Overview
SIST EN ISO/IEC 18045:2024, titled Information security, cybersecurity and privacy protection - Evaluation criteria for IT security - Methodology for IT security evaluation, is an international standard developed by CEN in alignment with ISO/IEC 18045:2022. This standard sets out the minimum required actions for evaluators conducting IT security evaluations against the ISO/IEC 15408 series (Common Criteria). SIST EN ISO/IEC 18045:2024 describes a comprehensive methodology for confirming that IT products and systems meet rigorous security requirements, supporting reliable security certifications across various industries.
Key Topics
-
Methodology for IT Security Evaluation
SIST EN ISO/IEC 18045:2024 defines a structured approach for the assessment of IT product and system security. It details the step-by-step methodology evaluators must follow, ensuring consistent, repeatable, and objective evaluations based on ISO/IEC 15408 series requirements.
-
Roles and Responsibilities
The standard clarifies the responsibilities of different stakeholders in the evaluation process, including evaluators, developers, and certifiers, fostering transparency and accountability throughout all evaluation tasks.
-
Evaluation Process and Tasks
The document describes the evaluation process, including input tasks (collecting and managing evaluation evidence), evaluation sub-activities (such as assessment of security objectives, requirements, and design), and output tasks (compiling evaluation results and verdicts).
-
Protection Profiles and Security Targets
SIST EN ISO/IEC 18045:2024 addresses methodologies for the evaluation of Protection Profiles (PPs), PP modules, configurations, and Security Targets (STs), ensuring that both standardized and tailored security needs can be assessed.
-
Life Cycle and Guidance Evaluation
The standard covers essential aspects of product life cycle security and guidance document evaluation, reinforcing confidence in operational and preparative documentation.
Applications
SIST EN ISO/IEC 18045:2024 is widely applicable wherever the security of IT products or systems must be reliably assessed and demonstrated. Key use cases include:
-
Product Certification:
Used by evaluation laboratories and certifying bodies to assess software, hardware, or system security against internationally recognized benchmarks.
-
Procurement and Supply Chains:
Organizations and government agencies rely on products assessed according to SIST EN ISO/IEC 18045:2024 and ISO/IEC 15408 criteria for secure procurement, minimizing security risks in their supply chains.
-
Vendor Assurance:
Developers and suppliers use the standard to structure their security documentation and processes, facilitating smoother engagement with evaluators and customers.
-
Compliance and Regulation:
Helps organizations demonstrate due diligence with respect to international security requirements and privacy protection standards in regulatory or contractual contexts.
-
Cloud and Connected Systems:
Ensures security requirements for emerging areas such as cloud computing, the Internet of Things (IoT), and complex IT system architectures are methodically evaluated and documented.
Related Standards
-
ISO/IEC 15408 Series (Common Criteria):
The foundational set of standards for security evaluation criteria, closely referenced and required for the methodologies outlined in SIST EN ISO/IEC 18045:2024.
-
ISO/IEC 27001:
Focuses on information security management systems, complementary for overall organizational security governance.
-
EN ISO/IEC 29119:
Provides standards on software testing which may intersect with security testing approaches in IT evaluations.
-
ISO/IEC 27034:
Focuses on application security, relevant for evaluating application-specific security requirements.
By adhering to SIST EN ISO/IEC 18045:2024, organizations can ensure their IT security evaluation activities meet globally recognized methodologies, delivering trust and assurance to customers, regulators, and stakeholders through standardized and robust security assessments.