GB/T 18336.1-2024 Cybersecurity technology—Evaluation criteria for IT security—Part 1:Introduction and general model
GB/T 18336.1-2024 Cybersecurity technology—Evaluation criteria for IT security—Part 1:Introduction and general model
Basic Information
Scope
This document establishes the general concepts and principles of information technology security assessment, and specifies the general assessment model given in all parts of ISO/IEC 15408, which can be used as the basis for assessing the security attributes of IT products. This document provides an overview of ISO/IEC 15408 (all parts). It describes the content of each part of ISO/IEC 15408; defines the terms and abbreviations used in each part; establishes the core concept of the Target of Evaluation (TOE); and describes the target readers of the assessment background and assessment criteria. This document also provides the basic security concepts required for the assessment of IT products. 1) ISO/IEC 154081~ISO/IEC 154085 have been adopted as national standards in China, corresponding to GB/T 18336.1~GB/T 18335.5. This document introduces: -- Core concepts such as protection profiles (PP), PP modules, PP configurations, packages, security targets (ST), and compliance types; -- Organized descriptions of security components in the entire model; -- Defines various operations allowed when customizing the functional components and assurance components given in ISO/IEC 154082 and ISO/IEC 154083; -- General information on the assessment methods given in ISO/IEC 18045; -- ISO/IEC 154084 application guidelines for developing assessment methods (EM) and assessment activities (EA) derived from ISO/IEC 18045; -- General information on the predefined assurance levels (EAL) in ISO/IEC 154085; -- Information on the scope of the assessment system.