Iso Iec 15408 Pdf |link| -
A document usually written by the vendor that describes the specific security properties of the actual product being evaluated. It maps the product's capabilities to a Protection Profile or a custom set of SFRs.
– Standardized sets of requirements for common product types. 2. Define Your Writing Goals
: Security functional components; lists the technical capabilities required. iso iec 15408 pdf
Getting a product certified under ISO/IEC 15408 is a rigorous, multi-month (and sometimes multi-year) process involving three main parties:
The standard is traditionally divided into several parts. When you download the full ISO/IEC 15408 documentation, you will typically find three core sections: Part 1: Introduction and General Model A document usually written by the vendor that
If you have opened the document, do not try to read it cover-to-cover. Follow this strategy instead:
The official Common Criteria website provides the latest versions of the standard (often referred to as CC version 3.1) and associated documents like Protection Profiles. When you download the full ISO/IEC 15408 documentation,
The first section introduces the Target of Evaluation (TOE). Not "the software." Not "the firewall." The TOE. A term so clinical it could describe a specimen under a microscope. This is the first deep truth of 15408: you cannot secure everything . You must draw a circle in the sand. Inside the circle is order; outside is chaos, the Operational Environment . The document implicitly admits its own failure—it only judges the artifact, never the human holding it.
The specific software, hardware, or firmware product undergoing security evaluation. Protection Profile
The specific product, system, or component being evaluated.
The standard is divided into three distinct parts. When searching for the "PDF" of this standard, one must typically acquire three separate documents: