BS-ISO-IEC-15292-2001.pdf

上传人:韩长文 文档编号:3747514 上传时间:2019-09-22 格式:PDF 页数:22 大小:969.15KB
返回 下载 相关 举报
BS-ISO-IEC-15292-2001.pdf_第1页
第1页 / 共22页
BS-ISO-IEC-15292-2001.pdf_第2页
第2页 / 共22页
BS-ISO-IEC-15292-2001.pdf_第3页
第3页 / 共22页
BS-ISO-IEC-15292-2001.pdf_第4页
第4页 / 共22页
BS-ISO-IEC-15292-2001.pdf_第5页
第5页 / 共22页
亲,该文档总共22页,到这儿已超出免费预览范围,如果喜欢就下载吧!
资源描述

《BS-ISO-IEC-15292-2001.pdf》由会员分享,可在线阅读,更多相关《BS-ISO-IEC-15292-2001.pdf(22页珍藏版)》请在三一文库上搜索。

1、BRITISH STANDARD BS ISO/IEC 15292:2001 Information technology Security techniques Protection Profile registration procedures ICS 35.040 NO COPYING WITHOUT BSI PERMISSION EXCEPT AS PERMITTED BY COPYRIGHT LAW Licensed Copy: sheffieldun sheffieldun, na, Thu Nov 23 04:00:05 GMT+00:00 2006, Uncontrolled

2、Copy, (c) BSI BS ISO/IEC 15292:2001 This British Standard, having been prepared under the direction of the DISC Board, was published under the authority of the Standards Policy and Strategy Committee on 23 January 2002 BSI 23 January 2002 ISBN 0 580 38894 8 National foreword This British Standard re

3、produces verbatim ISO/IEC 15292:2001 and implements it as the UK national standard. The UK participation in its preparation was entrusted to Technical Committee IST/33, IT Security Techniques, which has the responsibility to: A list of organizations represented on this committee can be obtained on r

4、equest to its secretary. Cross-references The British Standards which implement international or European publications referred to in this document may be found in the BSI Standards Catalogue under the section entitled “International Standards Correspondence Index”, or by using the “Find” facility o

5、f the BSI Standards Electronic Catalogue. A British Standard does not purport to include all the necessary provisions of a contract. Users of British Standards are responsible for their correct application. Compliance with a British Standard does not of itself confer immunity from legal obligations.

6、 aid enquirers to understand the text; present to the responsible international/European committee any enquiries on the interpretation, or proposals for change, and keep the UK interests informed; monitor related international and European developments and promulgate them in the UK. Summary of pages

7、 This document comprises a front cover, an inside front cover, the ISO/IEC title page, pages ii to iv, pages 1 to 14, an inside back cover and a back cover. The BSI copyright date displayed in this document indicates when the document was last issued. Amendments issued since publication Amd. No. Dat

8、eComments Licensed Copy: sheffieldun sheffieldun, na, Thu Nov 23 04:00:05 GMT+00:00 2006, Uncontrolled Copy, (c) BSI Reference number ISO/IEC 15292:2001(E) INTERNATIONAL STANDARD ISO/IEC 15292 First edition 2001-12-15 Information technology Security techniques Protection Profile registration procedu

9、res Technologies de linformation Techniques de scurit Procdures denregistrement du profil de protection Licensed Copy: sheffieldun sheffieldun, na, Thu Nov 23 04:00:05 GMT+00:00 2006, Uncontrolled Copy, (c) BSI ISO/IEC 15292:2001(E) lcsid FDParemi ihTs PDF file mac ytnoaie nmt deddebyfepca.se In cca

10、ocnadrw eith Aebods licsneilop gnic,y this file mairp eb yntiv ro deewb detu shlal ton ide ebtlnu desse tt ehyfepacse whice era hml era deddebicsnede to i dnanstlaled t noeh comtupfrep reomrign tide ehti.gn In wodnlidaogn this file, trapies ccatpe tiereht nsnopser ehibility fo ton infriignA gnebods

11、licnesilop gnic.y I ehTStneC Oarl Secrteiraat cacepts l oniibality in this .aera Ai ebods a tredamafo kr Aebod SystemI sncotaropr.de teDails fo ts ehoftwaorp ercudts ust deo crtaet ehis PDF file ceb na fi dnuon tlareneG eh Info leratit evo tf ehile; tP ehD-Fcrtaeiarap nomtesre were tpoimizf deoirp r

12、nti.gn Evyre casah er t neebakt neo snet eruhat tf ehile is suitlbaf eosu rI yb eSO memidob rebse. In the lnuikletneve y ttah alborp emler ati gnto it is fnuo,dlp saee inform ttneC ehlar Secrteiraat at tsserdda ehig leb nevwo. ii Licensed Copy: sheffieldun sheffieldun, na, Thu Nov 23 04:00:05 GMT+00

13、:00 2006, Uncontrolled Copy, (c) BSI ISO/IEC 15292:2001(E) iii Contents 1Scope1 2Normative references .1 3Terms and definitions.1 4Abbreviations 3 5Technical Specifications3 5.1Entry label 3 5.2Technical definition (within a register entry)3 6The JTC 1 Registration Authority for PPs and packages .4

14、6.1Appointment.4 6.2Qualifications.4 6.3Contract4 6.4Duties4 7Criteria for eligibility of applicants for registration.5 8Information to be included within an application for registration .5 9Steps involved in review and response to an application7 9.1Initial processing.7 9.2Validation7 10Criteria fo

15、r rejection of applications for registration 8 11Operation of the register8 11.1Notification of obsolescent entries .8 11.2Update of draft technical specifications.8 11.3Routine review of entries8 11.4Defect notification .9 11.5Other requests for update of entries.9 11.6Deletion of register entries.

16、10 12Maintenance of the register .10 13Confidentiality of information held within the register .10 14Publication of the register10 15Appeals procedure12 Annex A (informative) Benefits of registration.13 Annex B (informative) Lifecycle of a register entry14 Licensed Copy: sheffieldun sheffieldun, na,

17、 Thu Nov 23 04:00:05 GMT+00:00 2006, Uncontrolled Copy, (c) BSI Foreword ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC particip

18、ate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental a

19、nd non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 3. The

20、 main task of the joint technical committee is to prepare International Standards. Draft International Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as an International Standard requires approval by at least 75 % of the national bodies c

21、asting a vote. Attention is drawn to the possibility that some of the elements of this International Standard may be the subject of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights. ISO/IEC 15292 was prepared by Joint Technical Committee ISO/IEC

22、JTC 1, Information technology, Subcommittee SC 27, Security techniques. Annexes A and B of this International Standard are for information only. ISO/IEC 15292:2001(E) iv Licensed Copy: sheffieldun sheffieldun, na, Thu Nov 23 04:00:05 GMT+00:00 2006, Uncontrolled Copy, (c) BSI INTERNATIONAL STANDARD

23、ISO/IEC 15292:2001(E) Information technology Security techniques Protection Profile registration procedures 1 Scope This International Standard defines the procedures to be applied by the JTC 1 Registration Authority appointed by the ISO and IEC councils to maintain a register of Protection Profiles

24、 and packages for the purposes of IT security evaluation. These Protection Profiles and packages are specified in accordance with criteria given in ISO/IEC 15408. 2 Normative references The following normative documents contain provisions which, through reference in this text, constitute provisions

25、of this International Standard. For dated references, subsequent amendments to, or revisions of, any of these publications do not apply. However, parties to agreements based on this International Standard are encouraged to investigate the possibility of applying the most recent editions of the norma

26、tive documents indicated below. For undated references, the latest edition of the normative document referred to applies. Members of ISO and IEC maintain registers of currently valid International Standards. ISO 15408-1, Information technology Security techniques Evaluation criteria for IT security

27、Part 1: Introduction and general model ISO 15408-2, Information technology Security techniques Evaluation criteria for IT security Part 2: Security functionality requirements ISO 15408-3, Information technology Security techniques Evaluation criteria for IT security Part 2: Security assurance requir

28、ements Procedures for the technical work of ISO/IEC JTC 1 ISO/IEC/ITU ITSIG Guide for the use of IT in the development and delivery of standards 3 Terms and definitions For the purposes of this International Standard, the following terms and definitions apply. 3.1 applicant an entity (organisation,

29、individual etc.) which requests the assignment of a register entry and entry label 1 Licensed Copy: sheffieldun sheffieldun, na, Thu Nov 23 04:00:05 GMT+00:00 2006, Uncontrolled Copy, (c) BSI 2 3.2 certificate a declaration by an independent authority operating in accordance with ISO Guide 58, Calib

30、ration and testing laboratory accreditation systems - General requirements for operation and recognition, confirming that an evaluation pass statement is valid 3.3 entry label the naming information that identifies a registered PP or package uniquely 3.4 evaluation pass statement a statement issued

31、by an organisation that performs evaluations against ISO/IEC 15408 confirming that a PP has successfully passed assessment against the evaluation criteria given in clause 4 of Part 3 of that International Standard 3.5 JTC 1 Registration Authority an organisation appointed by the ISO and IEC councils

32、 to register objects in accordance with a JTC 1 procedural Standard 3.6 package a reusable set of either functional or assurance components combined together to satisfy a set of identified security objectives (from ISO/IEC 15408-1) 3.7 Protection Profile an implementation-independent set of security

33、 requirements for a category of IT products or systems that meet specific consumer needs (adapted from ISO/IEC 15408-1) 3.8 register a set of files (electronic, or a combination of electronic and paper) containing entry labels and their associated definitions and related information 3.9 register ent

34、ry the information within a register relating to a specific PP or package 3.10 registration the process of assigning a register entry 3.11 Security Target a set of security requirements and specifications to be used as the basis for evaluation of an identified IT product or system (adapted from ISO/

35、IEC 15408-1) 3.12 sponsor an entity (organisation, individual etc.) responsible for the content of a register entry ISO/IEC 15292:2001(E) Licensed Copy: sheffieldun sheffieldun, na, Thu Nov 23 04:00:05 GMT+00:00 2006, Uncontrolled Copy, (c) BSI 3 4Abbreviations ITTFInformation Technology Task Force

36、(of ISO/IEC) PPProtection Profile RARegistration Authority SCJTC 1 Subcommittee STSecurity Target 5Technical Specifications 5.1Entry label Every PP or package registered in accordance with this International Standard shall have an entry label assigned by the JTC 1 RA that uniquely identifies that PP

37、 or package within the register. The entry label shall be made up of the following elements, separated by dashes: -Entry Type -Registration Year -Registration Number. The Entry Type shall be PP for a protection profile, AP for an assurance package or FP for a functional package. The Registration Yea

38、r shall be the four digit representation of the year when the entry was registered. The Registration Number shall be a four digit sequentially assigned identification number, starting each year from 0001. EXAMPLEPP-2001-0001. 5.2Technical definition (within a register entry) 5.2.1PPs Every applicati

39、on for registration of a PP submitted for registration in accordance with this International Standard shall include a technical definition of the PP in question. This technical definition shall conform to the content requirements for PPs contained within Annex B to ISO/IEC 15408-1 and shall conform

40、to the structural outline portrayed in Figure B.1 of ISO/IEC 15408-1. 5.2.2Packages Every application for registration of a functional or assurance package submitted for registration in accordance with this International Standard shall include a technical definition of the package. This definition s

41、hall contain: - a package overview that summarises the package in narrative form - a specification of a set of either functional or assurance components. The package overview should be sufficiently detailed for a potential user of the package to determine whether the package is of interest. It shoul

42、d be understandable without reference to the component specifications. ISO/IEC 15292:2001(E) Licensed Copy: sheffieldun sheffieldun, na, Thu Nov 23 04:00:05 GMT+00:00 2006, Uncontrolled Copy, (c) BSI 4 Components for functional packages shall be selected from ISO/IEC 15408-2 or shall be constructed

43、and specified in accordance with the specification requirements for functional components given within clause 2 of ISO/IEC 15408-2. Components for assurance packages shall be selected from ISO/IEC 15408-3 or shall be constructed and specified in accordance with the specification requirements for ass

44、urance components given within subclause 2.1 of ISO/IEC 15408-3. The technical definition of a package may contain other descriptive information that might be relevant to the author of a PP or ST wishing to use or reference the package. This information shall be presented in the form of one or more

45、named PP or ST sections as defined within Annexes B and C of ISO/IEC 15408-1. The information should be suitable for direct incorporation within PPs or STs that make use of the package. 6The JTC 1 Registration Authority for PPs and packages 6.1Appointment The JTC 1 RA for PPs and packages shall be a

46、ppointed by the ISO and IEC councils in accordance with the procedure for the appointment of JTC 1 Registration Authorities defined in the JTC 1 Directives. 6.2Qualifications Any organisation seeking appointment as the JTC 1 RA for PPs and packages shall demonstrate that it meets the qualifications

47、required of JTC 1 RAs as defined in the JTC 1 Directives, with the following amendments: -it shall confirm its agreement to function as an RA for a minimum of 5 years; -it shall confirm that it has sufficient equipment resources and communication facilities to operate an Internet web site in support

48、 of this International Standard; -it shall confirm that on termination of its appointment, it will transfer its register and all supporting documentation at no cost to another organisation designated by the ISO and IEC councils. 6.3Contract The JTC 1 RA for PPs and packages shall operate under contr

49、act with the ITTF. Upon twelve-months notice, either the RA or the ITTF may terminate the contract. NOTE The contract has no fixed time limit. Although the organisation appointed as the JTC1 RA will have committed to function as the RA for a minimum of 5 years from the date of first appointment, circumstances can change. This subclause permits the RA to resign from its duties at any time, including before the 5 years is comple

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 其他


经营许可证编号:宁ICP备18001539号-1