Information technology. Security techniques. Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045
Information technology. Security techniques. Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045
  • Load image into Gallery viewer, Information technology. Security techniques. Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045
  • Load image into Gallery viewer, Information technology. Security techniques. Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045

Information technology. Security techniques. Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045

Regular price
£232.00
Sale price
£232.00
Regular price
£116.00
Sold out
Unit price
per 

What is ISO/IEC TR 20004- Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045 about?  

ISO/IEC TR 20004 is a technical report that refines the AVA_VAN assurance family activities defined in ISO/IEC 18045 and provides more specific guidance on the identification, selection and assessment of relevant potential vulnerabilities in order to conduct an ISO/IEC 15408 evaluation of a software target of evaluation.  

ISO/IEC TR 20004 leverages publicly available information security resources to support the method of scoping and implementing ISO/IEC 18045 vulnerability analysis activities. ISO/IEC TR 20004 currently uses the common weakness enumeration (CWE) and the common attack pattern enumeration and classification (CAPEC), but does not preclude the use of any other appropriate resources.  

Note 1: Furthermore, ISO/IEC TR 20004 is not meant to address all possible vulnerability analysis methods, including those that fall outside the scope of the activities outlined in ISO/IEC 18045. 

Note 2: ISO/IEC TR 20004 does not define evaluator actions for certain high assurance ISO/IEC 15408 components, where there is as yet no generally agreed guidance. 

Who is ISO/IEC TR 20004 - Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045 for? 

ISO/IEC TR 20004 on refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045 is useful for: 

  • Evaluators applying ISO/IEC 15408  
  • Certifiers confirming evaluator actions  
  • Technical committees  
  • Other parties interested in IT security  
  • Information technology indudtry 

Why should you use ISO/IEC TR 20004 - Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045? 

ISO/IEC TR 20004 is intended to provide added refinement, detail and guidance to the vulnerability analysis activities outlined in ISO/IEC 18045:2008 for the software elements of a TOE. Specifically, it is intended to add refinement and clarification of the “Potential vulnerability identification from public sources” (AVA_VAN.1.2E/2.2E/3.2E/4.2E) and “Penetration testing” (AVA_VAN.1.3E/2.4E/3.4E/4.4E) evaluator actions, which are currently imprecise in regards to searching for, identifying and testing relevant potential vulnerabilities.  

ISO/IEC TR 20004 provides guidance on an approach which enables you to objectively search for, identify, filter and test potential vulnerabilities utilizing international ad hoc standard resources for software weaknesses and attack patterns. The set of relevant software weaknesses and attack patterns identified through this ISO/IEC TR 20004 guidance represent a minimal set for analysis under the AVA_VAN assurance family in an ISO/IEC 15408 evaluation.  

Additional weaknesses and attack patterns may be determined relevant by specific national schemes, technical communities, associated protection profiles or other sources. In utilizing these standard structured resources, the approach defined in ISO/IEC TR 20004 provides the added benefit of being equally applicable to the TOE development process as it does to the TOE security evaluation process. This means that relevant weaknesses and attack patterns identified and tested for during development, whether defined ad hoc or as part of a structured assurance case, can provide a head start template for a TOE-specific set of relevant weaknesses and attack patterns for use in the security evaluation.  

ISO/IEC TR 20004 is intended to be used in conjunction with and, as an addendum to, ISO/IEC 18045. 

Note: ISO/IEC TR 20004 does not address all possible vulnerability analysis methods, in particular those that fall outside the scope of the activities outlined in ISO/IEC 18045