SANS 15408-3-2009 Information technology - Security techniques - Evaluation criteria for IT security Part 3 Security assurance components《信息技术 安全技术 IT安全性评价标准 第3部分 安全保证组件》.pdf
《SANS 15408-3-2009 Information technology - Security techniques - Evaluation criteria for IT security Part 3 Security assurance components《信息技术 安全技术 IT安全性评价标准 第3部分 安全保证组件》.pdf》由会员分享,可在线阅读,更多相关《SANS 15408-3-2009 Information technology - Security techniques - Evaluation criteria for IT security Part 3 Security assurance components《信息技术 安全技术 IT安全性评价标准 第3部分 安全保证组件》.pdf(188页珍藏版)》请在麦多课文档分享上搜索。
1、 Collection of SANS standards in electronic format (PDF) 1. Copyright This standard is available to staff members of companies that have subscribed to the complete collection of SANS standards in accordance with a formal copyright agreement. This document may reside on a CENTRAL FILE SERVER or INTRA
2、NET SYSTEM only. Unless specific permission has been granted, this document MAY NOT be sent or given to staff members from other companies or organizations. Doing so would constitute a VIOLATION of SABS copyright rules. 2. Indemnity The South African Bureau of Standards accepts no liability for any
3、damage whatsoever than may result from the use of this material or the information contain therein, irrespective of the cause and quantum thereof. ISBN 978-0-626-22332-8 SANS 15408-3:2009 Edition 3 ISO/IEC 15408-3: 2008 Edition 3 SOUTH AFRICAN NATIONAL STANDARD Information technology Security techni
4、ques Evaluation criteria for IT security Part 3: Security assurance components This national standard is the identical implementation of ISO/IEC 15408-3:2008 and is adopted with the permission of the International Organization for Standardization and the International Electrotechnical Commission. Pu
5、blished by SABS Standards Division 1 Dr Lategan Road Groenkloof envelopeback Private Bag X191 Pretoria 0001 Tel: +27 12 428 7911 Fax: +27 12 344 1568 www.sabs.co.za SABS SANS 15408-3:2009 Edition 3 ISO/IEC 15408-3:2008 Edition 3 Table of changes Change No. Date Scope National foreword This South Afr
6、ican standard was approved by National Committee SABS SC 71F, Information technology - Information security, in accordance with procedures of the SABS Standards Division, in compliance with annex 3 of the WTO/TBT agreement. This SANS document was published in June 2009. This SANS document supersedes
7、 SANS 15408-3:2007(edition 2). Reference numberISO/IEC 15408-3:2008(E)ISO/IEC 2008INTERNATIONAL STANDARD ISO/IEC15408-3Third edition2008-08-15Information technology Security techniques Evaluation criteria for IT security Part 3: Security assurance components Technologies de linformation Techniques d
8、e scurit Critres dvaluation pour la scurit TI Partie 3: Composants dassurance de scurit SANS 15408-3:2009This s tandard may only be used and printed by approved subscription and freemailing clients of the SABS .ISO/IEC 15408-3:2008(E) PDF disclaimer This PDF file may contain embedded typefaces. In a
9、ccordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobe
10、s licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for p
11、rinting. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. COPYRIGHT PROTECTED DOCUMENT ISO/IEC 2008 All rights reserved. Unless o
12、therwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISOs member body in the country of the requester. ISO copyr
13、ight office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail copyrightiso.org Web www.iso.org Published in Switzerland ii ISO/IEC 2008 All rights reservedSANS 15408-3:2009This s tandard may only be used and printed by approved subscription and freemailing clients
14、 of the SABS .ISO/IEC 15408-3:2008(E) ISO/IEC 2008 All rights reserved iiiContents Page 1 Scope 1 2 Normative references 1 3 Terms and definitions, symbols and abbreviated terms . 1 4 Overview . 1 4.1 Organisation of this part of ISO/IEC 15408 . 1 5 Assurance paradigm . 2 5.1 ISO/IEC 15408 philosoph
15、y 2 5.2 Assurance approach . 2 5.2.1 Significance of vulnerabilities 2 5.2.2 Cause of vulnerabilities 3 5.2.3 ISO/IEC 15408 assurance 3 5.2.4 Assurance through evaluation . 3 5.3 ISO/IEC 15408 evaluation assurance scale. 3 6 Security assurance components . 4 6.1 Security assurance classes, families
16、and components structure . 4 6.1.1 Assurance class structure 4 6.1.2 Assurance family structure 5 6.1.3 Assurance component structure . 6 6.1.4 Assurance elements 8 6.1.5 Component taxonomy . 8 6.2 EAL structure . 8 6.2.1 EAL name . 9 6.2.2 Objectives 9 6.2.3 Application notes 9 6.2.4 Assurance comp
17、onents 9 6.2.5 Relationship between assurances and assurance levels . 10 6.3 CAP structure 10 6.3.1 CAP name . 11 6.3.2 Objectives 11 6.3.3 Application notes 11 6.3.4 Assurance components 11 6.3.5 Relationship between assurances and assurance levels . 12 7 Evaluation assurance levels 12 7.1 Evaluati
18、on assurance level (EAL) overview . 13 7.2 Evaluation assurance level details 14 7.3 Evaluation assurance level 1 (EAL1) - functionally tested 14 7.3.1 Objectives 14 7.3.2 Assurance components 15 7.4 Evaluation assurance level 2 (EAL2) - structurally tested 15 7.4.1 Objectives 15 7.4.2 Assurance com
19、ponents 15 7.5 Evaluation assurance level 3 (EAL3) - methodically tested and checked . 16 7.5.1 Objectives 16 7.5.2 Assurance components 16 7.6 Evaluation assurance level 4 (EAL4) - methodically designed, tested, and reviewed . 17 7.6.1 Objectives 17 7.6.2 Assurance components 17 7.7 Evaluation assu
20、rance level 5 (EAL5) - semiformally designed and tested . 18 7.7.1 Objectives 18 7.7.2 Assurance components 18 7.8 Evaluation assurance level 6 (EAL6) - semiformally verified design and tested 19 SANS 15408-3:2009This s tandard may only be used and printed by approved subscription and freemailing cl
21、ients of the SABS .ISO/IEC 15408-3:2008(E) iv ISO/IEC 2008 All rights reserved7.8.1 Objectives 19 7.8.2 Assurance components . 19 7.9 Evaluation assurance level 7 (EAL7) - formally verified design and tested . 20 7.9.1 Objectives 20 7.9.2 Assurance components . 20 8 Composed assurance packages . 21
22、8.1 Composed assurance package (CAP) overview . 22 8.2 Composed assurance package details 23 8.3 Composition assurance level A (CAP-A) - Structurally composed . 23 8.3.1 Objectives 23 8.3.2 Assurance components . 23 8.4 Composition assurance level B (CAP-B) - Methodically composed . 24 8.4.1 Objecti
23、ves 24 8.4.2 Assurance components . 24 8.5 Composition assurance level C (CAP-C) - Methodically composed, tested and reviewed 25 8.5.1 Objectives 25 8.5.2 Assurance components . 25 9 Class APE: Protection Profile evaluation . 26 9.1 PP introduction (APE_INT) 27 9.1.1 Objectives 27 9.1.2 APE_INT.1 PP
24、 introduction 27 9.2 Conformance claims (APE_CCL) 27 9.2.1 Objectives 27 9.2.2 APE_CCL.1 Conformance claims 27 9.3 Security problem definition (APE_SPD) . 29 9.3.1 Objectives 29 9.3.2 APE_SPD.1 Security problem definition 29 9.4 Security objectives (APE_OBJ) . 30 9.4.1 Objectives 30 9.4.2 Component
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- SANS1540832009INFORMATIONTECHNOLOGYSECURITYTECHNIQUESEVALUATIONCRITERIAFORITSECURITYPART3SECURITYASSURANCECOMPONENTS

链接地址:http://www.mydoc123.com/p-1029445.html