EN ISO/IEC 19896-3:2023
(Main)IT security techniques - Competence requirements for information security testers and evaluators - Part 3: Knowledge, skills and effectiveness requirements for ISO/IEC 15408 evaluators (ISO/IEC 19896-3:2018)
IT security techniques - Competence requirements for information security testers and evaluators - Part 3: Knowledge, skills and effectiveness requirements for ISO/IEC 15408 evaluators (ISO/IEC 19896-3:2018)
This document provides the specialized requirements to demonstrate competence of individuals in performing IT product security evaluations in accordance with ISO/IEC 15408 (all parts) and ISO/IEC 18045.
IT-Sicherheitstechniken - Kompetenzanforderungen an Tester und Evaluatoren von Informationssicherheit - Teil 3: Anforderungen an die Kenntnisse, Fähigkeiten und Effektivität von Evaluatoren nach ISO/IEC 15408 (ISO/IEC 19896‑3:2018)
Techniques de sécurité IT - Exigences en matière de compétences des spécialistes en tests et évaluations de la sécurité de l'information - Partie 3: Exigences en matière de connaissances, compétences et efficacité des spécialistes en évaluations ISO/IEC 15408 (ISO/IEC 19896-3:2018)
Le présent document fournit les exigences spécifiques permettant de démontrer la compétence des personnes pour effectuer des évaluations de la sécurité des produits IT conformément à l'ISO/IEC 15408 (toutes les parties) et à l'ISO/IEC 18045.
Varnostne tehnike IT - Zahteve za usposobljenost za preskuševalce in ocenjevalce informacijske varnosti - 3. del: Zahteve glede znanja, veščin in učinkovitosti za ocenjevalce ISO/IEC 15408 (ISO/IEC 19896-3:2018)
Ta dokument določa posebne zahteve za dokazovanje usposobljenosti posameznikov pri
ocenjevanju varnosti izdelkov informacijske tehnologije v skladu s standardom ISO/IEC 15408 (vsi deli) in ISO/IEC 18045.
General Information
Standards Content (Sample)
SLOVENSKI STANDARD
01-maj-2023
Varnostne tehnike IT - Zahteve za usposobljenost za preskuševalce in ocenjevalce
informacijske varnosti - 3. del: Zahteve glede znanja, veščin in učinkovitosti za
ocenjevalce ISO/IEC 15408 (ISO/IEC 19896-3:2018)
IT security techniques - Competence requirements for information security testers and
evaluators - Part 3: Knowledge, skills and effectiveness requirements for ISO/IEC 15408
evaluators (ISO/IEC 19896-3:2018)
IT-Sicherheitstechniken - Kompetenzanforderungen an Tester und Evaluatoren von
Informationssicherheit - Teil 3: Anforderungen an die Kenntnisse, Fähigkeiten und
Effektivität von Evaluatoren nach ISO/IEC 15408 (ISO/IEC 19896-3:2018)
Techniques de sécurité IT - Exigences en matière de compétences des spécialistes en
tests et évaluations de la sécurité de l'information - Partie 3: Exigences en matière de
connaissances, compétences et efficacité des spécialistes en évaluations ISO/IEC
15408 (ISO/IEC 19896-3:2018)
Ta slovenski standard je istoveten z: EN ISO/IEC 19896-3:2023
ICS:
03.100.30 Vodenje ljudi Management of human
resources
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
EUROPEAN STANDARD EN ISO/IEC 19896-3
NORME EUROPÉENNE
EUROPÄISCHE NORM
January 2023
ICS 35.030
English version
IT security techniques - Competence requirements for
information security testers and evaluators - Part 3:
Knowledge, skills and effectiveness requirements for
ISO/IEC 15408 evaluators (ISO/IEC 19896-3:2018)
Techniques de sécurité IT - Exigences en matière de IT-Sicherheitstechniken - Kompetenzanforderungen an
compétences des spécialistes en tests et évaluations de Tester und Evaluatoren von Informationssicherheit -
la sécurité de l'information - Partie 3: Exigences en Teil 3: Anforderungen an die Kenntnisse, Fähigkeiten
matière de connaissances, compétences et efficacité und Effektivität von Evaluatoren nach ISO/IEC 15408
des spécialistes en évaluations ISO/IEC 15408 (ISO/IEC 19896-3:2018)
(ISO/IEC 19896-3:2018)
This European Standard was approved by CEN on 9 January 2023.
CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for
giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical
references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to
any CEN and CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC
Management Centre has the same status as the official versions.
CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.
Contents Page
European foreword . 3
European foreword
The text of ISO/IEC 19896-3:2018 has been prepared by Technical Committee ISO/IEC JTC 1
"Information technology” of the International Organization for Standardization (ISO) and has been
taken over as EN ISO/IEC 19896-3:2023 by Technical Committee CEN-CENELEC/ JTC 13 “Cybersecurity
and Data Protection” the secretariat of which is held by DIN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by July 2023, and conflicting national standards shall be
withdrawn at the latest by July 2023.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN-CENELEC shall not be held responsible for identifying any or all such patent rights.
Any feedback and questions on this document should be directed to the users’ national standards body.
A complete listing of these bodies can be found on the CEN and CENELEC websites.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO/IEC 19896-3:2018 has been approved by CEN-CENELEC as EN ISO/IEC 19896-3:2023
without any modification.
INTERNATIONAL ISO/IEC
STANDARD 19896-3
First edition
2018-08
IT security techniques — Competence
requirements for information security
testers and evaluators —
Part 3:
Knowledge, skills and effectiveness
requirements for ISO/IEC 15408
evaluators
Techniques de sécurité IT — Exigences en matière de compétences des
spécialistes en tests et évaluations de la sécurité de l'information —
Partie 3: Exigences en matière de connaissances, compétences et
efficacité des spécialistes en évaluations ISO/IEC 15408
Reference number
ISO/IEC 19896-3:2018(E)
©
ISO/IEC 2018
ISO/IEC 19896-3:2018(E)
© ISO/IEC 2018
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address
below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Fax: +41 22 749 09 47
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii © ISO/IEC 2018 – All rights reserved
ISO/IEC 19896-3:2018(E)
Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Knowledge . 2
4.1 General . 2
4.2 Knowledge of ISO/IEC 15408 and ISO/IEC 18045 . 2
4.2.1 ISO/IEC 15408-1 . 2
4.2.2 ISO/IEC 15408-2 . 2
4.2.3 ISO/IEC 15408-3 . 2
4.2.4 ISO/IEC 18045 . 3
4.3 Knowledge of the assurance paradigm . 3
4.3.1 Knowledge of the evaluation authority . 3
4.3.2 Knowledge of the evaluation scheme . 3
4.3.3 Knowledge of the laboratory and it’s management system . 4
4.4 Knowledge of information security . 4
4.5 Knowledge of the technology being evaluated . 5
4.5.1 Knowledge of the technology being evaluated . 5
4.5.2 Protection Profiles, packages and supporting documents . 5
4.6 Knowledge required for specific assurance classes . 5
4.7 Knowledge required when evaluating specific security functional requirements. 6
4.8 Knowledge needed when evaluating specific technologies . 6
5 Skills . 6
5.1 Basic evaluation skills . 6
5.1.1 Evaluation methods . . 6
5.1.2 Evaluation tools . 6
5.2 Core evaluation skills given in ISO/IEC 15408-3 and ISO/IEC 18045 . 7
5.2.1 Evaluation principles . 7
5.2.2 Evaluation methods and activities. 7
5.3 Skills required when evaluating specific security assurance classes. 8
5.3.1 General. 8
5.3.2 ADV (Development) Class . 8
5.3.3 AGD (Guidance Documents) Class . 9
5.3.4 ALC (Life-Cycle Support) Class . 9
5.3.5 ASE and APE (ST and PP evaluation) Classes . .10
5.3.6 ATE (Tests) Class . .10
5.3.7 AVA (Vulnerability Assessment) Class .11
5.3.8 ACO (Composition) Class .12
5.4 Skills required when evaluating specific security functional requirement classes .12
5.4.1 General.12
5.4.2 Skills required when evaluating the FCS (Cryptographic support) Class .13
5.5 Skills needed when evaluating specific technologies .13
6 Experience.13
7 Education .
...
Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.