Overview
ISO/IEC 15408-3:2026 is an international standard published by ISO, providing essential criteria for evaluating the security assurance of information technology (IT) products and systems. As part of the ISO/IEC 15408 series, also known as the Common Criteria, Part 3 focuses specifically on the structure and definition of security assurance components. These components form the basis for constructing and evaluating evaluation assurance levels (EALs), Protection Profiles (PPs), PP-Configurations, PP-Modules, and Security Targets (STs).
This standard plays a crucial role in information security, cybersecurity, and privacy protection frameworks, ensuring that IT products are evaluated consistently and robustly for security assurance.
Key Topics
- Security Assurance Paradigm: Defines the key concepts behind security assurance, including the evaluation approach, significance and causes of vulnerabilities, and the tiered evaluation assurance scale.
- Assurance Components Structure: Details the taxonomy and structure for assurance classes, families, and components, and outlines their naming, objectives, application notes, and dependencies.
- Protection Profile (PP) Evaluation: Specifies criteria for the evaluation of PPs, including their introduction, conformance claims, security problem definition, security objectives, extended components, and security requirements rationale.
- PP-Configuration & Module Evaluation: Covers the evaluation approach for PP-Configurations and PP-Modules, including consistency checks and security objectives for modular or composite security targets.
- Security Target (ST) Evaluation: Provides the framework for assessing security targets, including conformance claims, security problem definition, objectives, and component taxonomy.
- Development, Guidance, and Life Cycle Support: Includes criteria for evaluating development processes (e.g., architecture, functional specification), user and operational guidance, and life cycle security (e.g., configuration management, production support).
Applications
ISO/IEC 15408-3:2026 is widely applied in various sectors to:
- Certify IT Products for Security Assurance: Aid evaluators, developers, and regulators in assessing products for information security, cybersecurity, and privacy protection based on internationally recognized criteria.
- Develop Protection Profiles and Security Targets: Provide structured frameworks for vendors creating, documenting, and supporting security claims for their IT products or systems.
- Enhance Procurement Decisions: Support governments, enterprises, and organizations in selecting IT solutions that meet rigorous security assurance requirements.
- Support Regulatory and Compliance Initiatives: Serve as a reference for compliance with national and international security regulations and procurement standards.
- Facilitate Mutual Recognition: Promote interoperability and mutual recognition of security evaluations across countries, enhancing global cybersecurity.
Related Standards
- ISO/IEC 15408-1 - Introduction and general model, setting out the foundation for the entire Common Criteria series.
- ISO/IEC 15408-2 - Security functional components, detailing the functional requirements to be addressed in IT product evaluations.
- ISO/IEC 15408-5 - Providing additional packages, including predefined sets of security assurance and functional requirements.
- ISO/IEC 18045 - Methodology for IT security evaluation, complementing ISO/IEC 15408 by outlining practical evaluation processes.
- ISO/IEC 27001 - Information security management systems, often referenced in broader organizational risk frameworks.
ISO/IEC 15408-3:2026 is an indispensable resource for those responsible for developing, evaluating, procuring, or certifying IT security solutions, providing a clear pathway toward robust and harmonized assurance in cybersecurity and privacy protection.