SIST EN ISO/IEC 18045:2024 PDF
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Methodology for IT security evaluation (ISO/IEC 18045:2022)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Methodology for IT security evaluation (ISO/IEC 18045:2022)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 439
- Дата публикации:
- 23 февраля 2024 г.
- Издание:
- (ISO/IEC 18045:2022)
- ICS:
- 35.030
This document defines the minimum actions to be performed by an evaluator in order to conduct an ISO/IEC 15408 series evaluation, using the criteria and evaluation evidence defined in the ISO/IEC 15408 series.
Abstract
Overview
SIST EN ISO/IEC 18045:2024, titled Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Methodology for IT security evaluation, is an international standard developed by CEN in alignment with ISO/IEC 18045:2022. This standard sets out the minimum required actions for evaluators conducting IT security evaluations against the ISO/IEC 15408 series (Common Criteria). SIST EN ISO/IEC 18045:2024 describes a comprehensive methodology for confirming that IT products and systems meet rigorous security requirements, supporting reliable security certifications across various industries.
Key Topics
-
Methodology for IT Security Evaluation SIST EN ISO/IEC 18045:2024 defines a structured approach for the assessment of IT product and system security. It details the step-by-step methodology evaluators must follow, ensuring consistent, repeatable, and objective evaluations based on ISO/IEC 15408 series requirements.
-
Roles and Responsibilities The standard clarifies the responsibilities of different stakeholders in the evaluation process, including evaluators, developers, and certifiers, fostering transparency and accountability throughout all evaluation tasks.
-
Evaluation Process and Tasks The document describes the evaluation process, including input tasks (collecting and managing evaluation evidence), evaluation sub-activities (such as assessment of security objectives, requirements, and design), and output tasks (compiling evaluation results and verdicts).
-
Protection Profiles and Security Targets SIST EN ISO/IEC 18045:2024 addresses methodologies for the evaluation of Protection Profiles (PPs), PP modules, configurations, and Security Targets (STs), ensuring that both standardized and tailored security needs can be assessed.
-
Life Cycle and Guidance Evaluation The standard covers essential aspects of product life cycle security and guidance document evaluation, reinforcing confidence in operational and preparative documentation.
Applications
SIST EN ISO/IEC 18045:2024 is widely applicable wherever the security of IT products or systems must be reliably assessed and demonstrated. Key use cases include:
-
Product Certification: Used by evaluation laboratories and certifying bodies to assess software, hardware, or system security against internationally recognized benchmarks.
-
Procurement and Supply Chains: Organizations and government agencies rely on products assessed according to SIST EN ISO/IEC 18045:2024 and ISO/IEC 15408 criteria for secure procurement, minimizing security risks in their supply chains.
-
Vendor Assurance: Developers and suppliers use the standard to structure their security documentation and processes, facilitating smoother engagement with evaluators and customers.
-
Compliance and Regulation: Helps organizations demonstrate due diligence with respect to international security requirements and privacy protection standards in regulatory or contractual contexts.
-
Cloud and Connected Systems: Ensures security requirements for emerging areas such as cloud computing, the Internet of Things (IoT), and complex IT system architectures are methodically evaluated and documented.
Related Standards
-
ISO/IEC 15408 Series (Common Criteria): The foundational set of standards for security evaluation criteria, closely referenced and required for the methodologies outlined in SIST EN ISO/IEC 18045:2024.
-
ISO/IEC 27001: Focuses on information security management systems, complementary for overall organizational security governance.
-
EN ISO/IEC 29119: Provides standards on software testing which may intersect with security testing approaches in IT evaluations.
-
ISO/IEC 27034: Focuses on application security, relevant for evaluating application-specific security requirements.
By adhering to SIST EN ISO/IEC 18045:2024, organizations can ensure their IT security evaluation activities meet globally recognized methodologies, delivering trust and assurance to customers, regulators, and stakeholders through standardized and robust security assessments.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO/IEC 18045:2024
Похожие стандарты
Стандарты, упомянутые в описании
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
ISO/IEC 27034-1:2011
ДействующийInformation technology — Security techniques — Application security — Part 1: Overview and concepts
Overview ISO/IEC 27034-1:2011 is the international application security standard that provides an overview of concepts, definitions and principles for integrating security into application life‑cycle…