Overview
SIST EN ISO/IEC 15408-2:2024 (Information security, cybersecurity, and privacy protection - Evaluation criteria for IT security - Part 2: Security functional components) is an internationally recognized European standard developed by CEN under the ISO/IEC 15408 series. This standard delineates the structure and requirements for security functional components in IT security evaluation, supporting consistent, systematic assessments of IT products and systems. It is a cornerstone for organizations aiming to achieve robust information security, cybersecurity, and privacy protection compliance.
Key Topics
SIST EN ISO/IEC 15408-2:2024 provides a comprehensive framework for defining and cataloguing security functional requirements (SFRs) applicable to the evaluation of IT products (referred to as Targets of Evaluation). Key features include:
- Standardized Structure: The document details a well-structured organization of security functional components to facilitate uniformity in security evaluations.
- Component Catalogue: It includes a detailed catalogue of functional components addressing common requirements across information security, cybersecurity, and privacy contexts.
- Functional Classes: Functional components are organized into classes such as:
- Security audit
- Communication
- Cryptographic support
- User data protection
- Component Consistency: Ensures consistent application and interpretation of security functionality requirements for IT products.
- Evaluation Basis: Supports formulation of Security Targets and Protection Profiles, which are essential documents in the IT security certification process.
Applications
SIST EN ISO/IEC 15408-2:2024 is valuable across many sectors where robust information security, cybersecurity, and privacy enforcement are critical. Practical applications include:
- Product Evaluation: Used by certification bodies, evaluators, and developers to assess whether IT products meet international security requirements.
- Security Target Development: Helps organizations specify precisely which security functionalities their IT system or product will offer and under which conditions.
- Procurement and Compliance: Enables governments, corporations, and other stakeholders to select products that have been evaluated according to recognized international security standards.
- Protection Profile Authoring: Provides a modular approach for creating Protection Profiles, supporting reusable security requirement sets for product categories.
- Regulatory Adherence: Assists organizations in meeting data protection and privacy regulations by ensuring IT systems incorporate essential security functionalities.
Related Standards
SIST EN ISO/IEC 15408-2:2024 forms part of the broader ISO/IEC 15408 (Common Criteria) series and is closely integrated with the following standards:
- EN ISO/IEC 15408-1: Introduction and general model - Provides the foundational models and terms for IT security evaluation.
- EN ISO/IEC 15408-3: Security assurance components - Specifies the assurance requirements to complement the functional requirements of Part 2.
- ISO/IEC 18045: Evaluation methodology for IT security - Outlines how to apply evaluation criteria in practice.
- Related European and international standards for IT security, risk management, and privacy protection.
By following SIST EN ISO/IEC 15408-2:2024, organizations benefit from globally accepted practices for defining, assessing, and verifying security functionalities in IT products. This standard is essential for building trust in technology through certified assurance of information security, cybersecurity, and privacy protection.