热门站点| 世界资料网 | 专利资料网 | 世界资料网论坛
收藏本站| 设为首页| 首页

BS ISO/IEC 15408-1-1999 信息技术.安全技术.IT安全性评价准则.介绍和一般模式

作者:标准资料网 时间:2024-05-09 14:05:17  浏览:8551   来源:标准资料网
下载地址: 点击此处下载
【英文标准名称】:Informationtechnology-Securitytechniques-EvaluationcriteriaforITsecurity-Introductionandgeneralmodel
【原文标准名称】:信息技术.安全技术.IT安全性评价准则.介绍和一般模式
【标准号】:BSISO/IEC15408-1-1999
【标准状态】:作废
【国别】:英国
【发布日期】:2000-02-15
【实施或试行日期】:2000-02-15
【发布单位】:英国标准学会(GB-BSI)
【起草单位】:BSI
【标准类型】:()
【标准水平】:()
【中文主题词】:消费者;验收(鉴定);数据存储保护;信息交流;质量保证;资产;选择;数据处理;数据安全
【英文主题词】:definitions;informationexchange;datasecurity;definition;informationtechnology;dataprotection;datatransmission;models;confidenceintervals;dataprocessing;levelofconfidence;safety;informationinterchange
【摘要】:ThismultipartstandardISO/IEC15408definescriteria,whichforhistoricalandcontinuitypurposesarereferredtohereinastheCommonCriteria(CC),tobeusedasthebasisforevaluationofsecuritypropertiesofITproductsandsystems.Byestablishingsuchacommoncriteriabase,theresultsofanITsecurityevaluationwillbemeaningfultoawideraudience.TheCCwillpermitcomparabilitybetweentheresultsofindependentsecurityevaluations.ItdoessobyprovidingacommonsetofrequirementsforthesecurityfunctionsofITproductsandsystemsandforassurancemeasuresappliedtothemduringasecurityevaluation.Theevaluationprocessestablishesalevelofconfidencethatthesecurityfunctionsofsuchproductsandsystemsandtheassurancemeasuresappliedtothemmeettheserequirements.TheevaluationresultsmayhelpconsumerstodeterminewhethertheITproductorsystemissecureenoughfortheirintendedapplicationandwhetherthesecurityrisksimplicitinitsusearetolerable.TheCCisusefulasaguideforthedevelopmentofproductsorsystemswithITsecurityfunctionsandfortheprocurementofcommercialproductsandsystemswithsuchfunctions.Duringevaluation,suchanITproductorsystemisknownasaTargetofEvaluation(TOE).SuchTOEsinclude,forexample,operatingsystems,computernetworks,distributedsystems,andapplications.TheCCaddressesprotectionofinformationfromunauthoriseddisclosure,modification,orlossofuse.Thecategoriesofprotectionrelatingtothesethreetypesoffailureofsecurityarecommonlycalledconfidentiality,integrity,andavailability,respectively.TheCCmayalsobeapplicabletoaspectsofITsecurityoutsideofthesethree.TheCCconcentratesonthreatstothatinformationarisingfromhumanactivities,whethermaliciousorotherwise,butmaybeapplicabletosomenon-humanthreatsaswell.Inaddition,theCCmaybeappliedinotherareasofIT,butmakesnoclaimofcompetenceoutsidethestrictdomainofITsecurity.TheCCisapplicabletoITsecuritymeasuresimplementedinhardware,firmwareorsoftware.Whereparticularaspectsofevaluationareintendedonlytoapplytocertainmethodsofimplementation,thiswillbeindicatedwithintherelevantcriteriastatements.Certaintopics,becausetheyinvolvespecialisedtechniquesorbecausetheyaresomewhatperipheraltoITsecurity,areconsideredtobeoutsidethescopeoftheCC.Someoftheseareidentifiedbelow.a)TheCCdoesnotcontainsecurityevaluationcriteriapertainingtoadministrativesecuritymeasuresnotrelateddirectlytotheITsecuritymeasures.However,itisrecognisedthatasignificantpartofthesecurityofaTOEcanoftenbeachievedthroughadministrativemeasuressuchasorganisational,personnel,physical,andproceduralcontrols.AdministrativesecuritymeasuresintheoperatingenvironmentoftheTOEaretreatedassecureusageassumptionswherethesehaveanimpactontheabilityoftheITsecuritymeasurestocountertheidentifiedthreats.b)TheevaluationoftechnicalphysicalaspectsofITsecuritysuchaselectromagneticemanationcontrolisnotspecificallycovered,althoughmanyoftheconceptsaddressedwillbeapplicabletothatarea.Inparticular,theCCaddressessomeaspectsofphysicalprotectionoftheTOE.c)TheCCaddressesneithertheevaluationmethodologynortheadministrativeandlegalframeworkunderwhichthecriteriamaybeappliedbyevaluationauthorities.However,itisexpectedthattheCCwillbeusedforevaluationpurposesinthecontextofsuchaframeworkandsuchamethodology.d)TheproceduresforuseofevaluationresultsinproductorsystemaccreditationareoutsidethescopeoftheCC.ProductorsystemaccreditationistheadministrativeprocesswherebyauthorityisgrantedfortheoperationofanITproductorsysteminitsfulloperationalenvironment.EvaluationfocusesontheITsecurityparts
【中国标准分类号】:L70
【国际标准分类号】:35_040
【页数】:64P.;A4
【正文语种】:英语


下载地址: 点击此处下载
【英文标准名称】:Safetyofhouseholdandsimilarelectricalappliances-Part2-3:Particularrequirementsforelectricirons;Amendment2
【原文标准名称】:家用和类似电器的安全.第2-3部分:电熨斗的特殊要求.修改件2
【标准号】:IEC60335-2-3AMD2-1999
【标准状态】:作废
【国别】:国际
【发布日期】:1999-09
【实施或试行日期】:
【发布单位】:国际电工委员会(IEC)
【起草单位】:IEC/TC61
【标准类型】:()
【标准水平】:()
【中文主题词】:电气器具;家用电器;家用设备;安全要求;电气工程;熨斗
【英文主题词】:electricappliances;safetyrequirements;householdequipment;irons;electricalhouseholdappliances;electricalengineering
【摘要】:
【中国标准分类号】:Y63
【国际标准分类号】:97_060
【页数】:2P;A4
【正文语种】:英语


【英文标准名称】:StandardPracticeforCalculatingViscosityIndexFromKinematicViscosityat40and100°C
【原文标准名称】:在40℃和100℃时从运动粘度计算粘度指数的标准实施规程
【标准号】:ASTMD2270-2004
【标准状态】:现行
【国别】:美国
【发布日期】:2004
【实施或试行日期】:
【发布单位】:美国材料与试验协会(ASTM)
【起草单位】:ASTM
【标准类型】:()
【标准水平】:()
【中文主题词】:石油产品;质量;数量估计;工艺;运动粘度;粘度;润滑剂;检验
【英文主题词】:Inspection;Kinematicviscosity;Lubricants;Petroleumproducts;Processes;Quality;Quantitysurveying;Viscosity
【摘要】:
【中国标准分类号】:A42
【国际标准分类号】:17_060
【页数】:6P;A4
【正文语种】:英语



版权声明:所有资料均为作者提供或网友推荐收集整理而来,仅供爱好者学习和研究使用,版权归原作者所有。
如本站内容有侵犯您的合法权益,请和我们取得联系,我们将立即改正或删除。
京ICP备14017250号-1