热门站点| 世界资料网 | 专利资料网 | 世界资料网论坛
收藏本站| 设为首页| 首页

ISO/IEC 15408-1-2005 信息技术.安全技术.IT安全的评价标准.第1部分:介绍和一般模型

作者:标准资料网 时间:2024-05-15 00:12:25  浏览:8441   来源:标准资料网
下载地址: 点击此处下载
【英文标准名称】:Informationtechnology-Securitytechniques-EvaluationcriteriaforITsecurity-Part1:Introductionandgeneralmodel
【原文标准名称】:信息技术.安全技术.IT安全的评价标准.第1部分:介绍和一般模型
【标准号】:ISO/IEC15408-1-2005
【标准状态】:作废
【国别】:国际
【发布日期】:2005-10
【实施或试行日期】:
【发布单位】:国际标准化组织(IX-ISO)
【起草单位】:ISO/IECJTC1/SC27
【标准类型】:()
【标准水平】:()
【中文主题词】:置信区间;数据处理;数据保护;数据安全;数据传输;定义;信息交换;信息技术;信任等级;模型;特性;可靠度;安全
【英文主题词】:Confidenceintervals;Dataexchange;Dataprocessing;Dataprotection;Datasecurity;Datatransmission;Definitions;Englishlanguage;Evaluations;Informationexchange;Informationinterchange;Informationtechnology;ITsecurity;Levelofconfidence;Models;Properties;Reliability;Safety
【摘要】:ISO/IEC15408ismeanttobeusedasthebasisforevaluationofsecuritypropertiesofITproductsandsystems.Byestablishingsuchacommoncriteriabase,theresultsofanITsecurityevaluationwillbemeaningfultoawideraudience.Certaintopics,becausetheyinvolvespecializedtechniquesorbecausetheyaresomewhatperipheraltoITsecurity,areconsideredtobeoutsidethescopeofISO/IEC15408.Someoftheseareidentifiedbelow:a)ISO/IEC15408doesnotcontainsecurityevaluationcriteriapertainingtoadministrativesecuritymeasuresnotrelateddirectlytotheITsecuritymeasures.However,itisrecognisedthatasignificantpartofthesecurityofaTOEcanoftenbeachievedthroughadministrativemeasuressuchasorganisational,personnel,physical,andproceduralcontrols.AdministrativesecuritymeasuresintheoperatingenvironmentoftheTOEaretreatedassecureusageassumptionswherethesehaveanimpactontheabilityoftheITsecuritymeasurestocountertheidentifiedthreats.b)TheevaluationoftechnicalphysicalaspectsofITsecuritysuchaselectromagneticemanationcontrolisnotspecificallycovered,althoughmanyoftheconceptsaddressedwillbeapplicabletothatarea.Inparticular,ISO/IEC15408addressessomeaspectsofphysicalprotectionoftheTOE.c)ISO/IEC15408addressesneithertheevaluationmethodologynortheadministrativeandlegalframeworkunderwhichthecriteriamaybeappliedbyevaluationauthorities.However,itisexpectedthatISO/IEC15408willbeusedforevaluationpurposesinthecontextofsuchaframeworkandsuchamethodology.d)TheproceduresforuseofevaluationresultsinproductorsystemaccreditationareoutsidethescopeofISO/IEC15408.ProductorsystemaccreditationistheadministrativeprocesswherebyauthorityisgrantedfortheoperationofanITproductorsysteminitsfulloperationalenvironment.EvaluationfocusesontheITsecuritypartsoftheproductorsystemandthosepartsoftheoperationalenvironmentthatmaydirectlyaffectthesecureuseofITelements.Theresultsoftheevaluationprocessareconsequentlyavaluableinputtotheaccreditationprocess.However,asothertechniquesaremoreappropriatefortheassessmentsofnon-ITrelatedproductorsystemsecuritypropertiesandtheirrelationshiptotheITsecurityparts,accreditorsshouldmakeseparateprovisionforthoseaspects.e)ThesubjectofcriteriafortheassessmentoftheinherentqualitiesofcryptographicalgorithmsisnotcoveredinISO/IEC15408.ShouldindependentassessmentofmathematicalpropertiesofcryptographyembeddedinaTOEberequired,theevaluationschemeunderwhichISO/IEC15408isappliedmustmakeprovisionforsuchassessments.Informationtechnology—Securitytechniques—EvaluationcriteriaforITsecurity—Part1:IntroductionandgeneralmodelThispartofISO/IEC15408definestwoformsforexpressingITsecurityfunctionalandassurancerequirements.Theprotectionprofile(PP)constructallowscreationofgeneralizedreusablesetsofthesesecurityrequirements.ThePPcanbeusedbyprospectiveconsumersforspecificationandidentificationofproductswithITsecurityfeatureswhichwillmeettheirneeds.Thesecuritytarget(ST)expressesthesecurityrequirementsandspecifiesthesecurityfunctionsforaparticularproductorsystemtobeevaluated,calledthetargetofevaluation(TOE).TheSTisusedbyevaluatorsasthebasisforevaluationsconductedinaccordancewithISO/IEC15408.
【中国标准分类号】:L70
【国际标准分类号】:35_040
【页数】:41P;A4
【正文语种】:英语


下载地址: 点击此处下载
MIL-G-9954A (AMENDMENT 3), MILITARY SPECIFICATION: GLASS BEADS: FOR CLEANING AND PEENING (15 OCT 1987) [S/S BY MIL-PRF-9954B]., This specification covers glass beads to be used with pressure/suction type blasting equipment.【英文标准名称】:GuideforAluminumHullWelding
【原文标准名称】:铝制船体焊接指南
【标准号】:ANSI/AWSD3.7-2003
【标准状态】:作废
【国别】:美国
【发布日期】:2003
【实施或试行日期】:
【发布单位】:美国国家标准学会(ANSI)
【起草单位】:ANSI
【标准类型】:()
【标准水平】:()
【中文主题词】:焊接工艺;铝;焊接工程
【英文主题词】:weldingprocesses;weldingengineering;aluminium
【摘要】:
【中国标准分类号】:J33
【国际标准分类号】:
【页数】:
【正文语种】:英语



版权声明:所有资料均为作者提供或网友推荐收集整理而来,仅供爱好者学习和研究使用,版权归原作者所有。
如本站内容有侵犯您的合法权益,请和我们取得联系,我们将立即改正或删除。
京ICP备14017250号-1