Shopping Cart

No products in the cart.

BS ISO/IEC 18045:2022

$215.11

Information security, cybersecurity and privacy protection. Evaluation criteria for IT security. Methodology for IT security evaluation

Published By Publication Date Number of Pages
BSI 2022 440
Guaranteed Safe Checkout
Category:

If you have any questions, feel free to reach out to our online customer service team by clicking on the bottom right corner. We’re here to assist you 24/7.
Email:[email protected]

PDF Catalog

PDF Pages PDF Title
2 undefined
11 List of figures
12 List of tables
13 Foreword
14 Legal notice
15 Introduction
17 1 Scope
2 Normative references
3 Terms and definitions
20 4 Abbreviated terms
5 Terminology
6 Verb usage
21 7 General evaluation guidance
8 Relationship between the ISO/IEC 15408 series and ISO/IEC 18045 structures
Figure 1 — Mapping of the ISO/IEC 15408 series and ISO/IEC 18045 structures
9 Evaluation process and related tasks
9.1 General
22 9.2 Evaluation process overview
9.2.1 Objectives
9.2.2 Responsibilities of the roles
9.2.3 Relationship of roles
23 9.2.4 General evaluation model
Figure 2 — Generic evaluation model
9.2.5 Evaluator verdicts
24 Figure 3 — Example of the verdict assignment rule
25 9.3 Evaluation input task
9.3.1 Objectives
9.3.2 Application notes
26 9.3.3 Management of evaluation evidence sub-task
9.3.3.1 Configuration control
9.3.3.2 Disposal
9.3.3.3 Confidentiality
9.4 Evaluation sub-activities
9.5 Evaluation output task
9.5.1 Objectives
27 9.5.2 Management of evaluation outputs
9.5.3 Application notes
9.5.4 Write OR sub-task
9.5.5 Write ETR sub-task
9.5.5.1 Objectives
28 9.5.5.2 ETR for a PP Evaluation
9.5.5.2.1 General
Figure 4 — ETR information content for a PP evaluation
9.5.5.2.2 General
29 9.5.5.2.3 Evaluation
9.5.5.2.4 Results of the evaluation
9.5.5.2.5 Conclusions and recommendations
9.5.5.2.6 List of evaluation evidence
30 9.5.5.2.7 List of acronyms/Glossary of terms
9.5.5.2.8 Observation reports
9.5.5.3 ETR for a PP-Configuration Evaluation
9.5.5.3.1 General
Figure 5 — ETR information content for a PP-Configuration evaluation
31 9.5.5.3.2 General
9.5.5.3.3 PP-Configuration overview
9.5.5.3.4 Evaluation
32 9.5.5.3.5 Results of the evaluation
9.5.5.3.6 Conclusions and recommendations
9.5.5.3.7 List of evaluation evidence
9.5.5.3.8 List of acronyms/Glossary of terms
9.5.5.3.9 Observation reports
9.5.5.4 ETR for a TOE Evaluation
9.5.5.4.1 General
33 Figure 6 — ETR information content for a TOE evaluation
9.5.5.4.2 General
34 9.5.5.4.3 Architectural description of the TOE
9.5.5.4.4 Evaluation
9.5.5.4.5 Results of the evaluation
9.5.5.4.6 Conclusions and recommendations
35 9.5.5.4.7 List of evaluation evidence
9.5.5.4.8 List of acronyms/Glossary of terms
9.5.5.4.9 Observation reports
10 Class APE: Protection Profile evaluation
10.1 General
10.2 Re-using the evaluation results of certified PPs
36 10.3 PP introduction (APE_INT)
10.3.1 Evaluation of sub-activity (APE_INT.1)
10.3.1.1 Objectives
10.3.1.2 Input
10.3.1.3 Action APE_INT.1.1E
10.3.1.3.1 General
10.3.1.3.2 Work unit APE_INT.1-1
10.3.1.3.3 Work unit APE_INT.1-2
10.3.1.3.4 Work unit APE_INT.1-3
10.3.1.3.5 Work unit APE_INT.1-4
37 10.3.1.3.6 Work unit APE_INT.1-5
10.4 Conformance claims (APE_CCL)
10.4.1 Evaluation of sub-activity (APE_CCL.1)
10.4.1.1 Objectives
10.4.1.2 Input
10.4.1.3 Action APE_CCL.1.1E
10.4.1.3.1 General
10.4.1.3.2 Work unit APE_CCL.1-1
10.4.1.3.3 Work unit APE_CCL.1-2
38 10.4.1.3.4 Work unit APE_CCL.1-3
10.4.1.3.5 Work unit APE_CCL.1-4
10.4.1.3.6 Work unit APE_CCL.1-5
10.4.1.3.7 Work unit APE_CCL.1-6
10.4.1.3.8 Work unit APE_CCL.1-7
39 10.4.1.3.9 Work unit APE_CCL.1-8
40 10.4.1.3.10 Work unit APE_CCL.1-9
10.4.1.3.11 Work unit APE_CCL.1-10
10.4.1.3.12 Work unit APE_CCL.1-11
10.4.1.3.13 Work unit APE_CCL.1-12
41 10.4.1.3.14 Work unit APE_CCL.1-13
43 10.4.1.3.15 Work unit APE_CCL.1-14
44 10.4.1.3.16 Work unit APE_CCL.1-15
45 10.4.1.3.17 Work unit APE_CCL.1-16
10.4.1.3.18 Work unit APE_CCL.1-17
46 10.4.1.3.19 Work unit APE_CCL.1-18
10.4.1.3.20 Work unit APE_CCL.1-19
47 10.5 Security problem definition (APE_SPD)
10.5.1 Evaluation of sub-activity (APE_SPD.1)
10.5.1.1 Objectives
10.5.1.2 Input
10.5.1.3 Action APE_SPD.1.1E
10.5.1.3.1 General
10.5.1.3.2 Work unit APE_SPD.1-1
10.5.1.3.3 Work unit APE_SPD.1-2
10.5.1.3.4 Work unit APE_SPD.1-3
48 10.5.1.3.5 Work unit APE_SPD.1-4
10.6 Security objectives (APE_OBJ)
10.6.1 Evaluation of sub-activity (APE_OBJ.1)
10.6.1.1 Objectives
10.6.1.2 Input
10.6.1.3 Action APE_OBJ.1.1E
10.6.1.3.1 General
10.6.1.3.2 Work unit APE_OBJ.1-1
49 10.6.1.3.3 Work unit APE_OBJ.1-2
10.6.1.3.4 Work unit APE_OBJ.1-3
10.6.2 Evaluation of sub-activity (APE_OBJ.2)
10.6.2.1 Objectives
10.6.2.2 Input
50 10.6.2.3 Action APE_OBJ.2.1E
10.6.2.3.1 General
10.6.2.3.2 Work unit APE_OBJ.2-1
10.6.2.3.3 Work unit APE_OBJ.2-2
10.6.2.3.4 Work unit APE_OBJ.2-3
10.6.2.3.5 Work unit APE_OBJ.2-4
51 10.6.2.3.6 Work unit APE_OBJ.2-5
10.6.2.3.7 Work unit APE_OBJ.2-6
52 10.7 Extended components definition (APE_ECD)
10.7.1 Evaluation of sub-activity (APE_ECD.1)
10.7.1.1 Objectives
10.7.1.2 Input
10.7.1.3 Action APE_ECD.1.1E
10.7.1.3.1 General
10.7.1.3.2 Work unit APE_ECD.1-1
10.7.1.3.3 Work unit APE_ECD.1-2
10.7.1.3.4 Work unit APE_ECD.1-3
53 10.7.1.3.5 Work unit APE_ECD.1-4
10.7.1.3.6 Work unit APE_ECD.1-5
10.7.1.3.7 Work unit APE_ECD.1-6
54 10.7.1.3.8 Work unit APE_ECD.1-7
10.7.1.3.9 Work unit APE_ECD.1-8
10.7.1.3.10 Work unit APE_ECD.1-9
10.7.1.3.11 Work unit APE_ECD.1-10
55 10.7.1.3.12 Work unit APE_ECD.1-11
10.7.1.3.13 Work unit APE_ECD.1-12
10.7.1.4 Action APE_ECD.1.2E
10.7.1.4.1 Work unit APE_ECD.1-13
56 10.8 Security requirements (APE_REQ)
10.8.1 Evaluation of sub-activity (APE_REQ.1)
10.8.1.1 Objectives
10.8.1.2 Input
10.8.1.3 Action APE_REQ.1.1E
10.8.1.3.1 General
10.8.1.3.2 Work unit APE_REQ.1-1
10.8.1.3.3 Work unit APE_REQ.1-2
57 10.8.1.3.4 Work unit APE_REQ.1-3
10.8.1.3.5 Work unit APE_REQ.1-4
10.8.1.3.6 Work unit APE_REQ.1-5
58 10.8.1.3.7 Work unit APE_REQ.1-6
10.8.1.3.8 Work unit APE_REQ.1-7
10.8.1.3.9 Work unit APE_REQ.1-8
10.8.1.3.10 Work unit APE_REQ.1-9
10.8.1.3.11 Work unit APE_REQ.1-10
59 10.8.1.3.12 Work unit APE_REQ.1-11
10.8.1.3.13 Work unit APE_REQ.1-12
10.8.1.3.14 Work unit APE_REQ.1-13
60 10.8.1.3.15 Work unit APE_REQ.1-14
61 10.8.2 Evaluation of sub-activity (APE_REQ.2)
10.8.2.1 Objectives
10.8.2.2 Input
10.8.2.3 Action APE_REQ.2.1E
10.8.2.3.1 General
10.8.2.3.2 Work unit APE_REQ.2-1
10.8.2.3.3 Work unit APE_REQ.2-2
62 10.8.2.3.4 Work unit APE_REQ.2-3
10.8.2.3.5 Work unit APE_REQ.2-4
63 10.8.2.3.6 Work unit APE_REQ.2-5
10.8.2.3.7 Work unit APE_REQ.2-6
10.8.2.3.8 Work unit APE_REQ.2-7
10.8.2.3.9 Work unit APE_REQ.2-8
10.8.2.3.10 Work unit APE_REQ.2-9
64 10.8.2.3.11 Work unit APE_REQ.2-10
10.8.2.3.12 Work unit APE_REQ.2-11
10.8.2.3.13 Work unit APE_REQ.2-13
10.8.2.3.14 Work unit APE_REQ.2-14
65 11 Class ACE: Protection Profile Configuration evaluation
11.1 General
66 Figure 7 — Relationship between PPs and PP-Modules in a PP-Configuration
67 11.2 PP-Module introduction (ACE_INT)
11.2.1 Evaluation of sub-activity (ACE_INT.1)
11.2.1.1 Objectives
11.2.1.2 Input
11.2.1.3 Application notes
11.2.1.4 Action ACE_INT.1.1E
11.2.1.4.1 General
11.2.1.4.2 Work unit ACE_INT.1-1
11.2.1.4.3 Work unit ACE_INT.1-2
11.2.1.4.4 Work unit ACE_INT.1-3
68 11.2.1.4.5 Work unit ACE_INT.1-4
11.2.1.4.6 Work unit ACE_INT.1-5
11.2.1.4.7 Work unit ACE_INT.1-6
69 11.2.1.4.8 Work unit ACE_INT.1-7
11.2.1.4.9 Work unit ACE_INT.1-8
11.2.1.4.10 Work unit ACE_INT.1-9
11.3 PP-Module conformance claims (ACE_CCL)
11.3.1 Evaluation of sub-activity (ACE_CCL.1)
11.3.1.1 Objectives
11.3.1.2 Input
11.3.1.3 Action ACE_CCL.1.1E
11.3.1.3.1 Work unit ACE_CCL.1-1
70 11.3.1.3.2 Work unit ACE_CCL.1-2
11.3.1.3.3 Work unit ACE_CCL.1-3
11.3.1.3.4 Work unit ACE_CCL.1-4
11.3.1.3.5 Work unit ACE_CCL.1-5
71 11.3.1.3.6 Work unit ACE_CCL.1-6
11.3.1.3.7 Work unit ACE_CCL.1-7
72 11.3.1.3.8 Work unit ACE_CCL.1-8
11.3.1.3.9 Work unit ACE_CCL.1-9
73 11.3.1.3.10 Work unit ACE_CCL.1-10
11.3.1.3.11 Work unit ACE_CCL.1-11
11.3.1.3.12 Work unit ACE_CCL.1-12
74 11.4 PP-Module Security problem definition (ACE_SPD)
11.4.1 Evaluation of sub-activity (ACE_SPD.1)
11.4.1.1 Objectives
11.4.1.2 Input
11.4.1.3 Action ACE_SPD.1.1E
11.4.1.3.1 General
11.4.1.3.2 Work unit ACE_SPD.1-1
11.4.1.3.3 Work unit ACE_SPD.1-2
75 11.4.1.3.4 Work unit ACE_SPD.1-3
11.4.1.3.5 Work unit ACE_SPD.1-4
11.5 PP-Module Security objectives (ACE_OBJ)
11.5.1 Evaluation of sub-activity (ACE_OBJ.1)
11.5.1.1 Application notes
11.5.1.2 Action ACE_OBJ.1.1E
11.5.1.2.1 General
11.5.1.2.2 Work unit ACE_OBJ.1-1
76 11.5.1.2.3 Work unit ACE_OBJ.1-2
11.5.1.2.4 Work unit APE_OBJ.1-3
11.5.2 Evaluation of sub-activity (ACE_OBJ.2)
11.5.2.1 Objectives
11.5.2.2 Input
77 11.5.2.3 Action ACE_OBJ.2.1E
11.5.2.3.1 General
11.5.2.3.2 Work unit ACE_OBJ.2-1
11.5.2.3.3 Work unit ACE_OBJ.2-2
11.5.2.3.4 Work unit ACE_OBJ.2-3
11.5.2.3.5 Work unit ACE_OBJ.2-4
78 11.5.2.3.6 Work unit ACE_OBJ.2-6
79 11.6 PP-Module extended components definition (ACE_ECD)
11.6.1 Evaluation of sub-activity (ACE_ECD.1)
11.6.1.1 Objectives
11.6.1.2 Input
11.6.1.3 Action ACE_ECD.1.1E
11.6.1.3.1 General
11.6.1.3.2 Work unit ACE_ECD.1-1
11.6.1.3.3 Work unit ACE_ECD.1-2
11.6.1.3.4 Work unit ACE_ECD.1-3APE_ECD.1-3
80 11.6.1.3.5 Work unit ACE_ECD.1-4APE_ECD.1-4
11.6.1.3.6 Work unit ACE_ECD.1-5
11.6.1.3.7 Work unit ACE_ECD.1-6
81 11.6.1.3.8 Work unit ACE_ECD.1-7
11.6.1.3.9 Work unit ACE_ECD.1-8
11.6.1.3.10 Work unit ACE_ECD.1-9
11.6.1.3.11 Work unit ACE_ECD.1-10
82 11.6.1.3.12 Work unit ACE_ECD.1-11
11.6.1.3.13 Work unit ACE_ECD.1-12
11.6.1.4 Action ACE_ECD.1.2E
11.6.1.4.1 Work unit ACE_ECD.1-13
83 11.7 PP-Module security requirements (ACE_REQ)
11.7.1 Evaluation of sub-activity (ACE_REQ.1)
11.7.1.1 Objectives
11.7.1.2 Input
11.7.1.3 Action ACE_REQ.1.1E
11.7.1.3.1 General
11.7.1.3.2 Work unit ACE_REQ.1-1
11.7.1.3.3 Work unit ACE_REQ.1-2
84 11.7.1.3.4 Work unit ACE_REQ.1-3
11.7.1.3.5 Work unit ACE_REQ.1-4
11.7.1.3.6 Work unit ACE_REQ.1-5
85 11.7.1.3.7 Work unit ACE_REQ.1-6
11.7.1.3.8 Work unit ACE_REQ.1-7
11.7.1.3.9 Work unit ACE_REQ.1-8
11.7.1.3.10 Work unit ACE_REQ.1-9
11.7.1.3.11 Work unit ACE_REQ.1-10
86 11.7.1.3.12 Work unit ACE_REQ.1-11
11.7.1.3.13 Work unit ACE_REQ.1-12
11.7.1.3.14 Work unit ACE_REQ.1-13
87 11.7.1.3.15 Work unit ACE_REQ.1-14
88 11.7.2 Evaluation of sub-activity (ACE_REQ.2)
11.7.2.1 Objectives
11.7.2.2 Input
11.7.2.3 Action ACE_REQ.2.1E
11.7.2.3.1 General
11.7.2.3.2 Work unit ACE_REQ.2-1
11.7.2.3.3 Work unit ACE_REQ.2-2
89 11.7.2.3.4 Work unit ACE_REQ.2-3
11.7.2.3.5 Work unit ACE_REQ.2-4
11.7.2.3.6 Work unit ACE_REQ.2-5
90 11.7.2.3.7 Work unit ACE_REQ.2-6
11.7.2.3.8 Work unit ACE_REQ.2-7
11.7.2.3.9 Work unit ACE_REQ.2-8
11.7.2.3.10 Work unit ACE_REQ.2-9
11.7.2.3.11 Work unit ACE_REQ.2-10
91 11.7.2.3.12 Work unit ACE_REQ.2-11
11.7.2.3.13 Work unit ACE_REQ.2-12
11.7.2.3.14 Work unit ACE_REQ.2-13
92 11.8 PP-Module consistency (ACE_MCO)
11.8.1 Evaluation of sub-activity (ACE_MCO.1)
11.8.1.1 Objectives
11.8.1.2 Input
11.8.1.3 Action ACE_MCO.1.1E
11.8.1.3.1 General
93 11.8.1.3.2 Work unit ACE_MCO.1-1
11.8.1.3.3 Work unit ACE_MCO.1-2
11.8.1.3.4 Work unit ACE_MCO.1-3
11.8.1.3.5 Work unit ACE_MCO.1-4
94 11.8.1.3.6 Work unit ACE_MCO.1-5
11.8.1.3.7 Work unit ACE_MCO.1-6
11.8.1.3.8 Work unit ACE_MCO.1-7
95 11.8.1.3.9 Work unit ACE_MCO.1-8
11.8.1.3.10 Work unit ACE_MCO.1-9
11.8.1.3.11 Work unit ACE_MCO.1-10
11.8.1.3.12 Work unit ACE_MCO.1-11
11.8.1.3.13 Work unit ACE_MCO.1-12
11.9 PP-Configuration consistency (ACE_CCO)
11.9.1 Evaluation of sub-activity (ACE_CCO.1)
11.9.1.1 Objectives
96 11.9.1.2 Input
11.9.1.3 Action ACE_CCO.1.1E
11.9.1.3.1 General
11.9.1.3.2 Work unit ACE_CCO.1-1
11.9.1.3.3 Work unit ACE_CCO.1-2
11.9.1.3.4 Work unit ACE_CCO.1-3
11.9.1.3.5 Work unit ACE_CCO.1-4
11.9.1.3.6 Work unit ACE_CCO.1-5
97 11.9.1.3.7 Work unit ACE_CCO.1-6
11.9.1.3.8 Work unit ACE_CCO.1-7
11.9.1.3.9 Work unit ACE_CCO.1-8
11.9.1.3.10 Work unit ACE_CCO.1-9
11.9.1.3.11 Work unit ACE_CCO.1-10
98 11.9.1.3.12 Work unit ACE_CCO.1-11
11.9.1.3.13 Work unit ACE_CCO.1-12
11.9.1.3.14 Work unit ACE_CCO.1-13
11.9.1.3.15 Work unit ACE_CCO.1-14
11.9.1.3.16 Work unit ACE_CCO.1-15
99 11.9.1.3.17 Work unit ACE_CCO.1-16
11.9.1.3.18 Work unit ACE_CCO.1-17
11.9.1.3.19 Work unit ACE_CCO.1-18
100 11.9.1.3.20 Work unit ACE_CCO.1-19
11.9.1.3.21 Work unit ACE_CCO.1-20
11.9.1.3.22 Work unit ACE_CCO.1-21
11.9.1.3.23 Work unit ACE_CCO.1-22
11.9.1.3.24 Work unit ACE_CCO.1-23
11.9.1.3.25 Work unit ACE_CCO.1-24
101 11.9.1.3.26 Work unit ACE_CCO.1-25
11.9.1.3.27 Work unit ACE_CCO.1-26
11.9.1.3.28 Work unit ACE_CCO.1-27
11.9.1.3.29 Work unit ACE_CCO.1-28
11.9.1.3.30 Work unit ACE_CCO.1-29
102 11.9.1.3.31 Work unit ACE_CCO.1-30
11.9.1.3.32 Work unit ACE_CCO.1-31
11.9.1.3.33 Work unit ACE_CCO.1-32
11.9.1.3.34 Work unit ACE_CCO.1-33
11.9.1.3.35 Work unit ACE_CCO.1-34
11.9.1.3.36 Work unit ACE_CCO.1-35
11.9.1.3.37 Work unit ACE_CCO.1-36
11.9.1.4 Action ACE_CCO.1.2E
11.9.1.4.1 Work unit ACE_CCO.1-37
103 12 Class ASE: Security Target evaluation
12.1 General
12.2 Application notes
12.2.1 Re-using the evaluation results of certified PPs
104 12.3 ST introduction (ASE_INT)
12.3.1 Evaluation of sub-activity (ASE_INT.1)
12.3.1.1 Objectives
12.3.1.2 Input
12.3.1.3 Action ASE_INT.1.1E
12.3.1.3.1 General
12.3.1.3.2 Work unit ASE_INT.1-1
12.3.1.3.3 Work unit ASE_INT.1-2
12.3.1.3.4 Work unit ASE_INT.1-3
105 12.3.1.3.5 Work unit ASE_INT.1-4
12.3.1.3.6 Work unit ASE_INT.1-5
12.3.1.3.7 Work unit ASE_INT.1-6
12.3.1.3.8 Work unit ASE_INT.1-7
106 12.3.1.3.9 Work unit ASE_INT.1-8
12.3.1.3.10 Work unit ASE_INT.1-9
12.3.1.3.11 Work unit ASE_INT.1-10
12.3.1.3.12 Work unit ASE_INT.1-11
107 12.3.1.4 Action ASE_INT.1.2E
12.3.1.4.1 Work unit ASE_INT.1-12
12.4 Conformance claims (ASE_CCL)
12.4.1 Evaluation of sub-activity (ASE_CCL.1)
12.4.1.1 Objectives
12.4.1.2 Input
12.4.1.3 Action ASE_CCL.1.1E
12.4.1.3.1 General
12.4.1.3.2 Work unit ASE_CCL.1-1
108 12.4.1.3.3 Work unit ASE_CCL.1-2
12.4.1.3.4 Work unit ASE_CCL.1-3
12.4.1.3.5 Work unit ASE_CCL.1-4
12.4.1.3.6 Work unit ASE_CCL.1-5
109 12.4.1.3.7 Work unit ASE_CCL.1-6
12.4.1.3.8 Work unit ASE_CCL.1-7
12.4.1.3.9 Work unit ASE_CCL.1-8
110 Figure 8 — Example of exact conformance relationships between an ST and PPs
12.4.1.3.10 Work unit ASE_CCL.1-9
12.4.1.3.11 Work unit ASE_CCL.1-10
12.4.1.3.12 Work unit ASE_CCL.1-11
111 12.4.1.3.13 Work unit ASE_CCL.1-12
112 12.4.1.3.14 Work unit ASE_CCL.1-13
12.4.1.3.15 Work unit ASE_CCL.1-14
113 12.4.1.3.16 Work unit ASE_CCL.1-15
12.4.1.3.17 Work unit ASE_CCL.1-16
12.4.1.3.18 Work unit ASE_CCL.1-17
116 12.4.1.3.19 Work unit ASE_CCL.1-18
118 12.4.1.3.20 Work unit ASE_CCL.1-19
120 12.4.1.3.21 Work unit ASE_CCL.1-20
12.4.1.3.22 Work unit ASE_CCL.1-21
121 12.5 Security problem definition (ASE_SPD)
12.5.1 Evaluation of sub-activity (ASE_SPD.1)
12.5.1.1 Objectives
12.5.1.2 Input
12.5.1.3 Action ASE_SPD.1.1E
12.5.1.3.1 General
12.5.1.3.2 Work Unit ASE_SPD.1-1
12.5.1.3.3 Work unit ASE_SPD.1-2
12.5.1.3.4 Work unit ASE_SPD.1-3
122 12.5.1.3.5 Work unit ASE_SPD.1-4
12.6 Security objectives (ASE_OBJ)
12.6.1 Evaluation of sub-activity (ASE_OBJ.1)
12.6.1.1 Objectives
12.6.1.2 Input
12.6.1.3 Action ASE_OBJ.1.1E
12.6.1.3.1 General
12.6.1.3.2 Work unit ASE_OBJ.1-1
12.6.1.3.3 Work unit ASE_OBJ.1-2
123 12.6.1.3.4 Work unit ASE_OBJ.1-3
12.6.2 Evaluation of sub-activity (ASE_OBJ.2)
12.6.2.1 Objectives
12.6.2.2 Input
12.6.2.3 Action ASE_OBJ.2.1E
12.6.2.3.1 General
12.6.2.3.2 Work unit ASE_OBJ.2-1
124 12.6.2.3.3 Work unit ASE_OBJ.2-2
12.6.2.3.4 Work unit ASE_OBJ.2-3
12.6.2.3.5 Work unit ASE_OBJ.2-4
125 12.6.2.3.6 Work unit ASE_OBJ.2-5
12.6.2.3.7 Work unit ASE_OBJ.2-6
12.7 Extended components definition (ASE_ECD)
12.7.1 Evaluation of sub-activity (ASE_ECD.1)
12.7.1.1 Objectives
126 12.7.1.2 Input
12.7.1.3 Action ASE_ECD.1.1E
12.7.1.3.1 General
12.7.1.3.2 Work unit ASE_ECD.1-1
12.7.1.3.3 Work unit ASE_ECD.1-2
12.7.1.3.4 Work unit ASE_ECD.1-3
127 12.7.1.3.5 Work unit ASE_ECD.1-4
12.7.1.3.6 Work unit ASE_ECD.1-5
12.7.1.3.7 Work unit ASE_ECD.1-6
12.7.1.3.8 Work unit ASE_ECD.1-7
128 12.7.1.3.9 Work unit ASE_ECD.1-8
12.7.1.3.10 Work unit ASE_ECD.1-9
12.7.1.3.11 Work unit ASE_ECD.1-10
12.7.1.3.12 Work unit ASE_ECD.1-11
129 12.7.1.3.13 General
12.7.1.3.14 Work unit ASE_ECD.1-12
12.7.1.3.15 Action ASE_ECD.1.2E
12.7.1.3.16 Work unit ASE_ECD.1-13
12.8 Security requirements (ASE_REQ)
12.8.1 Evaluation of sub-activity (ASE_REQ.1)
12.8.1.1 Objectives
12.8.1.2 Input
130 12.8.1.3 Action ASE_REQ.1.1E
12.8.1.3.1 General
12.8.1.3.2 Work unit ASE_REQ.1-1
12.8.1.3.3 Work unit ASE_REQ.1-2
12.8.1.3.4 Work unit ASE_REQ.1-3
131 12.8.1.3.5 Work unit ASE_REQ.1-4
12.8.1.3.6 Work unit ASE_REQ.1-5
12.8.1.3.7 Work unit ASE_REQ.1-6
12.8.1.3.8 Work unit ASE_REQ.1-7
12.8.1.3.9 Work unit ASE_REQ.1-8
132 12.8.1.3.10 Work unit ASE_REQ.1-9
12.8.1.3.11 Work unit ASE_REQ.1-10
12.8.1.3.12 Work unit ASE_REQ.1-11
12.8.1.3.13 Work unit ASE_REQ.1-12
12.8.1.3.14 Work unit ASE_REQ.1-13
12.8.1.3.15 Work unit ASE_REQ.1-14
133 12.8.1.3.16 Work unit ASE_REQ.1-15
12.8.1.3.17 Work unit ASE_REQ.1-16
134 12.8.1.3.18 Work unit ASE_REQ.1-17
12.8.1.3.19 Work unit ASE_REQ.1-18
135 12.8.1.3.20 Work unit ASE_REQ.1-19
12.8.2 Evaluation of sub-activity (ASE_REQ.2)
12.8.2.1 Objectives
12.8.2.2 Input
12.8.2.3 Action ASE_REQ.2.1E
12.8.2.3.1 General
12.8.2.3.2 Work unit ASE_REQ.2-1
136 12.8.2.3.3 Work unit ASE_REQ.2-2
12.8.2.3.4 Work unit ASE_REQ.2-3
12.8.2.3.5 Work unit ASE_REQ.2-4
12.8.2.3.6 Work unit ASE_REQ.2-5
137 12.8.2.3.7 Work unit ASE_REQ.2-6
12.8.2.3.8 Work unit ASE_REQ.2-7
12.8.2.3.9 Work unit ASE_REQ.2-8
12.8.2.3.10 Work unit ASE_REQ.2-9
12.8.2.3.11 Work unit ASE_REQ.2-10
138 12.8.2.3.12 Work unit ASE_REQ.2-11
12.8.2.3.13 Work unit ASE_REQ.2-12
12.8.2.3.14 Work unit ASE_REQ.2-13
12.8.2.3.15 Work unit ASE_REQ.2-14
12.8.2.3.16 Work unit ASE_REQ.2-15
139 12.8.2.3.17 Work unit ASE_REQ.2-16
12.8.2.3.18 Work unit ASE_REQ.2-17
12.8.2.3.19 Work unit ASE_REQ.2-18
140 12.8.2.3.20 Work unit ASE_REQ.2-19
12.9 TOE summary specification (ASE_TSS)
12.9.1 Evaluation of sub-activity (ASE_TSS.1)
12.9.1.1 Objectives
141 12.9.1.2 Input
12.9.1.3 Action ASE_TSS.1.1E
12.9.1.3.1 General
12.9.1.3.2 Work unit ASE_TSS.1-1
12.9.1.4 Action ASE_TSS.1.2E
12.9.1.4.1 Work unit ASE_TSS.1-2
12.9.2 Evaluation of sub-activity (ASE_TSS.2)
12.9.2.1 Objectives
12.9.2.2 Input
12.9.2.3 Action ASE_TSS.2.1E
12.9.2.3.1 General
142 12.9.2.3.2 Work unit ASE_TSS.2-1
12.9.2.3.3 Work unit ASE_TSS.2-2
12.9.2.3.4 Work unit ASE_TSS.2-3
12.9.2.4 Action ASE_TSS.2.2E
12.9.2.4.1 Work unit ASE_TSS.2-4
143 12.10 Consistency of composite product Security Target (ASE_COMP)
12.10.1 General
12.10.2 Evaluation of sub-activity (ASE_COMP.1)
12.10.2.1 Objectives
12.10.2.2 Application notes
145 12.10.2.3 Action ASE_COMP.1.1E
12.10.2.3.1 General
12.10.2.3.2 Work unit ASE_COMP.1-1
146 12.10.2.3.3 Work unit ASE_COMP.1-2
12.10.2.3.4 Work unit ASE_COMP.1-3
12.10.2.3.5 Work unit ASE_COMP.1-4
147 12.10.2.3.6 Work unit ASE_COMP.1-5
12.10.2.3.7 Work unit ASE_COMP.1-6
148 13 Class ADV: Development
13.1 General
13.2 Application notes
149 13.3 Security Architecture (ADV_ARC)
13.3.1 Evaluation of sub-activity (ADV_ARC.1)
13.3.1.1 Objectives
13.3.1.2 Input
13.3.1.3 Application notes
150 13.3.1.4 Action ADV_ARC.1.1E
13.3.1.4.1 General
13.3.1.4.2 Work unit ADV_ARC.1-1
13.3.1.4.3 Work unit ADV_ARC.1-2
151 13.3.1.4.4 Work unit ADV_ARC.1-3
13.3.1.4.5 Work unit ADV_ARC.1-4
152 13.3.1.4.6 Work unit ADV_ARC.1-5
153 13.4 Functional specification (ADV_FSP)
13.4.1 Evaluation of sub-activity (ADV_FSP.1)
13.4.1.1 Objectives
13.4.1.2 Input
13.4.1.3 Action ADV_FSP.1.1E
13.4.1.3.1 General
13.4.1.3.2 Work unit ADV_FSP.1-1
154 13.4.1.3.3 Work unit ADV_FSP.1-2
155 13.4.1.3.4 Work unit ADV_FSP.1-3
13.4.1.3.5 Work unit ADV_FSP.1-4
13.4.1.3.6 Work unit ADV_FSP.1-5
156 13.4.1.4 Action ADV_FSP.1.2E
13.4.1.4.1 Work unit ADV_FSP.1-6
13.4.1.4.2 Work unit ADV_FSP.1-7
13.4.2 Evaluation of sub-activity (ADV_FSP.2)
13.4.2.1 Objectives
13.4.2.2 Input
157 13.4.2.3 Action ADV_FSP.2.1E
13.4.2.3.1 General
13.4.2.3.2 Work unit ADV_FSP.2-1
13.4.2.3.3 Work unit ADV_FSP.2-2
13.4.2.3.4 Work unit ADV_FSP.2-3
158 13.4.2.3.5 Work unit ADV_FSP.2-4
13.4.2.3.6 Work unit ADV_FSP.2-5
13.4.2.3.7 Work unit ADV_FSP.2-6
159 13.4.2.3.8 Work unit ADV_FSP.2-7
160 13.4.2.3.9 Work unit ADV_FSP.2-8
13.4.2.4 Action ADV_FSP.2.2E
13.4.2.4.1 Work unit ADV_FSP.2-9
13.4.2.4.2 Work unit ADV_FSP.2-10
161 13.4.3 Evaluation of sub-activity (ADV_FSP.3)
13.4.3.1 Objectives
13.4.3.2 Input
13.4.3.3 Action ADV_FSP.3.1E
13.4.3.3.1 General
13.4.3.3.2 Work unit ADV_FSP.3-1
162 13.4.3.3.3 Work unit ADV_FSP.3-2
13.4.3.3.4 Work unit ADV_FSP.3-3
13.4.3.3.5 Work unit ADV_FSP.3-4
163 13.4.3.3.6 Work unit ADV_FSP.3-5
13.4.3.3.7 Work unit ADV_FSP.3-6
164 13.4.3.3.8 Work unit ADV_FSP.3-7
165 13.4.3.3.9 Work unit ADV_FSP.3-8
13.4.3.3.10 Work unit ADV_FSP.3-9
13.4.3.4 Action ADV_FSP.3.2E
13.4.3.4.1 Work unit ADV_FSP.3-10
166 13.4.3.4.2 Work unit ADV_FSP.3-11
13.4.4 Evaluation of sub-activity (ADV_FSP.4)
13.4.4.1 Objectives
13.4.4.2 Input
13.4.4.3 Application notes
167 13.4.4.4 Action ADV_FSP.4.1E
13.4.4.4.1 General
13.4.4.4.2 Work unit ADV_FSP.4-1
13.4.4.4.3 Work unit ADV_FSP.4-2
13.4.4.4.4 Work unit ADV_FSP.4-3
168 13.4.4.4.5 Work unit ADV_FSP.4-4
13.4.4.4.6 Work unit ADV_FSP.4-5
13.4.4.4.7 Work unit ADV_FSP.4-6
169 13.4.4.4.8 Work unit ADV_FSP.4-7
13.4.4.4.9 Work unit ADV_FSP.4-8
170 13.4.4.4.10 Work unit ADV_FSP.4-9
13.4.4.4.11 Work unit ADV_FSP.4-10
13.4.4.5 Action ADV_FSP.4.2E
13.4.4.5.1 Work unit ADV_FSP.4-11
171 13.4.4.5.2 Work unit ADV_FSP.4-12
13.4.5 Evaluation of sub-activity (ADV_FSP.5)
13.4.5.1 Objectives
13.4.5.2 Input
172 13.4.5.3 Action ADV_FSP.5.1E
13.4.5.3.1 General
13.4.5.3.2 Work unit ADV_FSP.5-1
13.4.5.3.3 Work unit ADV_FSP.5-2
13.4.5.3.4 Work unit ADV_FSP.5-3
13.4.5.3.5 Work unit ADV_FSP.5-4
173 13.4.5.3.6 Work unit ADV_FSP.5-5
13.4.5.3.7 Work unit ADV_FSP.5-6
13.4.5.3.8 Work unit ADV_FSP.5-7
174 13.4.5.3.9 Work unit ADV_FSP.5-8
13.4.5.3.10 Work unit ADV_FSP.5-9
175 13.4.5.3.11 Work unit ADV_FSP.5-10
13.4.5.3.12 Work unit ADV_FSP.5-11
176 13.4.5.3.13 Work unit ADV_FSP.5-12
13.4.5.3.14 Work unit ADV_FSP.5-13
13.4.5.4 Action ADV_FSP.5.2E
13.4.5.4.1 Work unit ADV_FSP.5-14
13.4.5.4.2 Work unit ADV_FSP.5-15
177 13.4.6 Evaluation of sub-activity (ADV_FSP.6)
13.5 Implementation representation (ADV_IMP)
13.5.1 Evaluation of sub-activity (ADV_IMP.1)
13.5.1.1 Objectives
13.5.1.2 Input
178 13.5.1.3 Application notes
13.5.1.4 Action ADV_IMP.1.1E
13.5.1.4.1 General
13.5.1.4.2 Work unit ADV_IMP.1-1
13.5.1.4.3 Work unit ADV_IMP.1-2
179 13.5.1.4.4 Work unit ADV_IMP.1-3
180 13.5.2 Evaluation of sub-activity (ADV_IMP.2)
13.5.2.1 Objectives
13.5.2.2 Input
13.5.2.3 Application notes
13.5.2.4 Action ADV_IMP.2.1E
13.5.2.4.1 General
13.5.2.4.2 Work unit ADV_IMP.2-1
181 13.5.2.4.3 Work unit ADV_IMP.2-2
13.5.2.4.4 Work unit ADV_IMP.2-3
182 13.5.2.4.5 Work unit ADV_IMP.2-4
13.6 TSF internals (ADV_INT)
13.6.1 Evaluation of sub-activity (ADV_INT.1)
13.6.1.1 Objectives
13.6.1.2 Input
183 13.6.1.3 Application notes
13.6.1.4 Action ADV_INT.1.1E
13.6.1.4.1 General
13.6.1.4.2 Work unit ADV_INT.1-1
184 13.6.1.4.3 Work unit ADV_INT.1-2
13.6.1.4.4 Work unit ADV_INT.1-3
13.6.1.5 Action ADV_INT.1.2E
13.6.1.5.1 Work unit ADV_INT.1-4
13.6.1.5.2 Work unit ADV_INT.1-5
185 13.6.2 Evaluation of sub-activity (ADV_INT.2)
13.6.2.1 Objectives
13.6.2.2 Input
13.6.2.3 Application notes
13.6.2.4 Action ADV_INT.2.1E
13.6.2.4.1 General
13.6.2.4.2 Work unit ADV_INT.2-1
186 13.6.2.4.3 Work unit ADV_INT.2-2
13.6.2.5 Action ADV_INT.2.2E
13.6.2.5.1 Work unit ADV_INT.2-3
187 13.6.2.5.2 Work unit ADV_INT.2-4
13.6.3 Evaluation of sub-activity (ADV_INT.3)
13.6.3.1 Objectives
13.6.3.2 Input
13.6.3.3 Application notes
13.6.3.4 Action ADV_INT.3.1E
13.6.3.4.1 General
188 13.6.3.4.2 Work unit ADV_INT.3-1
13.6.3.4.3 Work unit ADV_INT.3-2
189 13.6.3.5 Action ADV_INT.3.2E
13.6.3.5.1 Work unit ADV_INT.3-3
13.6.3.5.2 Work unit ADV_INT.3-4
13.7 Formal TSF model (ADV_SPM)
13.7.1 Evaluation of sub-activity (ADV_SPM.1)
13.7.1.1 Objectives
190 13.7.1.2 Inputs
13.7.1.3 Application notes
191 13.7.1.4 Action ADV_SPM.1.1E
13.7.1.4.1 General
13.7.1.4.2 Work unit ADV_SPM.1-1
13.7.1.4.3 Work unit ADV_SPM.1-2
192 13.7.1.4.4 Work unit ADV_SPM.1-3
13.7.1.4.5 Work unit ADV_SPM.1-4
13.7.1.4.6 Work unit ADV_SPM.1-5
13.7.1.4.7 Work unit ADV_SPM.1-6
193 13.7.1.4.8 Work unit ADV_SPM.1-7
13.7.1.4.9 Work unit ADV_SPM.1-8
13.7.1.4.10 Work unit ADV_SPM.1-9
194 13.7.1.4.11 Work unit ADV_SPM.1-10
13.7.1.4.12 Work unit ADV_SPM.1-11
195 13.7.1.4.13 Work unit ADV_SPM.1-12
13.7.1.4.14 Work unit ADV_SPM.1-13
13.7.1.4.15 Work unit ADV_SPM.1-14
196 13.8 TOE design (ADV_TDS)
13.8.1 Evaluation of sub-activity (ADV_TDS.1)
13.8.1.1 Input
13.8.1.2 Action ADV_TDS.1.1E
13.8.1.2.1 General
13.8.1.2.2 Work unit ADV_TDS.1-1
13.8.1.2.3 Work unit ADV_TDS.1-2
197 13.8.1.2.4 Work unit ADV_TDS.1-3
13.8.1.2.5 Work unit ADV_TDS.1-4
198 13.8.1.2.6 Work unit ADV_TDS.1-5
13.8.1.2.7 Work unit ADV_TDS.1-6
199 13.8.1.3 Action ADV_TDS.1.2E
13.8.1.3.1 Work unit ADV_TDS.1-7
13.8.1.3.2 Work unit ADV_TDS.1-8
13.8.2 Evaluation of sub-activity (ADV_TDS.2)
13.8.2.1 Input
200 13.8.2.2 Action ADV_TDS.2.1E
13.8.2.2.1 General
13.8.2.2.2 Work unit ADV_TDS.2-1
13.8.2.2.3 Work unit ADV_TDS.2-2
13.8.2.2.4 Work unit ADV_TDS.2-3
201 13.8.2.2.5 Work unit ADV_TDS.2-4
13.8.2.2.6 Work unit ADV_TDS.2-5
202 13.8.2.2.7 Work unit ADV_TDS.2-6
13.8.2.2.8 Work unit ADV_TDS.2-7
203 13.8.2.2.9 Work unit ADV_TDS.2-8
13.8.2.3 Action ADV_TDS.2.2E
13.8.2.3.1 Work unit ADV_TDS.2-9
204 13.8.2.3.2 Work unit ADV_TDS.2-10
13.8.3 Evaluation of sub-activity (ADV_TDS.3)
13.8.3.1 Objectives
13.8.3.2 Input
13.8.3.3 Application notes
205 13.8.3.4 Action ADV_TDS.3.1E
13.8.3.4.1 General
13.8.3.4.2 Work unit ADV_TDS.3-1
206 13.8.3.4.3 Work unit ADV_TDS.3-2
13.8.3.4.4 Work unit ADV_TDS.3-3
13.8.3.4.5 Work unit ADV_TDS.3-4
207 13.8.3.4.6 Work unit ADV_TDS.3-5
13.8.3.4.7 Work unit ADV_TDS.3-6
208 13.8.3.4.8 Work unit ADV_TDS.3-7
13.8.3.4.9 Work unit ADV_TDS.3-8
13.8.3.4.10 Work unit ADV_TDS.3-9
209 13.8.3.4.11 Work unit ADV_TDS.3-10
210 13.8.3.4.12 Work unit ADV_TDS.3-11
211 13.8.3.4.13 Work unit ADV_TDS.3-12
13.8.3.4.14 Work unit ADV_TDS.3-13
212 13.8.3.4.15 Work unit ADV_TDS.3-14
13.8.3.5 Action ADV_TDS.3.2E
13.8.3.5.1 Work unit ADV_TDS.3-15
13.8.3.5.2 Work unit ADV_TDS.3-16
213 13.8.4 Evaluation of sub-activity (ADV_TDS.4)
13.8.4.1 Objectives
13.8.4.2 Input
13.8.4.3 Application notes
13.8.4.4 Action ADV_TDS.4.1E
13.8.4.4.1 General
214 13.8.4.4.2 Work unit ADV_TDS.4-1
13.8.4.4.3 Work unit ADV_TDS.4-2
13.8.4.4.4 Work unit ADV_TDS.4-3
215 13.8.4.4.5 Work unit ADV_TDS.4-4
13.8.4.4.6 Work unit ADV_TDS.4-5
13.8.4.4.7 Work unit ADV_TDS.4-6
216 13.8.4.4.8 Work unit ADV_TDS.4-7
13.8.4.4.9 Work unit ADV_TDS.4-8
217 13.8.4.4.10 Work unit ADV_TDS.4-9
13.8.4.4.11 Work unit ADV_TDS.4-10
13.8.4.4.12 Work unit ADV_TDS.4-11
218 13.8.4.4.13 Work unit ADV_TDS.4-12
219 13.8.4.4.14 Work unit ADV_TDS.4-13
220 13.8.4.4.15 Work unit ADV_TDS.4-14
13.8.4.4.16 Work unit ADV_TDS.4-15
221 13.8.4.4.17 Work unit ADV_TDS.4-16
13.8.4.5 Action ADV_TDS.4.2E
13.8.4.5.1 Work unit ADV_TDS.4-17
222 13.8.4.5.2 Work unit ADV_TDS.4-18
13.8.5 Evaluation of sub-activity (ADV_TDS.5)
13.8.5.1 Objectives
13.8.5.2 Input
13.8.5.3 Application notes
223 13.8.5.4 Action ADV_TDS.5.1E
13.8.5.4.1 General
13.8.5.4.2 Work unit ADV_TDS.5-1
13.8.5.4.3 Work unit ADV_TDS.5-2
224 13.8.5.4.4 Work unit ADV_TDS.5-3
13.8.5.4.5 Work unit ADV_TDS.5-4
13.8.5.4.6 Work unit ADV_TDS.5-5
225 13.8.5.4.7 Work unit ADV_TDS.5-6
13.8.5.4.8 Work unit ADV_TDS.5-7
13.8.5.4.9 Work unit ADV_TDS.5-8
226 13.8.5.4.10 Work unit ADV_TDS.5-9
13.8.5.4.11 Work unit ADV_TDS.5-10
227 13.8.5.4.12 Work unit ADV_TDS.5-11
13.8.5.4.13 Work unit ADV_TDS.5-12
228 13.8.5.4.14 Work unit ADV_TDS.5-13
229 13.8.5.4.15 Work unit ADV_TDS.5-14
13.8.5.4.16 Work unit ADV_TDS.5-15
13.8.6 Evaluation of sub-activity (ADV_TDS.6)
230 13.9 Composite design compliance (ADV_COMP)
13.9.1 General
Table 2 — ADV_COMP
13.9.2 Evaluation of sub-activity (ADV_COMP.1)
13.9.2.1 Objectives
13.9.2.2 Application notes
231 13.9.2.3 Action ADV_COMP.1.1E
13.9.2.3.1 General
13.9.2.3.2 Work unit ADV_COMP.1-1
232 14 Class AGD: Guidance documents
14.1 General
14.2 Application notes
233 14.3 Operational user guidance (AGD_OPE)
14.3.1 Evaluation of sub-activity (AGD_OPE.1)
14.3.1.1 Objectives
14.3.1.2 Input
14.3.1.3 Action AGD_OPE.1.1E
14.3.1.3.1 General
14.3.1.3.2 Work unit AGD_OPE.1-1
14.3.1.3.3 Work unit AGD_OPE.1-2
234 14.3.1.3.4 Work unit AGD_OPE.1-3
14.3.1.3.5 Work unit AGD_OPE.1-4
14.3.1.3.6 Work unit AGD_OPE.1-5
235 14.3.1.3.7 Work unit AGD_OPE.1-6
14.3.1.3.8 Work unit AGD_OPE.1-7
14.3.1.3.9 Work unit AGD_OPE.1-8
14.4 Preparative procedures (AGD_PRE)
14.4.1 Evaluation of sub-activity (AGD_PRE.1)
14.4.1.1 Objectives
236 14.4.1.2 Input
14.4.1.3 Application notes
14.4.1.4 Action AGD_PRE.1.1E
14.4.1.4.1 General
14.4.1.4.2 Work unit AGD_PRE.1-1
14.4.1.4.3 Work unit AGD_PRE.1-2
237 14.4.1.5 Action AGD_PRE.1.2E
14.4.1.5.1 Work unit AGD_PRE.1-3
15 Class ALC: Life-cycle support
15.1 General
238 15.2 CM capabilities (ALC_CMC)
15.2.1 Evaluation of sub-activity (ALC_CMC.1)
15.2.1.1 Objectives
15.2.1.2 Input
15.2.1.3 Action ALC_CMC.1.1E
15.2.1.3.1 General
15.2.1.3.2 Work unit ALC_CMC.1-1
15.2.1.3.3 Work unit ALC_CMC.1-2
239 15.2.2 Evaluation of sub-activity (ALC_CMC.2)
15.2.2.1 Objectives
15.2.2.2 Input
15.2.2.3 Application notes
15.2.2.4 Action ALC_CMC.2.1E
15.2.2.4.1 General
15.2.2.4.2 Work unit ALC_CMC.2-1
240 15.2.2.4.3 Work unit ALC_CMC.2-2
15.2.2.4.4 Work unit ALC_CMC.2-3
15.2.2.4.5 Work unit ALC_CMC.2-4
241 15.2.3 Evaluation of sub-activity (ALC_CMC.3)
15.2.3.1 Objectives
15.2.3.2 Input
15.2.3.3 Action ALC_CMC.3.1E
15.2.3.3.1 General
15.2.3.3.2 Work unit ALC_CMC.3-1
15.2.3.3.3 Work unit ALC_CMC.3-2
242 15.2.3.3.4 Work unit ALC_CMC.3-3
15.2.3.3.5 Work unit ALC_CMC.3-4
15.2.3.3.6 Work unit ALC_CMC.3-5
15.2.3.3.7 Work unit ALC_CMC.3-6
243 15.2.3.3.8 Work unit ALC_CMC.3-7
15.2.3.3.9 Work unit ALC_CMC.3-8
244 15.2.3.3.10 Work unit ALC_CMC.3-9
15.2.3.3.11 Work unit ALC_CMC.3-10
15.2.4 Evaluation of sub-activity (ALC_CMC.4)
15.2.4.1 Objectives
15.2.4.2 Input
245 15.2.4.3 Action ALC_CMC.4.1E
15.2.4.3.1 General
15.2.4.3.2 Work unit ALC_CMC.4-1
15.2.4.3.3 Work unit ALC_CMC.4-2
15.2.4.3.4 Work unit ALC_CMC.4-3
246 15.2.4.3.5 Work unit ALC_CMC.4-4
15.2.4.3.6 Work unit ALC_CMC.4-5
15.2.4.3.7 Work unit ALC_CMC.4-6
15.2.4.3.8 Work unit ALC_CMC.4-7
247 15.2.4.3.9 Work unit ALC_CMC.4-8
15.2.4.3.10 Work unit ALC_CMC.4-9
248 15.2.4.3.11 Work unit ALC_CMC.4-10
15.2.4.3.12 Work unit ALC_CMC.4-11
249 15.2.4.3.13 Work unit ALC_CMC.4-12
15.2.4.3.14 Work unit ALC_CMC.4-13
15.2.5 Evaluation of sub-activity (ALC_CMC.5)
15.2.5.1 Objectives
250 15.2.5.2 Input
15.2.5.3 Action ALC_CMC.5.1E
15.2.5.3.1 General
15.2.5.3.2 Work unit ALC_CMC.5-1
15.2.5.3.3 Work unit ALC_CMC.5-2
251 15.2.5.3.4 Work unit ALC_CMC.5-3
15.2.5.3.5 Work unit ALC_CMC.5-4
15.2.5.3.6 Work unit ALC_CMC.5-5
15.2.5.3.7 Work unit ALC_CMC.5-6
252 15.2.5.3.8 Work unit ALC_CMC.5-7
15.2.5.3.9 Work unit ALC_CMC.5-8
15.2.5.3.10 Work unit ALC_CMC.5-9
15.2.5.3.11 Work unit ALC_CMC.5-10
253 15.2.5.3.12 Work unit ALC_CMC.5-11
15.2.5.3.13 Work unit ALC_CMC.5-12
15.2.5.3.14 Work unit ALC_CMC.5-13
15.2.5.3.15 Work unit ALC_CMC.5-14
254 15.2.5.3.16 Work unit ALC_CMC.5-15
15.2.5.3.17 Work unit ALC_CMC.5-16
255 15.2.5.3.18 Work unit ALC_CMC.5-17
15.2.5.3.19 Work unit ALC_CMC.5-18
15.2.5.3.20 Work unit ALC_CMC.5-19
256 15.2.5.4 Action ALC_CMC.5.2E
15.2.5.4.1 Work unit ALC_CMC.5-20
15.3 CM scope (ALC_CMS)
15.3.1 Evaluation of sub-activity (ALC_CMS.1)
15.3.1.1 Objectives
15.3.1.2 Input
257 15.3.1.3 Action ALC_CMS.1.1E
15.3.1.3.1 General
15.3.1.3.2 Work unit ALC_CMS.1-1
15.3.1.3.3 Work unit ALC_CMS.1-2
15.3.2 Evaluation of sub-activity (ALC_CMS.2)
15.3.2.1 Objectives
15.3.2.2 Input
15.3.2.3 Action ALC_CMS.2.1E
15.3.2.3.1 General
15.3.2.3.2 Work unit ALC_CMS.2-1
258 15.3.2.3.3 Work unit ALC_CMS.2-2
15.3.2.3.4 Work unit ALC_CMS.2-3
15.3.3 Evaluation of sub-activity (ALC_CMS.3)
15.3.3.1 Objectives
15.3.3.2 Input
15.3.3.3 Action ALC_CMS.3.1E
15.3.3.3.1 General
15.3.3.3.2 Work unit ALC_CMS.3-1
259 15.3.3.3.3 Work unit ALC_CMS.3-2
15.3.3.3.4 Work unit ALC_CMS.3-3
15.3.4 Evaluation of sub-activity (ALC_CMS.4)
15.3.4.1 Objectives
15.3.4.2 Input
15.3.4.3 Action ALC_CMS.4.1E
15.3.4.3.1 General
15.3.4.3.2 Work unit ALC_CMS.4-1
260 15.3.4.3.3 Work unit ALC_CMS.4-2
15.3.4.3.4 Work unit ALC_CMS.4-3
15.3.5 Evaluation of sub-activity (ALC_CMS.5)
15.3.5.1 Objectives
15.3.5.2 Input
15.3.5.3 Action ALC_CMS.5.1E
15.3.5.3.1 General
15.3.5.3.2 Work unit ALC_CMS.5-1
261 15.3.5.3.3 Work unit ALC_CMS.5-2
15.3.5.3.4 Work unit ALC_CMS.5-3
15.4 Delivery (ALC_DEL)
15.4.1 Evaluation of sub-activity (ALC_DEL.1)
15.4.1.1 Objectives
15.4.1.2 Input
15.4.1.3 Action ALC_DEL.1.1E
15.4.1.3.1 General
262 15.4.1.3.2 Work unit ALC_DEL.1-1
15.4.1.4 Implied evaluator action
15.4.1.4.1 Work unit ALC_DEL.1-2
263 15.5 Development security (ALC_DVS)
15.5.1 Evaluation of sub-activity (ALC_DVS.1)
15.5.1.1 Objectives
15.5.1.2 Input
15.5.1.3 Action ALC_DVS.1.1E
15.5.1.3.1 General
15.5.1.3.2 Work unit ALC_DVS.1-1
264 15.5.1.3.3 Work unit ALC_DVS.1-2
265 15.5.1.4 Action ALC_DVS.1.2E
15.5.1.4.1 Work unit ALC_DVS.1-3
15.5.2 Evaluation of sub-activity (ALC_DVS.2)
15.5.2.1 Objectives
15.5.2.2 Input
15.5.2.3 Action ALC_DVS.2.1E
15.5.2.3.1 General
266 15.5.2.3.2 Work unit ALC_DVS.2-1
15.5.2.3.3 Work unit ALC_DVS.2-2
267 15.5.2.3.4 Work unit ALC_DVS.2-3
268 15.5.2.4 Action ALC_DVS.2.2E
15.5.2.4.1 Work unit ALC_DVS.2-4
15.6 Flaw remediation (ALC_FLR)
15.6.1 Evaluation of sub-activity (ALC_FLR.1)
15.6.1.1 Objectives
15.6.1.2 Input
15.6.1.3 Action ALC_FLR.1.1E
15.6.1.3.1 General
15.6.1.3.2 Work unit ALC_FLR.1-1
269 15.6.1.3.3 Work unit ALC_FLR.1-2
15.6.1.3.4 Work unit ALC_FLR.1-3
15.6.1.3.5 Work unit ALC_FLR.1-4
270 15.6.1.3.6 Work unit ALC_FLR.1-5
15.6.2 Evaluation of sub-activity (ALC_FLR.2)
15.6.2.1 Objectives
15.6.2.2 Input
15.6.2.3 Action ALC_FLR.2.1E
15.6.2.3.1 General
271 15.6.2.3.2 Work unit ALC_FLR.2-1
15.6.2.3.3 Work unit ALC_FLR.2-2
15.6.2.3.4 Work unit ALC_FLR.2-3
15.6.2.3.5 Work unit ALC_FLR.2-4
272 15.6.2.3.6 Work unit ALC_FLR.2-5
15.6.2.3.7 Work unit ALC_FLR.2-6
15.6.2.3.8 Work unit ALC_FLR.2-7
273 15.6.2.3.9 Work unit ALC_FLR.2-8
15.6.2.3.10 Work unit ALC_FLR.2-9
15.6.2.3.11 Work unit ALC_FLR.2-10
15.6.3 Evaluation of sub-activity (ALC_FLR.3)
15.6.3.1 Objectives
274 15.6.3.2 Input
15.6.3.3 Action ALC_FLR.3.1E
15.6.3.3.1 General
15.6.3.3.2 Work unit ALC_FLR.3-1
15.6.3.3.3 Work unit ALC_FLR.3-2
15.6.3.3.4 Work unit ALC_FLR.3-3
275 15.6.3.3.5 Work unit ALC_FLR.3-4
15.6.3.3.6 Work unit ALC_FLR.3-5
276 15.6.3.3.7 Work unit ALC_FLR.3-6
15.6.3.3.8 Work unit ALC_FLR.3-7
15.6.3.3.9 Work unit ALC_FLR.3-8
15.6.3.3.10 Work unit ALC_FLR.3-9
277 15.6.3.3.11 Work unit ALC_FLR.3-10
15.6.3.3.12 Work unit ALC_FLR.3-11
15.6.3.3.13 Work unit ALC_FLR.3-12
278 15.6.3.3.14 Work unit ALC_FLR.3-13
15.6.3.3.15 Work unit ALC_FLR.3-14
15.7 Life-cycle definition (ALC_LCD)
15.7.1 Evaluation of sub-activity (ALC_LCD.1)
15.7.1.1 Objectives
15.7.1.2 Input
279 15.7.1.3 Action ALC_LCD.1.1E
15.7.1.3.1 General
15.7.1.3.2 Work unit ALC_LCD.1-1
15.7.1.3.3 Work unit ALC_LCD.1-2
15.7.2 Evaluation of sub-activity (ALC_LCD.2)
15.7.2.1 Objectives
280 15.7.2.2 Input
15.7.2.3 Action ALC_LCD.2.1E
15.7.2.3.1 General
15.7.2.3.2 Work unit ALC_LCD.2-1
15.7.2.3.3 Work unit ALC_LCD.2-2
281 15.7.2.3.4 Work unit ALC_LCD.2-3
282 15.8 TOE Development Artifacts (ALC_TDA)
15.8.1 Evaluation of sub-activity (ALC_TDA.1)
15.8.1.1 Objectives
15.8.1.1.1 Input
15.8.1.2 Action ALC_TDA.1.1E
15.8.1.2.1 General
283 15.8.1.2.2 Work unit ALC_TDA.1-1
15.8.1.3 Action ALC_TDA.1.2E
15.8.1.3.1 General
15.8.1.3.2 Work unit ALC_TDA.1-2
15.8.1.4 Action ALC_TDA.1.3E
15.8.1.4.1 General
15.8.1.4.2 Work unit ALC_TDA.1-3
284 15.8.1.5 Action ALC_TDA.1.4E
15.8.1.5.1 General
15.8.1.5.2 Work unit ALC_TDA.1-4
15.8.1.6 Action ALC_TDA.1.5E
15.8.1.6.1 Work unit ALC_TDA.1-5
15.8.1.7 Action ALC_TDA.1.6E
15.8.1.7.1 Work unit ALC_TDA.1-6
285 15.8.2 Evaluation of sub-activity (ALC_TDA.2)
15.8.2.1 Objectives
15.8.2.2 Input
286 15.8.2.3 Action ALC_TDA.2.1E
15.8.2.3.1 General
15.8.2.3.2 Work unit ALC_TDA.2-1
15.8.2.4 Action ALC_TDA.2.2E
15.8.2.4.1 General
15.8.2.4.2 Work unit ALC_TDA.2-2
287 15.8.2.5 Action ALC_TDA.2.3E
15.8.2.5.1 General
15.8.2.5.2 Work unit ALC_TDA.2-3
15.8.2.6 Action ALC_TDA.2.4E
15.8.2.6.1 General
15.8.2.6.2 Work unit ALC_TDA.2-4
15.8.2.7 Action ALC_TDA.2.5E
15.8.2.7.1 General
15.8.2.7.2 Work unit ALC_TDA.2-5
288 15.8.2.8 Action ALC_TDA.2.6E
15.8.2.8.1 Work unit ALC_TDA.2-6
15.8.2.9 Action ALC_TDA.2.7E
15.8.2.9.1 Work unit ALC_TDA.2-7
15.8.3 Evaluation of sub-activity (ALC_TDA.3)
15.8.3.1 Objectives
15.8.3.2 Input
289 15.8.3.3 Action ALC_TDA.3.1E
15.8.3.3.1 General
290 15.8.3.3.2 Work unit ALC_TDA.3-1
15.8.3.3.3 Work unit ALC_TDA.3-2
15.8.3.3.4 Work unit ALC_TDA.3-3
15.8.3.4 Action ALC_TDA.3.4E
15.8.3.4.1 General
291 15.8.3.4.2 Work unit ALC_TDA.3-4
15.8.3.5 Action ALC_TDA.3.5E
15.8.3.5.1 General
15.8.3.5.2 Work unit ALC_TDA.3-5
15.8.3.6 Action ALC_TDA.3.6E
15.8.3.6.1 General
292 15.8.3.6.2 Work unit ALC_TDA.3-6
15.8.3.7 Action ALC_TDA.3.7E
15.8.3.7.1 Work unit ALC_TDA.3-7
15.8.3.8 Action ALC_TDA.3.8E
15.8.3.8.1 Work unit ALC_TDA.3-8
15.9 Tools and techniques (ALC_TAT)
15.9.1 Evaluation of sub-activity (ALC_TAT.1)
15.9.1.1 Objectives
15.9.1.2 Input
293 15.9.1.3 Application notes
15.9.1.4 Action ALC_TAT.1.1E
15.9.1.4.1 General
15.9.1.4.2 Work unit ALC_TAT.1-1
15.9.1.4.3 Work unit ALC_TAT.1-2
294 15.9.1.4.4 Work unit ALC_TAT.1-3
15.9.2 Evaluation of sub-activity (ALC_TAT.2)
15.9.2.1 Objectives
15.9.2.2 Input
295 15.9.2.3 Application notes
15.9.2.4 Action ALC_TAT.2.1E
15.9.2.4.1 General
15.9.2.4.2 Work unit ALC_TAT.2-1
15.9.2.4.3 Work unit ALC_TAT.2-2
296 15.9.2.4.4 Work unit ALC_TAT.2-3
15.9.2.5 Action ALC_TAT.2.2E
15.9.2.5.1 Work unit ALC_TAT.2-4
297 15.9.3 Evaluation of sub-activity (ALC_TAT.3)
15.9.3.1 Objectives
15.9.3.2 Input
15.9.3.3 Application notes
15.9.3.4 Action ALC_TAT.3.1E
15.9.3.4.1 General
298 15.9.3.4.2 Work unit ALC_TAT.3-1
15.9.3.4.3 Work unit ALC_TAT.3-2
299 15.9.3.4.4 Work unit ALC_TAT.3-3
15.9.3.5 Action ALC_TAT.3.2E
15.9.3.5.1 Work unit ALC_TAT.3-4
300 15.10 Integration of composition parts and consistency check of delivery procedures (ALC_COMP)
15.10.1 General
Table 3 — ALC_COMP
15.10.2 Evaluation of sub-activity (ALC_COMP.1)
15.10.2.1 Objectives
15.10.2.2 Application notes
301 15.10.2.3 Action ALC_COMP.1.1E
15.10.2.3.1 General
15.10.2.3.2 Work unit ALC_COMP.1-1
302 15.10.2.4 Action ALC_COMP.1.2E
15.10.2.4.1 General
15.10.2.4.2 Work unit ALC_COMP.1-2
303 16 Class ATE: Tests
16.1 General
16.2 Application notes
16.2.1 Understanding the expected behaviour of the TOE
304 16.2.2 Testing vs. alternate approaches to verify the expected behaviour of functionality
16.2.3 Verifying the adequacy of tests
305 16.3 Coverage (ATE_COV)
16.3.1 Evaluation of sub-activity (ATE_COV.1)
16.3.1.1 Objectives
16.3.1.2 Input
16.3.1.3 Application notes
16.3.1.4 Action ATE_COV.1.1E
16.3.1.4.1 General
16.3.1.4.2 Work unit ATE_COV.1-1
16.3.2 Evaluation of sub-activity (ATE_COV.2)
16.3.2.1 Objectives
306 16.3.2.2 Input
16.3.2.3 Action ATE_COV.2.1E
16.3.2.3.1 General
16.3.2.3.2 Work unit ATE_COV.2-1
16.3.2.3.3 Work unit ATE_COV.2-2
16.3.2.3.4 Work unit ATE_COV.2-3
16.3.2.3.5 Work unit ATE_COV.2-4
307 16.3.3 Evaluation of sub-activity (ATE_COV.3)
16.3.3.1 Objectives
16.3.3.2 Input
16.3.3.3 Action ATE_COV.3.1E
16.3.3.3.1 General
16.3.3.3.2 Work unit ATE_COV.3-1
16.3.3.3.3 Work unit ATE_COV.3-2
308 16.3.3.3.4 Work unit ATE_COV.3-3
16.3.3.3.5 Work unit ATE_COV.3-4
16.3.3.3.6 Work unit ATE_COV.3-5
309 16.4 Depth (ATE_DPT)
16.4.1 Evaluation of sub-activity (ATE_DPT.1)
16.4.1.1 Objectives
16.4.1.2 Input
16.4.1.3 Action ATE_DPT.1.1E
16.4.1.3.1 General
16.4.1.3.2 Work unit ATE_DPT.1-1
310 16.4.1.3.3 Work unit ATE_DPT.1-2
16.4.1.3.4 Work unit ATE_DPT.1-3
311 16.4.1.3.5 Work unit ATE_DPT.1-4
16.4.2 Evaluation of sub-activity (ATE_DPT.2)
16.4.2.1 Objectives
16.4.2.2 Input
16.4.2.3 Action ATE_DPT.2.1E
16.4.2.3.1 General
312 16.4.2.3.2 Work unit ATE_DPT.2-1
16.4.2.3.3 Work unit ATE_DPT.2-2
16.4.2.3.4 Work unit ATE_DPT.2-3
16.4.2.3.5 Work unit ATE_DPT.2-4
313 16.4.2.3.6 Work unit ATE_DPT.2-5
16.4.2.3.7 Work unit ATE_DPT.2-6
16.4.2.3.8 Work unit ATE_DPT.2-7
314 16.4.3 Evaluation of sub-activity (ATE_DPT.3)
16.4.3.1 Objectives
16.4.3.2 Input
16.4.3.3 Action ATE_DPT.3.1E
16.4.3.3.1 General
16.4.3.3.2 Work unit ATE_DPT.3-1
16.4.3.3.3 Work unit ATE_DPT.3-2
315 16.4.3.3.4 Work unit ATE_DPT.3-3
16.4.3.3.5 Work unit ATE_DPT.3-4
16.4.3.3.6 Work unit ATE_DPT.3-5
316 16.4.3.3.7 Work unit ATE_DPT.3-6
16.4.3.3.8 Work unit ATE_DPT.3-7
16.4.4 Evaluation of sub-activity (ATE_DPT.4)
16.5 Functional tests (ATE_FUN)
16.5.1 Evaluation of sub-activity (ATE_FUN.1)
16.5.1.1 Objectives
16.5.1.2 Input
317 16.5.1.3 Application notes
16.5.1.4 Action ATE_FUN.1.1E
16.5.1.4.1 General
16.5.1.4.2 Work unit ATE_FUN.1-1
16.5.1.4.3 Work unit ATE_FUN.1-2
16.5.1.4.4 Work unit ATE_FUN.1-3
318 16.5.1.4.5 Work unit ATE_FUN.1-4
16.5.1.4.6 Work unit ATE_FUN.1-5
16.5.1.4.7 Work unit ATE_FUN.1-6
319 16.5.1.4.8 Work unit ATE_FUN.1-7
16.5.2 Evaluation of sub-activity (ATE_FUN.2)
16.5.2.1 Objectives
16.5.2.2 Input
320 16.5.2.3 Application notes
16.5.2.4 Action ATE_FUN.2.1E
16.5.2.4.1 General
16.5.2.4.2 Work unit ATE_FUN.2-1
16.5.2.4.3 Work unit ATE_FUN.2-2
16.5.2.4.4 Work unit ATE_FUN.2-3
321 16.5.2.4.5 Work unit ATE_FUN.2-4
16.5.2.4.6 Work unit ATE_FUN.2-5
16.5.2.4.7 Work unit ATE_FUN.2-6
322 16.5.2.4.8 Work unit ATE_FUN.2-7
16.5.2.4.9 Work unit ATE_FUN.2-8
323 16.6 Independent testing (ATE_IND)
16.6.1 Evaluation of sub-activity (ATE_IND.1)
16.6.1.1 Objectives
16.6.1.2 Input
16.6.1.3 Action ATE_IND.1.1E
16.6.1.3.1 General
16.6.1.3.2 Work unit ATE_IND.1-1
324 16.6.1.3.3 Work unit ATE_IND.1-2
16.6.1.4 Action ATE_IND.1.2E
16.6.1.4.1 Work unit ATE_IND.1-3
325 16.6.1.4.2 Work unit ATE_IND.1-4
16.6.1.4.3 Work unit ATE_IND.1-5
16.6.1.4.4 Work unit ATE_IND.1-6
326 16.6.1.4.5 Work unit ATE_IND.1-7
16.6.1.4.6 Work unit ATE_IND.1-8
327 16.6.2 Evaluation of sub-activity (ATE_IND.2)
16.6.2.1 Objectives
16.6.2.2 Input
16.6.2.3 Action ATE_IND.2.1E
16.6.2.3.1 General
16.6.2.3.2 Work unit ATE_IND.2-1
328 16.6.2.3.3 Work unit ATE_IND.2-2
16.6.2.3.4 Work unit ATE_IND.2-3
16.6.2.4 Action ATE_IND.2.2E
16.6.2.4.1 Work unit ATE_IND.2-4
16.6.2.4.2 Work unit ATE_IND.2-5
329 16.6.2.5 Action ATE_IND.2.3E
16.6.2.5.1 Work unit ATE_IND.2-6
330 16.6.2.5.2 Work unit ATE_IND.2-7
16.6.2.5.3 Work unit ATE_IND.2-8
16.6.2.5.4 Work unit ATE_IND.2-9
331 16.6.2.5.5 Work unit ATE_IND.2-10
16.6.2.5.6 Work unit ATE_IND.2-11
332 16.6.3 Evaluation of sub-activity (ATE_IND.3)
16.7 Composite functional testing (ATE_COMP)
16.7.1 General
16.7.2 Evaluation of sub-activity (ATE_COMP.1)
16.7.2.1 Objectives
16.7.2.2 Application notes
333 16.7.2.3 Action ATE_COMP.1.1E
16.7.2.3.1 General
16.7.2.3.2 Work unit ATE_COMP.1-1
334 17 Class AVA: Vulnerability assessment
17.1 General
17.2 Vulnerability analysis (AVA_VAN)
17.2.1 Evaluation of sub-activity (AVA_VAN.1)
17.2.1.1 Objectives
17.2.1.2 Input
17.2.1.3 Application notes
17.2.1.4 Action AVA_VAN.1.1E
17.2.1.4.1 General
17.2.1.4.2 Work unit AVA_VAN.1-1
335 17.2.1.4.3 Work unit AVA_VAN.1-2
17.2.1.5 Action AVA_VAN.1.2E
17.2.1.5.1 Work unit AVA_VAN.1-3
336 17.2.1.5.2 Work unit AVA_VAN.1-4
17.2.1.6 Action AVA_VAN.1.3E
17.2.1.6.1 Work unit AVA_VAN.1-5
17.2.1.6.2 Work unit AVA_VAN.1-6
337 17.2.1.6.3 Work unit AVA_VAN.1-7
338 17.2.1.6.4 Work unit AVA_VAN.1-8
17.2.1.6.5 Work unit AVA_VAN.1-9
17.2.1.6.6 Work unit AVA_VAN.1-10
17.2.1.6.7 Work unit AVA_VAN.1-11
339 17.2.2 Evaluation of sub-activity (AVA_VAN.2)
17.2.2.1 Objectives
17.2.2.2 Input
17.2.2.3 Application notes
17.2.2.4 Action AVA_VAN.2.1E
17.2.2.4.1 General
340 17.2.2.4.2 Work unit AVA_VAN.2-1
17.2.2.4.3 Work unit AVA_VAN.2-2
17.2.2.5 Action AVA_VAN.2.2E
17.2.2.5.1 Work unit AVA_VAN.2-3
341 17.2.2.6 Action AVA_VAN.2.3E
17.2.2.6.1 Work unit AVA_VAN.2-4
342 17.2.2.6.2 Work unit AVA_VAN.2-5
17.2.2.7 Action AVA_VAN.2.4E
17.2.2.7.1 Work unit AVA_VAN.2-6
343 17.2.2.7.2 Work unit AVA_VAN.2-7
344 17.2.2.7.3 Work unit AVA_VAN.2-8
17.2.2.7.4 Work unit AVA_VAN.2-9
17.2.2.7.5 Work unit AVA_VAN.2-10
345 17.2.2.7.6 Work unit AVA_VAN.2-11
17.2.2.7.7 Work unit AVA_VAN.2-12
17.2.3 Evaluation of sub-activity (AVA_VAN.3)
17.2.3.1 Objectives
17.2.3.2 Input
346 17.2.3.3 Application notes
17.2.3.4 Action AVA_VAN.3.1E
17.2.3.4.1 General
17.2.3.4.2 Work unit AVA_VAN.3-1
347 17.2.3.4.3 Work unit AVA_VAN.3-2
17.2.3.5 Action AVA_VAN.3.2E
17.2.3.5.1 Work unit AVA_VAN.3-3
348 17.2.3.6 Action AVA_VAN.3.3E
17.2.3.6.1 Work unit AVA_VAN.3-4
350 17.2.3.6.2 Work unit AVA_VAN.3-5
17.2.3.7 Action AVA_VAN.3.4E
17.2.3.7.1 Work unit AVA_VAN.3-6
351 17.2.3.7.2 Work unit AVA_VAN.3-7
352 17.2.3.7.3 Work unit AVA_VAN.3-8
17.2.3.7.4 Work unit AVA_VAN.3-9
17.2.3.7.5 Work unit AVA_VAN.3-10
353 17.2.3.7.6 Work unit AVA_VAN.3-11
17.2.3.7.7 Work unit AVA_VAN.3-12
17.2.4 Evaluation of sub-activity (AVA_VAN.4)
17.2.4.1 Objectives
17.2.4.2 Input
354 17.2.4.3 Application notes
17.2.4.4 Action AVA_VAN.4.1E
17.2.4.4.1 General
17.2.4.4.2 Work unit AVA_VAN.4-1
355 17.2.4.4.3 Work unit AVA_VAN.4-2
17.2.4.5 Action AVA_VAN.4.2E
17.2.4.5.1 Work unit AVA_VAN.4-3
356 17.2.4.6 Action AVA_VAN.4.3E
17.2.4.6.1 Work unit AVA_VAN.4-4
357 17.2.4.6.2 Work unit AVA_VAN.4-5
358 17.2.4.7 Action AVA_VAN.4.4E
17.2.4.7.1 Work unit AVA_VAN.4-6
17.2.4.7.2 Work unit AVA_VAN.4-7
359 17.2.4.7.3 Work unit AVA_VAN.4-8
360 17.2.4.7.4 Work unit AVA_VAN.4-9
17.2.4.7.5 Work unit AVA_VAN.4-10
17.2.4.7.6 Work unit AVA_VAN.4-11
17.2.4.7.7 Work unit AVA_VAN.4-12
361 17.2.5 Evaluation of sub-activity (AVA_VAN.5)
17.2.5.1 Objectives
17.2.5.2 Input
17.2.5.3 Application notes
362 17.2.5.4 Action AVA_VAN.5.1E
17.2.5.4.1 General
17.2.5.4.2 Work unit AVA_VAN.5-1
17.2.5.4.3 Work unit AVA_VAN.5-2
17.2.5.5 Action AVA_VAN.5.2E
17.2.5.5.1 Work unit AVA_VAN.5-3
363 17.2.5.6 Action AVA_VAN.5.3E
17.2.5.6.1 Work unit AVA_VAN.5-4
365 17.2.5.7 Action AVA_VAN.5.4E
17.2.5.7.1 Work unit AVA_VAN.5-6
17.2.5.7.2 Work unit AVA_VAN.5-7
366 17.2.5.7.3 Work unit AVA_VAN.5-8
367 17.2.5.7.4 Work unit AVA_VAN.5-9
17.2.5.7.5 Work unit AVA_VAN.5-10
17.2.5.7.6 Work unit AVA_VAN.5-11
368 17.2.5.7.7 Work unit AVA_VAN.5-12
17.3 Composite vulnerability assessment (AVA_COMP)
17.3.1 General
17.3.2 Evaluation of sub-activity (AVA_COMP.1)
17.3.2.1 Objectives
17.3.2.2 Application notes
369 17.3.2.3 Action AVA_COMP.1.1E
17.3.2.3.1 General
17.3.2.3.2 Work unit AVA_COMP.1-1
370 17.3.2.3.3 Work unit AVA_COMP.1-2
18 Class ACO: Composition
18.1 General
18.2 Application notes
371 18.3 Composition rationale (ACO_COR)
18.3.1 Evaluation of sub-activity (ACO_COR.1)
18.3.1.1 Input
372 18.3.1.2 Action ACO_COR.1.1E
18.3.1.2.1 General
18.3.1.2.2 Work unit ACO_COR.1-1
18.3.1.2.3 Work unit ACO_COR.1-2
373 18.3.1.2.4 Work unit ACO_COR.1-3
378 18.4 Development evidence (ACO_DEV)
18.4.1 Evaluation of sub-activity (ACO_DEV.1)
18.4.1.1 Objectives
18.4.1.2 Input
18.4.1.3 Action ACO_DEV.1.1E
18.4.1.3.1 General
18.4.1.3.2 Work unit ACO_DEV.1-1
379 18.4.1.3.3 Work unit ACO_DEV.1-2
18.4.1.4 Action ACO_DEV.1.2E
18.4.1.4.1 Work unit ACO_DEV.1-3
18.4.2 Evaluation of sub-activity (ACO_DEV.2)
18.4.2.1 Objectives
18.4.2.2 Input
380 18.4.2.3 Action ACO_DEV.2.1E
18.4.2.3.1 General
18.4.2.3.2 Work unit ACO_DEV.2-1
18.4.2.3.3 Work unit ACO_DEV.2-2
18.4.2.3.4 Work unit ACO_DEV.2-3
381 18.4.2.3.5 Work unit ACO_DEV.2-4
18.4.2.4 Action ACO_DEV.2.2E
18.4.2.4.1 Work unit ACO_DEV.2-5
18.4.3 Evaluation of sub-activity (ACO_DEV.3)
18.4.3.1 Objectives
18.4.3.2 Input
18.4.3.3 Action ACO_DEV.3.1E
18.4.3.3.1 General
382 18.4.3.3.2 Work unit ACO_DEV.3-1
18.4.3.3.3 Work unit ACO_DEV.3-2
18.4.3.3.4 Work unit ACO_DEV.3-3
18.4.3.3.5 Work unit ACO_DEV.3-4
383 18.4.3.3.6 Work unit ACO_DEV.3-5
18.4.3.3.7 Work unit ACO_DEV.3-6
18.4.3.4 Action ACO_DEV.3.2E
18.4.3.4.1 Work unit ACO_DEV.3-7
384 18.5 Reliance of dependent component (ACO_REL)
18.5.1 Evaluation of sub-activity (ACO_REL.1)
18.5.1.1 Objectives
18.5.1.2 Input
18.5.1.3 Application notes
18.5.1.4 Action ACO_REL.1.1E
18.5.1.4.1 General
18.5.1.4.2 Work unit ACO_REL.1-1
18.5.1.4.3 Work unit ACO_REL.1-2
385 18.5.1.4.4 Work unit ACO_REL.1-3
18.5.1.4.5 Work unit ACO_REL.1-4
386 18.5.2 Evaluation of sub-activity (ACO_REL.2)
18.5.2.1 Objectives
18.5.2.2 Input
18.5.2.3 Application notes
18.5.2.4 Action ACO_REL.2.1E
18.5.2.4.1 General
18.5.2.4.2 Work unit ACO_REL.2-1
387 18.5.2.4.3 Work unit ACO_REL.2-2
18.5.2.4.4 Work unit ACO_REL.2-3
18.5.2.4.5 Work unit ACO_REL.2-4
388 18.5.2.4.6 Work unit ACO_REL.2-5
18.6 Composed TOE testing (ACO_CTT)
18.6.1 Evaluation of sub-activity (ACO_CTT.1)
18.6.1.1 Objectives
18.6.1.2 Input
18.6.1.3 Action ACO_CTT.1.1E
18.6.1.3.1 General
18.6.1.3.2 Work unit ACO_CTT.1-1
389 18.6.1.3.3 Work unit ACO_CTT.1-2
18.6.1.3.4 Work unit ACO_CTT.1-3
18.6.1.3.5 Work unit ACO_CTT.1-4
390 18.6.1.3.6 Work unit ACO_CTT.1-5
18.6.1.3.7 Work unit ACO_CTT.1-6
18.6.1.4 Action ACO_CTT.1.2E
18.6.1.4.1 Work unit ACO_CTT.1-7
18.6.1.5 Action ACO_CTT.1.3E
18.6.1.5.1 Work unit ACO_CTT.1-8
391 18.6.2 Evaluation of sub-activity (ACO_CTT.2)
18.6.2.1 Objectives
18.6.2.2 Input
18.6.2.3 Action ACO_CTT.2.1E
18.6.2.3.1 General
18.6.2.3.2 Work unit ACO_CTT.2-1
18.6.2.3.3 Work unit ACO_CTT.2-2
392 18.6.2.3.4 Work unit ACO_CTT.2-3
18.6.2.3.5 Work unit ACO_CTT.2-4
18.6.2.3.6 Work unit ACO_CTT.2-5
18.6.2.3.7 Work unit ACO_CTT.2-6
393 18.6.2.3.8 Work unit ACO_CTT.2-7
18.6.2.3.9 Work unit ACO_CTT.2-8
18.6.2.4 Action ACO_CTT.2.2E
18.6.2.4.1 Work unit ACO_CTT.2-9
18.6.2.5 Action ACO_CTT.2.3E
18.6.2.5.1 Work unit ACO_CTT.2-10
18.6.2.5.2 Work unit ACO_CTT.2-11
394 18.7 Composition vulnerability analysis (ACO_VUL)
18.7.1 Evaluation of sub-activity (ACO_VUL.1)
18.7.1.1 Objectives
18.7.1.2 Input
18.7.2 Application notes
18.7.2.1 Action ACO_VUL.1.1E
18.7.2.1.1 General
18.7.2.1.2 Work unit ACO_VUL.1-1
395 18.7.2.1.3 Work unit ACO_VUL.1-2
18.7.2.2 Action ACO_VUL.1.2E
18.7.2.2.1 Work unit ACO_VUL.1-3
18.7.2.2.2 Work unit ACO_VUL.1-4
396 18.7.2.3 Action ACO_VUL.1.3E
18.7.2.3.1 Work unit ACO_VUL.1-5
18.7.2.3.2 Work unit ACO_VUL.1-6
18.7.2.3.3 Work unit ACO_VUL.1-7
18.7.2.4 Action ACO_VUL.1.4E
18.7.2.4.1 Work unit ACO_VUL.1-8
397 18.7.3 Evaluation of sub-activity (ACO_VUL.2)
18.7.3.1 Objectives
18.7.3.2 Input
18.7.3.3 Application notes
18.7.3.4 Action ACO_VUL.2.1E
18.7.3.4.1 General
18.7.3.4.2 Work unit ACO_VUL.2-1
398 18.7.3.4.3 Work unit ACO_VUL.2-2
18.7.3.5 Action ACO_VUL.2.2E
18.7.3.5.1 Work unit ACO_VUL.2-3
18.7.3.5.2 Work unit ACO_VUL.2-4
399 18.7.3.6 Action ACO_VUL.2.3E
18.7.3.6.1 Work unit ACO_VUL.2-5
18.7.3.6.2 Work unit ACO_VUL.2-6
18.7.3.6.3 Work unit ACO_VUL.2-7
18.7.3.7 Action ACO_VUL.2.4E
18.7.3.7.1 Work unit ACO_VUL.2-8
400 18.7.3.8 Action ACO_VUL.2.5E
18.7.3.8.1 Work unit ACO_VUL.2-9
18.7.4 Evaluation of sub-activity (ACO_VUL.3)
18.7.4.1 Objectives
401 18.7.4.2 Input
18.7.4.3 Application notes
18.7.4.4 Action ACO_VUL.3.1E
18.7.4.4.1 General
18.7.4.4.2 Work unit ACO_VUL.3-1
18.7.4.4.3 Work unit ACO_VUL.3-2
18.7.4.5 Action ACO_VUL.3.2E
18.7.4.5.1 Work unit ACO_VUL.3-3
402 18.7.4.5.2 Work unit ACO_VUL.3-4
18.7.4.6 Action ACO_VUL.3.3E
18.7.4.6.1 Work unit ACO_VUL.3-5
18.7.4.6.2 Work unit ACO_VUL.3-6
403 18.7.4.6.3 Work unit ACO_VUL.3-7
18.7.4.7 Action ACO_VUL.3.4E
18.7.4.7.1 Work unit ACO_VUL.3-8
404 18.7.4.8 Action ACO_VUL.3.5E
18.7.4.8.1 Work unit ACO_VUL.3-9
405 Annex A (informative) General evaluation guidance
A.1 Objectives
A.2 Sampling
407 A.3 Dependencies
A.3.1 General
A.3.2 Dependencies between activities
A.3.3 Dependencies between sub-activities
A.3.4 Dependencies between actions
A.4 Site Visits
A.4.1 General
408 A.4.2 General approach
409 A.5 Orientation guide for the preparation of the checklist
A.5.1 Aspects of configuration management
A.5.2 Aspects of development security
410 A.5.3 Example of a checklist
411 Table A.1 — Example of a checklist at EAL 4 (extract)
413 A.6 Scheme responsibilities
415 Annex B (informative) Vulnerability assessment (AVA)
B.1 What is vulnerability analysis
B.2 Evaluator construction of a vulnerability analysis
416 B.3 Generic vulnerability guidance
B.3.1 Bypassing
418 B.3.2 Tampering
421 B.3.3 Direct attacks
B.3.4 Monitoring
422 B.3.5 Misuse
423 B.4 Identification of potential vulnerabilities
B.4.1 Encountered
424 B.4.2 Analysis
B.4.2.1 General
B.4.2.2 Unstructured analysis
B.4.2.3 Focused
425 B.4.2.4 Methodical
426 B.5 When attack potential is used
B.5.1 Developer
B.5.2 Evaluator
427 B.6 Calculating attack potential
B.6.1 Application of attack potential
B.6.1.1 General
B.6.1.2 Treatment of motivation
428 B.6.2 Characterising attack potential
B.6.2.1 General
B.6.2.2 Determining the attack potential
B.6.2.3 Factors to be considered
431 B.6.2.4 Calculation of attack potential
434 B.7 Example calculation for direct attack
436 Annex C (informative) Evaluation techniques and tools
C.1 Semiformal and formal methods
C.1.1 General
C.1.2 Description of styles
437 C.1.2.1 Informal style
438 C.1.2.2 Semiformal style
439 C.1.2.3 Formal style
BS ISO/IEC 18045:2022
$215.11