BS ISO/IEC 15408-1-1999 信息技术.安全技术.IT安全性评价准则.介绍和一般模式

作者:标准资料网 时间:2024-05-14 03:37:32   浏览:9315   来源:标准资料网
下载地址: 点击此处下载
【英文标准名称】:Informationtechnology-Securitytechniques-EvaluationcriteriaforITsecurity-Introductionandgeneralmodel
【原文标准名称】:信息技术.安全技术.IT安全性评价准则.介绍和一般模式
【标准号】:BSISO/IEC15408-1-1999
【标准状态】:作废
【国别】:英国
【发布日期】:2000-02-15
【实施或试行日期】:2000-02-15
【发布单位】:英国标准学会(GB-BSI)
【起草单位】:BSI
【标准类型】:()
【标准水平】:()
【中文主题词】:消费者;验收(鉴定);数据存储保护;信息交流;质量保证;资产;选择;数据处理;数据安全
【英文主题词】:definitions;informationexchange;datasecurity;definition;informationtechnology;dataprotection;datatransmission;models;confidenceintervals;dataprocessing;levelofconfidence;safety;informationinterchange
【摘要】:ThismultipartstandardISO/IEC15408definescriteria,whichforhistoricalandcontinuitypurposesarereferredtohereinastheCommonCriteria(CC),tobeusedasthebasisforevaluationofsecuritypropertiesofITproductsandsystems.Byestablishingsuchacommoncriteriabase,theresultsofanITsecurityevaluationwillbemeaningfultoawideraudience.TheCCwillpermitcomparabilitybetweentheresultsofindependentsecurityevaluations.ItdoessobyprovidingacommonsetofrequirementsforthesecurityfunctionsofITproductsandsystemsandforassurancemeasuresappliedtothemduringasecurityevaluation.Theevaluationprocessestablishesalevelofconfidencethatthesecurityfunctionsofsuchproductsandsystemsandtheassurancemeasuresappliedtothemmeettheserequirements.TheevaluationresultsmayhelpconsumerstodeterminewhethertheITproductorsystemissecureenoughfortheirintendedapplicationandwhetherthesecurityrisksimplicitinitsusearetolerable.TheCCisusefulasaguideforthedevelopmentofproductsorsystemswithITsecurityfunctionsandfortheprocurementofcommercialproductsandsystemswithsuchfunctions.Duringevaluation,suchanITproductorsystemisknownasaTargetofEvaluation(TOE).SuchTOEsinclude,forexample,operatingsystems,computernetworks,distributedsystems,andapplications.TheCCaddressesprotectionofinformationfromunauthoriseddisclosure,modification,orlossofuse.Thecategoriesofprotectionrelatingtothesethreetypesoffailureofsecurityarecommonlycalledconfidentiality,integrity,andavailability,respectively.TheCCmayalsobeapplicabletoaspectsofITsecurityoutsideofthesethree.TheCCconcentratesonthreatstothatinformationarisingfromhumanactivities,whethermaliciousorotherwise,butmaybeapplicabletosomenon-humanthreatsaswell.Inaddition,theCCmaybeappliedinotherareasofIT,butmakesnoclaimofcompetenceoutsidethestrictdomainofITsecurity.TheCCisapplicabletoITsecuritymeasuresimplementedinhardware,firmwareorsoftware.Whereparticularaspectsofevaluationareintendedonlytoapplytocertainmethodsofimplementation,thiswillbeindicatedwithintherelevantcriteriastatements.Certaintopics,becausetheyinvolvespecialisedtechniquesorbecausetheyaresomewhatperipheraltoITsecurity,areconsideredtobeoutsidethescopeoftheCC.Someoftheseareidentifiedbelow.a)TheCCdoesnotcontainsecurityevaluationcriteriapertainingtoadministrativesecuritymeasuresnotrelateddirectlytotheITsecuritymeasures.However,itisrecognisedthatasignificantpartofthesecurityofaTOEcanoftenbeachievedthroughadministrativemeasuressuchasorganisational,personnel,physical,andproceduralcontrols.AdministrativesecuritymeasuresintheoperatingenvironmentoftheTOEaretreatedassecureusageassumptionswherethesehaveanimpactontheabilityoftheITsecuritymeasurestocountertheidentifiedthreats.b)TheevaluationoftechnicalphysicalaspectsofITsecuritysuchaselectromagneticemanationcontrolisnotspecificallycovered,althoughmanyoftheconceptsaddressedwillbeapplicabletothatarea.Inparticular,theCCaddressessomeaspectsofphysicalprotectionoftheTOE.c)TheCCaddressesneithertheevaluationmethodologynortheadministrativeandlegalframeworkunderwhichthecriteriamaybeappliedbyevaluationauthorities.However,itisexpectedthattheCCwillbeusedforevaluationpurposesinthecontextofsuchaframeworkandsuchamethodology.d)TheproceduresforuseofevaluationresultsinproductorsystemaccreditationareoutsidethescopeoftheCC.ProductorsystemaccreditationistheadministrativeprocesswherebyauthorityisgrantedfortheoperationofanITproductorsysteminitsfulloperationalenvironment.EvaluationfocusesontheITsecurityparts
【中国标准分类号】:L70
【国际标准分类号】:35_040
【页数】:64P.;A4
【正文语种】:英语


下载地址: 点击此处下载
【英文标准名称】:Radiofrequencyandcoaxialcableassemblies-Part1:Genericspecification;generalrequirementsandtestmethods(IEC60966-1:1999);GermanversionEN60966-1:1999
【原文标准名称】:射频与同轴电缆组件.第1部分:总规范.一般要求和试验方法.
【标准号】:DINEN60966-1-1999
【标准状态】:现行
【国别】:德国
【发布日期】:1999-11
【实施或试行日期】:1999-11-01
【发布单位】:德国标准化学会(DIN)
【起草单位】:
【标准类型】:()
【标准水平】:()
【中文主题词】:电缆敷设;电路网络;射频电缆;定义;详细规范;设计;电气工程;局域网;规范(验收);试验;试验;包装件;作标记;电缆;电缆;通信电缆;特性;规范;总论;局部地区网络;分规范;总规范;现成的;同轴;网络;环境试验;同轴电缆;状态调
【英文主题词】:
【摘要】:Thedocumentspecifiesrequirementsforradiofrequencycoaxialcableassembliesoperatinginthetranverseelectromagneticmode(TEM)andestablishesgeneralrequirementsfortestingtheelectrical,mechanicalandenvironmentalpropertiesofradiofrequencycoaxialcableassembliescomposedofcablesandconnectors.#,,#
【中国标准分类号】:K13
【国际标准分类号】:33_120_10
【页数】:33P;A4
【正文语种】:德语


【英文标准名称】:Materialsandarticlesincontactwithfoodstuffs-Plasticssubstancessubjecttolimitation-Guidetothetestmethodsforthespecificmigrationofsubstancesfromplasticsintofoodandfoodsimulantsandthedeterminationofsubstancesinplasticsa
【原文标准名称】:与食品接触的材料和制品.对塑料物质的限制.测定从塑料进入食品的特殊迁移物质和对食品诱发物质以及塑料中的物质和暴露于食品诱发物质的选择条件的测定指南
【标准号】:BSDDENV13130-1-1999
【标准状态】:作废
【国别】:英国
【发布日期】:1999-06-15
【实施或试行日期】:1999-06-15
【发布单位】:英国标准学会(BSI)
【起草单位】:BSI
【标准类型】:()
【标准水平】:()
【中文主题词】:接触食品的材料;迁移;定义;触点;含量测定;指导手册;试验条件;物品;材料规范;食品包装;极限(数学);试验;试验;食品;材料试验;塑料;定义;材料
【英文主题词】:
【摘要】:
【中国标准分类号】:X08;G31
【国际标准分类号】:67_250
【页数】:44P;A4
【正文语种】:英语