part of the Common Criteria family - defines a standardized framework for specifying Evaluation Methods (EMs) and Evaluation Activities (EAs) used in IT security, cybersecurity and privacy protection assessments. Aligned with ISO/IEC 15408-1 and ISO/IEC 18045, this part focuses on making evaluation methods objective, repeatable and reproducible so independent security evaluations are comparable across labs and certification schemes.
Key topics and requirements
- Framework scope: Provides a model to derive EMs and EAs from generic work units and group them for specific technologies, protection profiles (PPs), packages or Security Targets (STs).
- Structure of an Evaluation Method: Guidance on identification, ownership, scope, dependencies, required developer input, required tool types, evaluator competences, reporting requirements and rationale.
- Structure of an Evaluation Activity: Defines unique identification, objective, links to Security Functional Requirements (SFRs) and Security Assurance Requirements (SARs), required inputs, tool types, evaluator competences, assessment strategy, pass/fail criteria, reporting and rationale.
- Conventions and verb usage: Prescribes consistent language and conventions to ensure EMs/EAs are unambiguous and actionable.
- Goal: Ensure EMs/EAs are objective, repeatable, reproducible, and traceable to SFRs/SARs.
Keywords: EN ISO/IEC 15408-4:2023, Evaluation Methods, Evaluation Activities, Common Criteria, security evaluation, protection profiles, SFRs, SARs, ISO/IEC 18045.
Practical applications
- Creating or refining Protection Profiles (PPs) and Security Targets (STs) that reference specific evaluation methods and activities.
- Enabling certification bodies and independent laboratories to follow well-defined EMs/EAs for consistent security assessments.
- Defining technology-specific assessment activities (e.g., for cloud services, IoT devices or cryptographic modules) derived from generic CC guidance.
- Improving procurement and compliance by specifying measurable pass/fail criteria and reporting requirements in contract and certification documentation.
- Supporting reproducible testing and facilitating cross-lab comparability for conformity assessment and accreditation.
Who uses this standard
- Certification bodies and evaluators - to implement and report standardized evaluation activities.
- Protection profile authors and security architects - to specify concrete methods within PPs and STs.
- Developers and vendors - to understand required evidence, tool support and developer inputs for evaluation.
- Procurement officers and integrators - to reference objective evaluation methods in contracts and compliance checks.
Related standards
- EN ISO/IEC 15408-1 (Common Criteria: general model)
- ISO/IEC 18045 (companion methodology for assurance requirements)
- Other parts of the ISO/IEC 15408 series
Adopted by CEN as EN ISO/IEC 15408-4:2023 (SIST EN ISO/IEC 15408-4:2024 in Slovenia), this document helps harmonize evaluation practice and strengthens the reliability of IT security certification.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO/IEC 15408-4:2024
Похожие стандарты
Упомянутые в описании и другие стандарты SIST
SIST EN ISO/IEC 15408-1:2024
ДействующийInformation security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 1: In…
Overview SIST EN ISO/IEC 15408-1:2024 (ISO/IEC 15408-1:2022) establishes the general model and foundational concepts for evaluating IT security, cybersecurity and privacy protection. Part 1 provides…
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…
SIST EN ISO 6338:2026
ДействующийMethod to calculate GHG emissions at LNG plant (ISO 6338:2023)
Overview SIST EN ISO 6338:2026 / ISO 6338:2023 establishes a standardized method for calculating greenhouse gas (GHG) emissions at liquefied natural gas (LNG) plants, both onshore and offshore. Devel…
SIST-TP CEN ISO/ASTM TR 52958:2026
Additive manufacturing of metals - Powder bed fusion (PBF) - In-situ coaxial photodiode monitoring for lack o…
Overview SIST-TP CEN ISO/ASTM TR 52958:2026 specifies a workflow for the detection of lack of fusion flaws during the additive manufacturing of metals using powder bed fusion-laser based (PBF-LB) pro…
SIST EN ISO 41002:2026
ДействующийFacility management - Development of the facility management organization (ISO 41002:2026)
Overview SIST EN ISO 41002:2026 - Facility management - Development of the facility management organization offers strategic guidance for building and developing robust facility management (FM) organ…
SIST EN ISO 844:2026
ДействующийRigid cellular plastics - Determination of compressive properties (ISO 844:2026)
Overview SIST EN ISO 844:2026 - Rigid Cellular Plastics: Determination of Compressive Properties (ISO 844:2026) provides standardized methods for measuring the compressive properties of rigid cellula…
SIST-TS CEN ISO/TS 17664-3:2026
ДействующийProcessing of health care products - Information to be provided by the medical device manufacturer for the pr…
Overview SIST-TS CEN ISO/TS 17664-3:2026 sets out comprehensive guidance for grouping reusable medical devices based on their cleaning requirements. This technical specification, prepared collaborati…
SIST EN ISO 8980-4:2026
ДействующийOphthalmic optics - Uncut finished spectacle lenses - Part 4: Specifications and test methods for the propert…
Overview SIST EN ISO 8980-4:2026 specifies requirements and test methods for the properties of anti-reflective coatings and hydrophobic coatings applied to uncut finished spectacle lenses. Developed…