The Security Target is the document produced by a vendor that identifies the specific security features and claims for their product, along with the claims of assurance that the evaluation will confirm.
ISO/IEC 15408 remains the benchmark for security evaluation. By obtaining the , organizations can align their security development lifecycle with international standards, ensuring products are not only functional but also secure and trusted. If you'd like, I can:
The standard is divided into three distinct parts. When searching for the "PDF" of this standard, one must typically acquire three separate documents: iso iec 15408 pdf
Sets out the foundational concepts, definitions, and the evaluation framework.
Do you need assistance understanding how to write a ? Share public link The Security Target is the document produced by
A key strength of the Common Criteria is international cooperation through the . Member countries (including the US, UK, Canada, Germany, France, Japan, and many others) agree to mutually recognize each other's Common Criteria certificates. This means that if your smartcard product receives a certification from a lab in Germany, that same certification is automatically accepted in Japan, significantly reducing barriers to international trade.
The document specifying the exact security properties and mechanisms of the TOE. It acts as the contract between the vendor and the evaluator. If you'd like, I can: The standard is
This article serves as both. Below, we will explore what ISO/IEC 15408 is, how to legally access the PDF, its structure, and why it matters for your organization.
Defines the methodology for determining if the security features are effective.
ISO/IEC 15408 is the international standard for IT security evaluation. Globally known as the Common Criteria (CC), this standard provides a structured framework for validating that computer security products meet specific claims.
October 26, 2023 Subject: Overview and Analysis of ISO/IEC 15408 (Common Criteria for Information Technology Security Evaluation)
You can find a more exhaustive list of contributers on the wiki.