Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 4: Framework for the specification of evaluation methods and activities (ISO/IEC 15408-4:2022)

The ISO/IEC 15408 series permits comparability between the results of independent security evaluations. The ISO/IEC 15408 series does so by providing a common set of requirements for the security functionality of IT products and for assurance measures applied to these IT products during a security evaluation. ISO/IEC 18045 provides a companion methodology for some of the assurance requirements specified in the ISO/IEC 15408 series, ISO/IEC 15408-1 and ISO/IEC 18045 also allow that more specific Evaluation Activities (EAs) may be derived for use in particular evaluation contexts. Specification of such Evaluation Activities is already occurring amongst practitioners and this creates a need for a specification for defining such Evaluation Activities.
This document, ISO/IEC 15408-4, provides a standardised framework for specifying objective, repeatable and reproducible Evaluation Methods (EMs), and Evaluation Activities.

Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre - Evaluationskriterien für IT-Sicherheit - Teil 4: Rahmen für die Festlegung von Bewertungsmethoden und -tätigkeiten (ISO/IEC 15408-4:2022)

Dieses Dokument bietet einen standardisierten Rahmen für die Spezifikation objektiver, wiederholbarer und reproduzierbarer Evaluierungsmethoden und Evaluierungsaufgaben.
In diesem Dokument wird nicht spezifiziert, wie Evaluierungsmethoden und Evaluierungsaufgaben zu evalu
ieren, zu übernehmen oder zu pflegen sind. Diese Aspekte fallen in den Zuständigkeitsbereich derjenigen, die die Evaluierungsmethoden und die Evaluierungsaufgaben in ihrem jeweiligen Interessengebiet entwickeln.

Sécurité de l'information, cybersécurité et protection de la vie privée - Critères d'évaluation pour la sécurité des technologies de l'information - Partie 4: Cadre prévu pour la spécification des méthodes d'évaluation et des activités connexes (ISO/IEC 15408-4:2022)

Informacijska varnost, kibernetska varnost in varovanje zasebnosti - Merila za vrednotenje varnosti IT - 4. del: Okvir za specifikacijo metod vrednotenja in dejavnosti (ISO/IEC 15408-4:2022)

General Information

Status
Not Published
Publication Date
23-Jun-2025
Current Stage
4060 - Closure of enquiry - Enquiry
Start Date
19-Oct-2023
Due Date
17-Mar-2024
Completion Date
19-Oct-2023

Buy Standard

Draft
prEN ISO/IEC 15408-4:2023
English language
22 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)

SLOVENSKI STANDARD
oSIST prEN ISO/IEC 15408-4:2023
01-oktober-2023
Informacijska varnost, kibernetska varnost in varovanje zasebnosti - Merila za
vrednotenje varnosti IT - 4. del: Okvir za specifikacijo metod vrednotenja in
dejavnosti (ISO/IEC 15408-4:2022)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT
security - Part 4: Framework for the specification of evaluation methods and activities
(ISO/IEC 15408-4:2022)
Informationstechnik - IT-Sicherheitsverfahren - Evaluationskriterien für IT-Sicherheit -
Teil 4: Rahmen für die Festlegung von Bewertungsmethoden und -tätigkeiten (ISO/IEC
15408-4:2022)
Sécurité de l'information, cybersécurité et protection de la vie privée - Critères
d'évaluation pour la sécurité des technologies de l'information - Partie 4: Cadre prévu
pour la spécification des méthodes d'évaluation et des activités connexes (ISO/IEC
15408-4:2022)
Ta slovenski standard je istoveten z: prEN ISO/IEC 15408-4
ICS:
35.030 Informacijska varnost IT Security
oSIST prEN ISO/IEC 15408-4:2023 en,fr,de
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

---------------------- Page: 1 ----------------------
oSIST prEN ISO/IEC 15408-4:2023

---------------------- Page: 2 ----------------------
oSIST prEN ISO/IEC 15408-4:2023
INTERNATIONAL ISO/IEC
STANDARD 15408-4
First edition
2022-08
Information security, cybersecurity
and privacy protection — Evaluation
criteria for IT security —
Part 4:
Framework for the specification of
evaluation methods and activities
Sécurité de l'information, cybersécurité et protection de la vie privée
— Critères d'évaluation pour la sécurité des technologies de
l'information —
Partie 4: Cadre prévu pour la spécification des méthodes d'évaluation
et des activités connexes
Reference number
ISO/IEC 15408-4:2022(E)
© ISO/IEC 2022

---------------------- Page: 3 ----------------------
oSIST prEN ISO/IEC 15408-4:2023
ISO/IEC 15408-4:2022(E)
COPYRIGHT PROTECTED DOCUMENT
© ISO/IEC 2022
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
  © ISO/IEC 2022 – All rights reserved

---------------------- Page: 4 ----------------------
oSIST prEN ISO/IEC 15408-4:2023
ISO/IEC 15408-4:2022(E)
Contents Page
Foreword .iv
Introduction . vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 General model of evaluation methods and evaluation activities .1
4.1 Concepts and model . 1
4.2 Deriving evaluation methods and evaluation activities . 3
4.3 Verb usage in the description of evaluation methods and evaluation activities . 5
4.4 Conventions for the description of evaluation methods and evaluation activities . 6
5 Structure of an evaluation method .6
5.1 Overview .
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.