Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 4: Framework for the specification of evaluation methods and activities (ISO/IEC 15408-4:2022)

The ISO/IEC 15408 series permits comparability between the results of independent security evaluations. The ISO/IEC 15408 series does so by providing a common set of requirements for the security functionality of IT products and for assurance measures applied to these IT products during a security evaluation. ISO/IEC 18045 provides a companion methodology for some of the assurance requirements specified in the ISO/IEC 15408 series, ISO/IEC 15408-1 and ISO/IEC 18045 also allow that more specific Evaluation Activities (EAs) may be derived for use in particular evaluation contexts. Specification of such Evaluation Activities is already occurring amongst practitioners and this creates a need for a specification for defining such Evaluation Activities.
This document, ISO/IEC 15408-4, provides a standardised framework for specifying objective, repeatable and reproducible Evaluation Methods (EMs), and Evaluation Activities.

Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre - Evaluationskriterien für IT-Sicherheit - Teil 4: Rahmen für die Festlegung von Bewertungsmethoden und -tätigkeiten (ISO/IEC 15408-4:2022)

Dieses Dokument bietet einen standardisierten Rahmen für die Spezifikation objektiver, wiederholbarer und reproduzierbarer Evaluierungsmethoden und Evaluierungsaufgaben.
In diesem Dokument wird nicht spezifiziert, wie Evaluierungsmethoden und Evaluierungsaufgaben zu evalu
ieren, zu übernehmen oder zu pflegen sind. Diese Aspekte fallen in den Zuständigkeitsbereich derjenigen, die die Evaluierungsmethoden und die Evaluierungsaufgaben in ihrem jeweiligen Interessengebiet entwickeln.

Sécurité de l'information, cybersécurité et protection de la vie privée - Critères d'évaluation pour la sécurité des technologies de l'information - Partie 4: Cadre prévu pour la spécification des méthodes d'évaluation et des activités connexes (ISO/IEC 15408-4:2022)

Informacijska varnost, kibernetska varnost in varovanje zasebnosti - Merila za vrednotenje varnosti IT - 4. del: Okvir za specifikacijo metod vrednotenja in dejavnosti (ISO/IEC 15408-4:2022)

Skupina standardov ISO/IEC 15408 omogoča primerjavo med rezultati neodvisnih vrednotenj varnosti. Skupina standardov ISO/IEC 15408 omogoča to primerjavo z zagotavljanjem splošnega sklopa zahtev za varnostno funkcionalnost izdelkov IT in za ukrepe za zagotavljanje varnosti, ki veljajo za te izdelke IT med vrednotenjem varnosti. Standard ISO/IEC 18045 določa spremljevalno metodologijo za nekatere zahteve za zagotavljanje varnosti, določene v skupini standardov ISO/IEC 15408, standarda ISO/IEC 15408-1 in ISO/IEC 18045 pa prav tako omogočata izpeljavo podrobneje določenih dejavnosti vrednotenja za uporabo v določenih okvirih vrednotenja. Specifikacija tovrstnih dejavnosti vrednotenja se že pojavlja med izvajalci, to pa ustvarja potrebo po specifikaciji za opredeljevanje tovrstnih dejavnosti vrednotenja.
Ta dokument, standard ISO/IEC 15408-4, določa standardiziran okvir za določanje objektivnih in ponovljivih metod vrednotenja in dejavnosti vrednotenja.

General Information

Status
Published
Publication Date
05-Dec-2023
Current Stage
6060 - Definitive text made available (DAV) - Publishing
Start Date
06-Dec-2023
Due Date
23-Jun-2025
Completion Date
06-Dec-2023

Relations

Buy Standard

Standard
EN ISO/IEC 15408-4:2024
English language
25 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)


SLOVENSKI STANDARD
01-maj-2024
Informacijska varnost, kibernetska varnost in varovanje zasebnosti - Merila za
vrednotenje varnosti IT - 4. del: Okvir za specifikacijo metod vrednotenja in
dejavnosti (ISO/IEC 15408-4:2022)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT
security - Part 4: Framework for the specification of evaluation methods and activities
(ISO/IEC 15408-4:2022)
Informationstechnik - IT-Sicherheitsverfahren - Evaluationskriterien für IT-Sicherheit -
Teil 4: Rahmen für die Festlegung von Bewertungsmethoden und -tätigkeiten (ISO/IEC
15408-4:2022)
Sécurité de l'information, cybersécurité et protection de la vie privée - Critères
d'évaluation pour la sécurité des technologies de l'information - Partie 4: Cadre prévu
pour la spécification des méthodes d'évaluation et des activités connexes (ISO/IEC
15408-4:2022)
Ta slovenski standard je istoveten z: EN ISO/IEC 15408-4:2023
ICS:
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EUROPEAN STANDARD EN ISO/IEC 15408-4

NORME EUROPÉENNE
EUROPÄISCHE NORM
December 2023
ICS 35.030
English version
Information security, cybersecurity and privacy protection
- Evaluation criteria for IT security - Part 4: Framework for
the specification of evaluation methods and activities
(ISO/IEC 15408-4:2022)
Sécurité de l'information, cybersécurité et protection Informationssicherheit, Cybersicherheit und Schutz
de la vie privée - Critères d'évaluation pour la sécurité der Privatsphäre - Evaluationskriterien für IT-
des technologies de l'information - Partie 4: Cadre Sicherheit - Teil 4: Rahmen für die Festlegung von
prévu pour la spécification des méthodes d'évaluation Bewertungsmethoden und -tätigkeiten (ISO/IEC
et des activités connexes (ISO/IEC 15408-4:2022) 15408-4:2022)
This European Standard was approved by CEN on 20 November 2023.

CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.

CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2023 CEN/CENELEC All rights of exploitation in any form and by any means
Ref. No. EN ISO/IEC 15408-4:2023 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3

European foreword
The text of ISO/IEC 15408-4:2022 has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology” of the International Organization for Standardization (ISO) and has been
taken over as EN ISO/IEC 15408-4:2023 by Technical Committee CEN-CENELEC/ JTC 13 “Cybersecurity
and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by June 2024, and conflicting national standards shall be
withdrawn at the latest by June 2024.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
Any feedback and questions on this document should be directed to the users’ national standards body.
A complete listing of these bodies can be found on the CEN and CENELEC websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 15408-4:2022 has been approved by CEN-CENELEC as EN ISO/IEC 15408-4:2023
without any modification.
INTERNATIONAL ISO/IEC
STANDARD 15408-4
First edition
2022-08
Information security, cybersecurity
and privacy protection — Evaluation
criteria for IT security —
Part 4:
Framework for the specification of
evaluation methods and activities
Sécurité de l'information, cybersécurité et protection de la vie privée
— Critères d'évaluation pour la sécurité des technologies de
l'information —
Partie 4: Cadre prévu pour la spécification des méthodes d'évaluation
et des activités connexes
Reference number
ISO/IEC 15408-4:2022(E)
© ISO/IEC 2022
ISO/IEC 15408-4:2022(E)
© ISO/IEC 2022
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
© ISO/IEC 2022 – All rights reserved

ISO/IEC 15408-4:2022(E)
Contents Page
Foreword .iv
Introduction . vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 General model of evaluation methods and evaluation activities .1
4.1 Concepts and model . 1
4.2 Deriving evaluation methods and evaluation activities . 3
4.3 Verb usage in the description of evaluation methods and evaluation activities . 5
4.4 Conventions for the description of evaluation methods and evaluation activities . 6
5 Structure of an evaluation method .6
5.1 Overview . 6
5.2 Specification of an evaluation method . 7
5.2.1 Overview . 7
5.2.2 Identification of evaluation methods . 8
5.2.3 Entity responsible for the evaluation method . 9
5.2.4 Scope of the evaluation method . 9
5.2.5 Dependencies . 9
5.2.6 Required input from the developer or other entities . 9
5.2.7 Required tool types . 10
5.2.8 Required evaluator competences . 10
5.2.9 Requirements for reporting . 10
5.2.10 Rationale for the evaluation method . 10
5.2.11 Additional verb definitions .12
5.2.12 Set of evaluation activities.12
6 Structure of evaluation activities .12
6.1 Overview .12
6.2 Specification of an evaluation activity .12
6.2.1 Unique identification of the evaluation activity .12
6.2.2 Objective of the evaluation activity .12
6.2.3 Evaluation activity links to SFRs, SARs, and other evaluation activities .13
6.2.4 Required input from the developer or other entities .13
6.2.5 Required tool types . 13
6.2.6 Required evaluator competences . 13
6.2.7 Assessment strategy .13
6.2.8 Pass/fail criteria . 14
6.2.9 Requirements for reporting . 15
6.2.10 Rationale for the evaluation activity . 15
Bibliography .16
iii
© ISO/IEC 2022 – All rights reserved

ISO/IEC 15408-4:2022(E)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work.
The procedures used to develop this docu
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.