Overview
EN ISO/IEC 15408-3:2023 (aligned with ISO/IEC 15408-3:2022) is the Part 3 specification of the ISO/IEC 15408 series-commonly known as the Common Criteria. This European adoption by CEN defines the security assurance components used to build evaluation assurance levels (EALs) and assurance packages. It establishes the assurance requirements and the criteria for evaluating Protection Profiles (PPs), PP‑Configurations, PP‑Modules and Security Targets (STs).
Key topics and technical requirements
- Assurance paradigm and evaluation scale: Describes the assurance approach, significance and causes of vulnerabilities, and the ISO/IEC 15408 evaluation assurance scale used to express confidence in security functions.
- Assurance class, family and component structure: Defines how assurance classes are organized into families and individual components, including naming, introductions and objectives.
- Component levelling and dependencies: Components are leveled (to indicate strength/rigor) and include explicit dependencies and application notes to guide evaluation scope.
- Assurance elements: Breaks components down into measurable elements (work units for evaluators) used during evaluation.
- Protection Profile and Security Target evaluation: Contains specific classes (e.g., APE - PP evaluation, ACE - PP‑Module/Configuration evaluation) and components such as APE_INT, APE_CCL, APE_SPD, APE_OBJ, APE_REQ for documenting PP/ST introductions, conformance claims, problem definitions, objectives and requirements.
- Taxonomy and application guidance: Provides a standardized taxonomy and guidance to ensure consistent interpretation across evaluations and national schemes.
Practical applications and users
- Evaluation laboratories and certification bodies use this document to structure and perform conformity assessments against Protection Profiles and Security Targets.
- Product vendors and developers rely on the assurance components to prepare Security Targets and evidence packages that meet required assurance levels.
- Security architects and system integrators consult it to design systems whose security claims can be evaluated and certified.
- Procurement teams and regulators reference the standard when specifying required assurance levels or accepting certified IT products for sensitive environments.
Related standards
- ISO/IEC 15408 (Common Criteria) - the series within which Part 3 sits.
- EN ISO/IEC 15408-5 - defines evaluation assurance levels and packages composed from the components in Part 3.
Keywords: EN ISO/IEC 15408-3:2023, ISO/IEC 15408-3:2022, Common Criteria, security assurance components, Protection Profile evaluation, Security Target, evaluation assurance levels, IT security assurance, cybersecurity standard.