GB/T 18336.1-2008 Information technology—Security techniques—Evaluation criteria for IT security—Part 1:Introduction and general model
GB/T 18336.1-2008 Information technology—Security techniques—Evaluation criteria for IT security—Part 1:Introduction and general model
Basic Information
Scope
GB/T 18336 is intended to serve as a basic guideline for evaluating the security characteristics of information technology products and systems. By establishing such a common guideline library, the results of information technology security assessments can be better understood by more people. This standard defines two structures for expressing IT security functions and assurance requirements. Among them, the Protection Profile (PP) allows the creation of universally reusable sets of security requirements. PP can be used by target customers to standardize and identify products that meet their needs and their IT security features. Security Target (ST) is used to elaborate security requirements and describe in detail the security functions of the products or systems being evaluated, which are often referred to as Evaluation Objects (TOE). ST is used by evaluators as the basis for conducting evaluation activities under the guidance of GB/T 18336.