ISO/IEC 18045:2008 信息技术 安全技术 IT安全评估方法

标准编号:ISO/IEC 18045:2008

中文名称:信息技术 安全技术 IT安全评估方法

英文名称:Information technology — Security techniques — Methodology for IT security evaluation

发布日期:2008-08

标准范围

ISO/IEC 18045:2008是ISO/IEC 15408《信息技术-安全技术-信息技术安全评估标准》的配套文件。ISO/IEC 18045:2008规定了评估员使用ISO/IEC 15408中规定的标准和评估证据进行ISO/IEC 15408评估时应采取的最低措施。ISO/IEC 18045:2008没有对某些高保证ISO/IEC 15408组件的评估人员行动进行定义,但目前还没有达成一致的指导意见。

ISO/IEC 18045:2008 is a companion document to ISO/IEC 15408, Information technology - Security techniques - Evaluation criteria for IT security. ISO/IEC 18045:2008 defines the minimum actions to be performed by an evaluator in order to conduct an ISO/IEC 15408 evaluation, using the criteria and evaluation evidence defined in ISO/IEC 15408. ISO/IEC 18045:2008 does not define evaluator actions for certain high assurance ISO/IEC 15408 components, where there is as yet no generally agreed guidance.

标准预览图


立即下载标准文件