Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Methodology for IT security evaluation (ISO/IEC DIS 18045:2024)

This document defines the minimum actions to be performed by an evaluator in order to conduct an ISO/IEC 15408 series evaluation, using the criteria and evaluation evidence defined in the ISO/IEC 15408 series.

Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre - Evaluationskriterien für IT-Sicherheit - Methodik für die Bewertung der IT-Sicherheit (ISO/IEC DIS 18045:2024)

Sécurité de l'information, cybersécurité et protection de la vie privée - Critères d'évaluation pour la sécurité des technologies de l'information - Méthodologie pour l'évaluation de sécurité (ISO/IEC DIS 18045:2024)

Informacijska varnost, kibernetska varnost in varovanje zasebnosti - Merila za ocenjevanje varnosti IT - Metodologija za ocenjevanje varnosti IT (ISO/IEC DIS 18045:2024)

General Information

Status
Not Published
Publication Date
08-Mar-2026
Current Stage
4060 - Closure of enquiry - Enquiry
Start Date
06-Nov-2024
Completion Date
06-Nov-2024

Relations

Buy Standard

Draft
prEN ISO/IEC 18045:2024
English language
440 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)


SLOVENSKI STANDARD
01-oktober-2024
Informacijska varnost, kibernetska varnost in varovanje zasebnosti - Merila za
ocenjevanje varnosti IT - Metodologija za ocenjevanje varnosti IT (ISO/IEC DIS
18045:2024)
Information security, cybersecurity and privacy protection - Evaluation criteria for IT
security - Methodology for IT security evaluation (ISO/IEC DIS 18045:2024)
Informationssicherheit, Cybersicherheit und Schutz der Privatsphäre -
Evaluationskriterien für IT-Sicherheit - Methodik für die Bewertung der IT-Sicherheit
(ISO/IEC DIS 18045:2024)
Sécurité de l'information, cybersécurité et protection de la vie privée - Critères
d'évaluation pour la sécurité des technologies de l'information - Méthodologie pour
l'évaluation de sécurité (ISO/IEC DIS 18045:2024)
Ta slovenski standard je istoveten z: prEN ISO/IEC 18045
ICS:
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

DRAFT
International
Standard
ISO/IEC DIS 18045
ISO/IEC JTC 1/SC 27
Information security, cybersecurity
Secretariat: DIN
and privacy protection —
Voting begins on:
Evaluation criteria for IT security
2024-08-14
— Methodology for IT security
Voting terminates on:
evaluation
2024-11-06
Sécurité de l'information, cybersécurité et protection de la vie
privée — Critères d'évaluation pour la sécurité des technologies
de l'information — Méthodologie pour l'évaluation de sécurité
ICS: 35.030
THIS DOCUMENT IS A DRAFT CIRCULATED
FOR COMMENTS AND APPROVAL. IT
IS THEREFORE SUBJECT TO CHANGE
AND MAY NOT BE REFERRED TO AS AN
INTERNATIONAL STANDARD UNTIL
PUBLISHED AS SUCH.
This document is circulated as received from the committee secretariat.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL,
TECHNOLOGICAL, COMMERCIAL AND
USER PURPOSES, DRAFT INTERNATIONAL
STANDARDS MAY ON OCCASION HAVE TO
ISO/CEN PARALLEL PROCESSING
BE CONSIDERED IN THE LIGHT OF THEIR
POTENTIAL TO BECOME STANDARDS TO
WHICH REFERENCE MAY BE MADE IN
NATIONAL REGULATIONS.
RECIPIENTS OF THIS DRAFT ARE INVITED
TO SUBMIT, WITH THEIR COMMENTS,
NOTIFICATION OF ANY RELEVANT PATENT
RIGHTS OF WHICH THEY ARE AWARE AND TO
PROVIDE SUPPORTING DOCUMENTATION.
Reference number
© ISO/IEC 2024
ISO/IEC DIS 18045:2024(en)
DRAFT
ISO/IEC DIS 18045:2024(en)
International
Standard
ISO/IEC DIS 18045
ISO/IEC JTC 1/SC 27
Information security, cybersecurity
Secretariat: DIN
and privacy protection —
Voting begins on:
Evaluation criteria for IT security
— Methodology for IT security
Voting terminates on:
evaluation
Sécurité de l'information, cybersécurité et protection de la vie
privée — Critères d'évaluation pour la sécurité des technologies
de l'information — Méthodologie pour l'évaluation de sécurité
ICS: 35.030
THIS DOCUMENT IS A DRAFT CIRCULATED
FOR COMMENTS AND APPROVAL. IT
IS THEREFORE SUBJECT TO CHANGE
AND MAY NOT BE REFERRED TO AS AN
INTERNATIONAL STANDARD UNTIL
PUBLISHED AS SUCH.
This document is circulated as received from the committee secretariat.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL,
© ISO/IEC 2024
TECHNOLOGICAL, COMMERCIAL AND
USER PURPOSES, DRAFT INTERNATIONAL
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
STANDARDS MAY ON OCCASION HAVE TO
ISO/CEN PARALLEL PROCESSING
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
BE CONSIDERED IN THE LIGHT OF THEIR
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
POTENTIAL TO BECOME STANDARDS TO
WHICH REFERENCE MAY BE MADE IN
or ISO’s member body in the country of the requester.
NATIONAL REGULATIONS.
ISO copyright office
RECIPIENTS OF THIS DRAFT ARE INVITED
CP 401 • Ch. de Blandonnet 8
TO SUBMIT, WITH THEIR COMMENTS,
CH-1214 Vernier, Geneva
NOTIFICATION OF ANY RELEVANT PATENT
Phone: +41 22 749 01 11
RIGHTS OF WHICH THEY ARE AWARE AND TO
PROVIDE SUPPORTING DOCUMENTATION.
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2024
ISO/IEC DIS 18045:2024(en)
© ISO/IEC 2024 – All rights reserved
ii
ISO/IEC DIS 18045:2024(en)
Contents Page
Foreword .vii
Introduction .ix
1 Scope . 1
2 Normative references . 1
3 Terms, definitions and abbreviated terms . 1
4 Terminology . . 4
5 Verb usage . 4
6 General evaluation guidance . 4
7 Relationship between the ISO/IEC 15408 series and ISO/IEC 18045 structures . 4
8 Evaluation process and related tasks . 5
8.1 General .5
8.2 Evaluation process overview . .6
8.2.1 Objectives .6
8.2.2 Responsibilities of the roles .6
8.2.3 Relationship of roles .6
8.2.4 General evaluation model .6
8.2.5 Evaluator verdicts .7
8.3 Evaluation input task .9
8.3.1 Objectives .9
8.3.2 Application notes .9
8.3.3 Management of evaluation evidence sub-task .10
8.4 Evaluation sub-activities .10
8.5 Evaluation output task .10
8.5.1 Objectives .10
8.5.2 Management of evaluation outputs .11
8.5.3 Application notes .11
8.5.4 Write OR sub-task .11
8.5.5 Write ETR sub-task .11
9 Class APE Protection Profile (PP) evaluation .18
9.1 Introduction .18
9.1.1 Re-using the evaluation results of certified PPs .18
9.2 Conformance claims (APE_CCL) .19
9.2.1 Evaluation of sub-activity (APE_CCL.1) .19
9.3 Extended components definition (APE_ECD) . 29
9.3.1 Evaluation of sub-activity (APE_ECD.1) . 29
9.4 PP introduction (APE_INT) . 33
9.4.1 Evaluation of sub-activity (APE_INT.1) . 33
9.5 Security objectives (APE_OBJ) . 34
9.5.1 Evaluation of sub-activity (APE_OBJ.1) . 34
9.5.2 Evaluation of sub-activity (APE_OBJ.2) . 36
9.6 Security requirements (APE_REQ) . 38
9.6.1 Evaluation of sub-activity (APE_REQ.1) . 38
9.6.2 Evaluation of sub-activity (APE_REQ.2). 44
9.7 Security problem definition (APE_SPD) . 48
9.7.1 Evaluation of sub-activity (APE_SPD.1) . 48
10 Class ACE Protection Profile Configuration evaluation .50
10.1 Introduction . 50
10.2 PP-Module conformance claims (ACE_CCL) .51
10.2.1 Evaluation of sub-activity (ACE_CCL.1) .51
10.3 PP-Configuration consistency (ACE_CCO) .57
10.3.1 Evaluation of sub-activity (ACE_CCO.1) .57

© ISO/IEC 2024 – All rights reserved
iii
ISO/IEC DIS 18045:2024(en)
10.4 PP-Module extended components definition (ACE_ECD). 65
10.4.1 Evaluation of sub-activity (ACE_ECD.1) . 65
10.5 PP-Module introduction (ACE_I
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.