DIN ISO/IEC 15408-1-2007 信息技术.安全技术.IT安全的评价标准.第1部分:引言和一般模型
作者:标准资料网 时间:2024-05-13 08:08:45 浏览:9801
来源:标准资料网
下载地址: 点击此处下载
【英文标准名称】:Informationtechnology-Securitytechniques-EvaluationcriteriaforITsecurity-Part1:Introductionandgeneralmodel(ISO/IEC15408-1:2005);TextinEnglish
【原文标准名称】:信息技术.安全技术.IT安全的评价标准.第1部分:引言和一般模型
【标准号】:DINISO/IEC15408-1-2007
【标准状态】:作废
【国别】:德国
【发布日期】:2007-11
【实施或试行日期】:
【发布单位】:德国标准化学会(DE-DIN)
【起草单位】:
【标准类型】:()
【标准水平】:()
【中文主题词】:置信区间;数据交换;数据处理;数据保护;数据安全;数据传输;定义;英语;评估;信息交流;信息交换;信息技术;IT安全;信用等级;模型;性能;可靠度;安全
【英文主题词】:Confidenceintervals;Dataexchange;Dataprocessing;Dataprotection;Datasecurity;Datatransmission;Definition;Definitions;Englishlanguage;Evaluations;Informationexchange;Informationinterchange;Informationtechnology;ITsecurity;Levelofconfidence;Models;Properties;Reliability;Safety
【摘要】:Thismultipartstandard,"EvaluationcriteriaforITsecurity",ismeanttobeusedasthebasisforevaluationofsecuritypropertiesofITproductsandsystems.Byestablishingsuchacommoncriteriabase,theresultsofanITsecurityevaluationwillbemeaningfultoawideraudience.Certaintopics,becausetheyinvolvespecializedtechniquesorbecausetheyaresomewhatperipheraltoITsecurity,areconsideredtobeoutsidethescopeofISO/IEC15408.Someoftheseareidentifiedbelow:b)ISO/IEC15408doesnotcontainsecurityevaluationcriteriapertainingtoadministrativesecuritymeasuresnotrelateddirectlytotheITsecuritymeasures.However,itisrecognisedthatasignificantpartofthesecurityofaTOEcanoftenbeachievedthroughadministrativemeasuressuchasorganisational,personnel,physical,andproceduralcontrols.AdministrativesecuritymeasuresintheoperatingenvironmentoftheTOEaretreatedassecureusageassumptionswherethesehaveanimpactontheabilityoftheITsecuritymeasurestocountertheidentifiedthreats.c)TheevaluationoftechnicalphysicalaspectsofITsecuritysuchaselectromagneticemanationcontrolisnotspecificallycovered,althoughmanyoftheconceptsaddressedwillbeapplicabletothatarea.Inparticular,ISO/IEC15408addressessomeaspectsofphysicalprotectionoftheTOE.d)ISO/IEC15408addressesneithertheevaluationmethodologynortheadministrativeandlegalframeworkunderwhichthecriteriamaybeappliedbyevaluationauthorities.However,itisexpectedthatISO/IEC15408willbeusedforevaluationpurposesinthecontextofsuchaframeworkandsuchamethodology.e)TheproceduresforuseofevaluationresultsinproductorsystemaccreditationareoutsidethescopeofISO/IEC15408.ProductorsystemaccreditationistheadministrativeprocesswherebyauthorityisgrantedfortheoperationofanITproductorsysteminitsfulloperationalenvironment.EvaluationfocusesontheITsecuritypartsoftheproductorsystemandthosepartsoftheoperationalenvironmentthatmaydirectlyaffectthesecureuseofITelements.Theresultsoftheevaluationprocessareconsequentlyavaluableinputtotheaccreditationprocess.However,asothertechniquesaremoreappropriatefortheassessmentsofnon-ITrelatedproductorsystemsecuritypropertiesandtheirrelationshiptotheITsecurityparts,accreditorsshouldmakeseparateprovisionforthoseaspects.f)ThesubjectofcriteriafortheassessmentoftheinherentqualitiesofcryptographicalgorithmsisnotcoveredinISO/IEC15408.ShouldindependentassessmentofmathematicalpropertiesofcryptographyembeddedinaTOEberequired,theevaluationschemeunderwhichISO/IEC15408isappliedmustmakeprovisionforsuchassessments.
【中国标准分类号】:L70
【国际标准分类号】:35_040
【页数】:59P.;A4
【正文语种】:英语
【原文标准名称】:信息技术.安全技术.IT安全的评价标准.第1部分:引言和一般模型
【标准号】:DINISO/IEC15408-1-2007
【标准状态】:作废
【国别】:德国
【发布日期】:2007-11
【实施或试行日期】:
【发布单位】:德国标准化学会(DE-DIN)
【起草单位】:
【标准类型】:()
【标准水平】:()
【中文主题词】:置信区间;数据交换;数据处理;数据保护;数据安全;数据传输;定义;英语;评估;信息交流;信息交换;信息技术;IT安全;信用等级;模型;性能;可靠度;安全
【英文主题词】:Confidenceintervals;Dataexchange;Dataprocessing;Dataprotection;Datasecurity;Datatransmission;Definition;Definitions;Englishlanguage;Evaluations;Informationexchange;Informationinterchange;Informationtechnology;ITsecurity;Levelofconfidence;Models;Properties;Reliability;Safety
【摘要】:Thismultipartstandard,"EvaluationcriteriaforITsecurity",ismeanttobeusedasthebasisforevaluationofsecuritypropertiesofITproductsandsystems.Byestablishingsuchacommoncriteriabase,theresultsofanITsecurityevaluationwillbemeaningfultoawideraudience.Certaintopics,becausetheyinvolvespecializedtechniquesorbecausetheyaresomewhatperipheraltoITsecurity,areconsideredtobeoutsidethescopeofISO/IEC15408.Someoftheseareidentifiedbelow:b)ISO/IEC15408doesnotcontainsecurityevaluationcriteriapertainingtoadministrativesecuritymeasuresnotrelateddirectlytotheITsecuritymeasures.However,itisrecognisedthatasignificantpartofthesecurityofaTOEcanoftenbeachievedthroughadministrativemeasuressuchasorganisational,personnel,physical,andproceduralcontrols.AdministrativesecuritymeasuresintheoperatingenvironmentoftheTOEaretreatedassecureusageassumptionswherethesehaveanimpactontheabilityoftheITsecuritymeasurestocountertheidentifiedthreats.c)TheevaluationoftechnicalphysicalaspectsofITsecuritysuchaselectromagneticemanationcontrolisnotspecificallycovered,althoughmanyoftheconceptsaddressedwillbeapplicabletothatarea.Inparticular,ISO/IEC15408addressessomeaspectsofphysicalprotectionoftheTOE.d)ISO/IEC15408addressesneithertheevaluationmethodologynortheadministrativeandlegalframeworkunderwhichthecriteriamaybeappliedbyevaluationauthorities.However,itisexpectedthatISO/IEC15408willbeusedforevaluationpurposesinthecontextofsuchaframeworkandsuchamethodology.e)TheproceduresforuseofevaluationresultsinproductorsystemaccreditationareoutsidethescopeofISO/IEC15408.ProductorsystemaccreditationistheadministrativeprocesswherebyauthorityisgrantedfortheoperationofanITproductorsysteminitsfulloperationalenvironment.EvaluationfocusesontheITsecuritypartsoftheproductorsystemandthosepartsoftheoperationalenvironmentthatmaydirectlyaffectthesecureuseofITelements.Theresultsoftheevaluationprocessareconsequentlyavaluableinputtotheaccreditationprocess.However,asothertechniquesaremoreappropriatefortheassessmentsofnon-ITrelatedproductorsystemsecuritypropertiesandtheirrelationshiptotheITsecurityparts,accreditorsshouldmakeseparateprovisionforthoseaspects.f)ThesubjectofcriteriafortheassessmentoftheinherentqualitiesofcryptographicalgorithmsisnotcoveredinISO/IEC15408.ShouldindependentassessmentofmathematicalpropertiesofcryptographyembeddedinaTOEberequired,theevaluationschemeunderwhichISO/IEC15408isappliedmustmakeprovisionforsuchassessments.
【中国标准分类号】:L70
【国际标准分类号】:35_040
【页数】:59P.;A4
【正文语种】:英语
下载地址: 点击此处下载