IT security techniques - Competence requirements for information security testers and evaluators - Part 2: Knowledge, skills and effectiveness requirements for ISO/IEC 19790 testers (ISO/IEC 19896-2:2018)

This document provides the minimum requirements for the knowledge, skills and effectiveness requirements of individuals performing testing activities for a conformance scheme using ISO/IEC 19790 and ISO/IEC 24759.

IT-Sicherheitstechniken - Kompetenzanforderungen an Tester und Evaluatoren von Informationssicherheit - Teil 2: Anforderungen an Wissen, Fähigkeiten und Effektivität für ISO/IEC 19790‑Tester (ISO/IEC 19896‑2:2018)

Dieses Dokument enthält die Mindestanforderungen an Wissen, Fertigkeiten und Anforderungen an die Effektivität von Personen, die Prüftätigkeiten für ein Konformitätsschema im Rahmen von ISO/IEC19790 und ISO/IEC24759 durchführen.

Techniques de sécurité IT - Exigences de compétence pour l'information testeurs d'assurance et les évaluateurs - Partie 2: Exigences en matière de connaissances, de compétences et d'efficacité pour ISO/IEC 19790 testeurs (ISO/IEC 19896-2:2018)

Le présent document fournit les exigences minimales en matière de connaissances, de savoir-faire et d'efficacité des personnes chargées de réaliser des activités d'essai dans le cadre d'un schéma de conformité utilisant l'ISO/IEC 19790 et l'ISO/IEC 24759.

Varnostne tehnike IT - Zahteve za usposobljenost za preskuševalce in ocenjevalce informacijske varnosti - 2. del: Zahteve glede znanja, veščin in učinkovitosti za preskuševalce ISO/IEC 19790 (ISO/IEC 19896-2:2018)

Ta dokument določa minimalne zahteve glede znanj, spretnosti in učinkovitosti posameznikov, ki izvajajo dejavnosti preskušanja sheme skladnosti z uporabo standarda ISO/IEC 19790:2012 in ISO/IEC 24759.

General Information

Status
Published
Publication Date
24-Jan-2023
Current Stage
6060 - Definitive text made available (DAV) - Publishing
Start Date
25-Jan-2023
Due Date
06-Nov-2024
Completion Date
25-Jan-2023

Buy Standard

Standard
EN ISO/IEC 19896-2:2023 - BARVE
English language
42 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)


SLOVENSKI STANDARD
01-maj-2023
Varnostne tehnike IT - Zahteve za usposobljenost za preskuševalce in ocenjevalce
informacijske varnosti - 2. del: Zahteve glede znanja, veščin in učinkovitosti za
preskuševalce ISO/IEC 19790 (ISO/IEC 19896-2:2018)
IT security techniques - Competence requirements for information security testers and
evaluators - Part 2: Knowledge, skills and effectiveness requirements for ISO/IEC 19790
testers (ISO/IEC 19896-2:2018)
IT-Sicherheitstechniken - Kompetenzanforderungen an Tester und Evaluatoren von
Informationssicherheit - Teil 2: Anforderungen an Wissen, Fähigkeiten und Effektivität für
ISO/IEC 19790‑Tester (ISO/IEC 19896-2:2018)
Techniques de sécurité IT - Exigences de compétence pour l'information testeurs
d'assurance et les évaluateurs - Partie 2: Exigences en matière de connaissances, de
compétences et d'efficacité pour ISO/IEC 19790 testeurs (ISO/IEC 19896-2:2018)
Ta slovenski standard je istoveten z: EN ISO/IEC 19896-2:2023
ICS:
03.100.30 Vodenje ljudi Management of human
resources
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

EUROPEAN STANDARD EN ISO/IEC 19896-2

NORME EUROPÉENNE
EUROPÄISCHE NORM
January 2023
ICS 35.030
English version
IT security techniques - Competence requirements for
information security testers and evaluators - Part 2:
Knowledge, skills and effectiveness requirements for
ISO/IEC 19790 testers (ISO/IEC 19896-2:2018)
Techniques de sécurité IT - Exigences de compétence IT-Sicherheitstechniken - Kompetenzanforderungen an
pour l'information testeurs d'assurance et les Tester und Evaluatoren von Informationssicherheit -
évaluateurs - Partie 2: Exigences en matière de Teil 2: Anforderungen an Wissen, Fähigkeiten und
connaissances, de compétences et d'efficacité pour Effektivität für ISO/IEC 19790-Tester (ISO/IEC 19896-
ISO/IEC 19790 testeurs (ISO/IEC 19896-2:2018) 2:2018)
This European Standard was approved by CEN on 9 January 2023.

CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.

CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.

CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2023 CEN/CENELEC All rights of exploitation in any form and by any means
Ref. No. EN ISO/IEC 19896-2:2023 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3

European foreword
The text of ISO/IEC 19896-2:2018 has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology” of the International Organization for Standardization (ISO) and has been
taken over as EN ISO/IEC 19896-2:2023 by Technical Committee CEN-CENELEC/ JTC 13 “Cybersecurity
and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by July 2023, and conflicting national standards shall be
withdrawn at the latest by July 2023.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
Any feedback and questions on this document should be directed to the users’ national standards body.
A complete listing of these bodies can be found on the CEN and CENELEC websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 19896-2:2018 has been approved by CEN-CENELEC as EN ISO/IEC 19896-2:2023
without any modification.
INTERNATIONAL ISO/IEC
STANDARD 19896-2
First edition
2018-08
IT security techniques — Competence
requirements for information security
testers and evaluators —
Part 2:
Knowledge, skills and effectiveness
requirements for ISO/IEC 19790
testers
Techniques de sécurité IT — Exigences de compétence pour
l'information testeurs d'assurance et les évaluateurs —
Partie 2: Exigences en matière de connaissances, de compétences et
d'efficacité pour ISO / IEC 19790 testeurs
Reference number
ISO/IEC 19896-2:2018(E)
©
ISO/IEC 2018
ISO/IEC 19896-2:2018(E)
© ISO/IEC 2018
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address
below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Fax: +41 22 749 09 47
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii © ISO/IEC 2018 – All rights reserved

ISO/IEC 19896-2:2018(E)
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 2
5 Structure of this document . 2
6 Knowledge . 2
6.1 General . 2
6.2 Tertiary education . 2
6.2.1 General. 2
6.2.2 Technical specialities . 2
6.2.3 Speciality topics . 3
6.3 Knowledge of standards . 7
6.3.1 General. 7
6.3.2 ISO/IEC 19790 concepts . 7
6.3.3 ISO/IEC 24759 . 7
6.3.4 Additional ISO/IEC standards . 8
6.4 Knowledge of the validation program . 8
6.4.1 Validation program . 8
6.5 Knowledge of the requirements of ISO/IEC 17025 .10
7 Skills .10
7.1 General .10
7.2 Algorithm testing .10
7.3 Physical security testing .10
7.4 Side channel analysis .10
7.5 Technology types .10
8 Experience.10
8.1 General .10
8.2 Demonstration of technical competence to the validation program .11
8.2.1 Experience with performing testing .11
8.2.2 Experience with particular technology types .11
9 Education .11
10 Effectiveness .11
Annex A (informative) Example of an ISO/IEC 24759 testers’ log.12
Annex B (informative) Ontology of technology types and associated bodies of knowledge .13
Annex C (informative) Specific knowledge associated with the security of cryptographic
modules .16
Annex D (informative) Competence requirements for ISO/IEC 19790 validators .33
Bibliography .
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.