
【国外标准】 Information technology - Security techniques - Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045
本网站 发布时间:
2023-07-12
开通会员免费在线看70000余条国内标准,赠送文本下载次数,单本最低仅合13.3元!还可享标准出版进度查询、定制跟踪推送、标准查新等超多特权!  
查看详情>>

适用范围:
Refines the AVA_VAN assurance family activities defined in ISO/IEC 18045 and provides more specific guidance on the identification, selection and assessment of relevant potential vulnerabilities in order to conduct an ISO/IEC 15408 evaluation of a software target of evaluation. This Technical Report leverages publicly available information security resources to support the method of scoping and implementing ISO/IEC 18045 vulnerability analysis activities. The Technical Report currently uses the common weakness enumeration (CWE) and the common attack pattern enumeration and classification (CAPEC), but does not preclude the use of any other appropriate resources. Furthermore, this Technical Report is not meant to address all possible vulnerability analysis methods, including those that fall outside the scope of the activities outlined in ISO/IEC 18045. ISO/IEC TR 20004:2015 does not define evaluator actions for certain high assurance ISO/IEC 15408 components, where there is as yet no generally agreed guidance
标准号:
INCITS/ISO/IEC TR 20004:2015 (2017)
标准名称:
Information technology - Security techniques - Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045
英文名称:
Information technology - Security techniques - Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045标准状态:
现行-
发布日期:
-
实施日期:
出版语种:
- 其它标准
- 上一篇: INCITS/ISO/IEC TR 20000-5:2013 (2018) Information technology -- Service management -- Part 5: Exemplar implementation plan for ISO/IEC 20000-1
- 下一篇: INCITS/ISO/IEC TR 20004:2015 (R2022) Information technology - Security techniques - Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045, a Technical Report prepared by INCITS and registered with ANSI
- 推荐标准
- AS 2337.3-2006 (R2017)/Amdt 1-2007 Gas cylinder test stations Transportable gas cylinders - Periodic inspection and testing of composite gas cylinders (ISO 11623:2002, MOD)
- AS 2503.6-2007 (R2017)/Amdt 1-2011 Refractories and refractory material - Chemical analysis Refractories, refractory mortars and silicate materials - Determination of major and minor elements - Wavelength dispersive X-ray fluorescence spectrometry using lithium borate fusion
- AS 4032.2-2005 (R2015)/Amdt 1-2006 Water supply - Valves for the control of hot water supply temperatures Tempering valves and end-of-line temperature-actuated devices
- AS 4046.5-2002 (R2015)/Amdt 1-2006 Methods of testing roof tiles Determination of permeability
- AS 4046.7-2002 (R2015)/Amdt 1-2006 Methods of testing roof tiles Determination of resistance to salt attack
- AS 4123.7-2006 (R2017)/Amdt 1-2008 Mobile waste containers Colours, markings, and designation requirements
- AS IEC 60300.3.11-2011 Dependability management Application guide - Reliability centred maintenance
- AS IEC 60300.3.12-2011 Dependability management Application guide - Integrated logistic support
- AS IEC 60300.3.15-2011 Dependability management Application guide - Engineering of system dependability
- AS IEC 60812-2008 Analysis techniques for system reliability - Procedure for failure mode and effects analysis (FMEA)
- AS IEC 60942-2004 Electroacoustics - Sound calibrators
- AS IEC 61131.3-2004 Programmable controllers Programming languages
- AS IEC 61672.1-2004 Electroacoustics - Sound level meters Specifications
- AS IEC 62628:2014 Guidance on software aspects of dependability
- AS ISO 10006-2003 Quality management systems - Guidelines for quality management in projects