首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
制定中 prEN ISO/IEC 15408-5
到馆提醒
收藏跟踪
购买正版
Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Part 5: Pre-defined packages of security requirements (ISO/IEC DIS 15408-5:2024) 信息安全、网络安全和隐私保护-IT安全评估标准第5部分:预定义的安全要求包
本文档提供了一系列安全保证和安全功能要求,这些要求已被确定为有助于支持利益相关者的共同使用。 示例所提供的包的示例包括评估保证级别(EAL)和组合保证包(CAP)。 本文件介绍: --评估保证级别(EAL)包系列,指定了可在PP和ST中引用的预定义安全保证组件集,并指定了在评估目标(TOE)评估期间提供的适当安全保证; --组合保证(CAP)包系列,指定了用于指定在组合TOE评估期间提供的适当安全保证的安全保证组件集; --复合产品(COMP)包,指定了一组安全保证组件,用于指定在评估复合产品TOE期间提供的适当安全保证; --保护配置文件保证(PPA)包系列,指定了用于指定在保护配置文件评估期间提供的适当安全保证的安全保证组件集; --安全目标保证(STA)包系列,指定了用于指定在安全目标评估期间提供的适当安全保证的安全保证组件集。 本文档的用户可以包括安全IT产品的消费者、开发人员和评估人员。
This document provides packages of security assurance and security functional requirements that have been identified as useful in support of common usage by stakeholders. EXAMPLE        Examples of provided packages include the evaluation assurance levels (EAL) and the composed assurance packages (CAPs). This document presents: —    evaluation assurance level (EAL) family of packages that specify pre-defined sets of security assurance components that may be referenced in PPs and STs and which specify appropriate security assurances to be provided during an evaluation of a target of evaluation (TOE); —    composition assurance (CAP) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during an evaluation of composed TOEs; —    composite product (COMP) package that specifies a set of security assurance components used for specifying appropriate security assurances to be provided during an evaluation of a composite product TOEs; —    protection profile assurance (PPA) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during a protection profile evaluation; —    security target assurance (STA) family of packages that specify sets of security assurance components used for specifying appropriate security assurances to be provided during a security target evaluation. The users of this document can include consumers, developers, and evaluators of secure IT products.
分类信息
关联关系
研制信息
归口单位: CEN/CLC/JTC 13
相似标准/计划/法规
现行
ISO/IEC 15408-5-2022
Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 5: Pre-defined packages of security requirements
信息安全、网络安全和隐私保护.IT安全评估标准.第5部分:预先定义的安全要求包
2022-08-09
现行
GB/T 18336.5-2024
网络安全技术 信息技术安全评估准则 第5部分:预定义的安全要求包
Cybersecurity technology—Evaluation criteria for IT security—Part 5:Pre-defined packages of security requirements
2024-04-25
现行
ISO/IEC 20897-1-2020
Information security, cybersecurity and privacy protection — Physically unclonable functions — Part 1: Security requirements
信息安全、网络安全和隐私保护物理上不可关闭的功能第1部分:安全要求
2020-12-09
现行
ISO/IEC TS 23532-1-2021
Information security, cybersecurity and privacy protection — Requirements for the competence of IT security testing and evaluation laboratories — Part 1: Evaluation for ISO/IEC 15408
信息安全、网络安全和隐私保护IT安全测试和评估实验室的能力要求第1部分:ISO/IEC 15408的评估
2021-11-12
现行
ISO/IEC TS 23532-2-2021
Information security, cybersecurity and privacy protection — Requirements for the competence of IT security testing and evaluation laboratories — Part 2: Testing for ISO/IEC 19790
信息安全、网络安全和隐私保护IT安全测试和评估实验室的能力要求第2部分:ISO/IEC 19790的测试
2021-11-12