您的位置: 标准下载 » 国际标准 » BS 英国标准 »

BS ISO/IEC 15408-1-1999 信息技术.安全技术.IT安全性评价准则.介绍和一般模式

时间:2024-05-10 17:46:22 来源: 标准资料网 作者:标准资料网 阅读:8721
下载地址: 点击此处下载
【英文标准名称】:Informationtechnology-Securitytechniques-EvaluationcriteriaforITsecurity-Introductionandgeneralmodel
【原文标准名称】:信息技术.安全技术.IT安全性评价准则.介绍和一般模式
【标准号】:BSISO/IEC15408-1-1999
【标准状态】:作废
【国别】:英国
【发布日期】:2000-02-15
【实施或试行日期】:2000-02-15
【发布单位】:英国标准学会(GB-BSI)
【起草单位】:BSI
【标准类型】:()
【标准水平】:()
【中文主题词】:消费者;验收(鉴定);数据存储保护;信息交流;质量保证;资产;选择;数据处理;数据安全
【英文主题词】:definitions;informationexchange;datasecurity;definition;informationtechnology;dataprotection;datatransmission;models;confidenceintervals;dataprocessing;levelofconfidence;safety;informationinterchange
【摘要】:ThismultipartstandardISO/IEC15408definescriteria,whichforhistoricalandcontinuitypurposesarereferredtohereinastheCommonCriteria(CC),tobeusedasthebasisforevaluationofsecuritypropertiesofITproductsandsystems.Byestablishingsuchacommoncriteriabase,theresultsofanITsecurityevaluationwillbemeaningfultoawideraudience.TheCCwillpermitcomparabilitybetweentheresultsofindependentsecurityevaluations.ItdoessobyprovidingacommonsetofrequirementsforthesecurityfunctionsofITproductsandsystemsandforassurancemeasuresappliedtothemduringasecurityevaluation.Theevaluationprocessestablishesalevelofconfidencethatthesecurityfunctionsofsuchproductsandsystemsandtheassurancemeasuresappliedtothemmeettheserequirements.TheevaluationresultsmayhelpconsumerstodeterminewhethertheITproductorsystemissecureenoughfortheirintendedapplicationandwhetherthesecurityrisksimplicitinitsusearetolerable.TheCCisusefulasaguideforthedevelopmentofproductsorsystemswithITsecurityfunctionsandfortheprocurementofcommercialproductsandsystemswithsuchfunctions.Duringevaluation,suchanITproductorsystemisknownasaTargetofEvaluation(TOE).SuchTOEsinclude,forexample,operatingsystems,computernetworks,distributedsystems,andapplications.TheCCaddressesprotectionofinformationfromunauthoriseddisclosure,modification,orlossofuse.Thecategoriesofprotectionrelatingtothesethreetypesoffailureofsecurityarecommonlycalledconfidentiality,integrity,andavailability,respectively.TheCCmayalsobeapplicabletoaspectsofITsecurityoutsideofthesethree.TheCCconcentratesonthreatstothatinformationarisingfromhumanactivities,whethermaliciousorotherwise,butmaybeapplicabletosomenon-humanthreatsaswell.Inaddition,theCCmaybeappliedinotherareasofIT,butmakesnoclaimofcompetenceoutsidethestrictdomainofITsecurity.TheCCisapplicabletoITsecuritymeasuresimplementedinhardware,firmwareorsoftware.Whereparticularaspectsofevaluationareintendedonlytoapplytocertainmethodsofimplementation,thiswillbeindicatedwithintherelevantcriteriastatements.Certaintopics,becausetheyinvolvespecialisedtechniquesorbecausetheyaresomewhatperipheraltoITsecurity,areconsideredtobeoutsidethescopeoftheCC.Someoftheseareidentifiedbelow.a)TheCCdoesnotcontainsecurityevaluationcriteriapertainingtoadministrativesecuritymeasuresnotrelateddirectlytotheITsecuritymeasures.However,itisrecognisedthatasignificantpartofthesecurityofaTOEcanoftenbeachievedthroughadministrativemeasuressuchasorganisational,personnel,physical,andproceduralcontrols.AdministrativesecuritymeasuresintheoperatingenvironmentoftheTOEaretreatedassecureusageassumptionswherethesehaveanimpactontheabilityoftheITsecuritymeasurestocountertheidentifiedthreats.b)TheevaluationoftechnicalphysicalaspectsofITsecuritysuchaselectromagneticemanationcontrolisnotspecificallycovered,althoughmanyoftheconceptsaddressedwillbeapplicabletothatarea.Inparticular,theCCaddressessomeaspectsofphysicalprotectionoftheTOE.c)TheCCaddressesneithertheevaluationmethodologynortheadministrativeandlegalframeworkunderwhichthecriteriamaybeappliedbyevaluationauthorities.However,itisexpectedthattheCCwillbeusedforevaluationpurposesinthecontextofsuchaframeworkandsuchamethodology.d)TheproceduresforuseofevaluationresultsinproductorsystemaccreditationareoutsidethescopeoftheCC.ProductorsystemaccreditationistheadministrativeprocesswherebyauthorityisgrantedfortheoperationofanITproductorsysteminitsfulloperationalenvironment.EvaluationfocusesontheITsecurityparts
【中国标准分类号】:L70
【国际标准分类号】:35_040
【页数】:64P.;A4
【正文语种】:英语


基本信息
标准名称:美澳型核果褐腐病菌检疫鉴定方法
英文名称:Identification of Monilinia fructicola (Winter) Honey
中标分类: 农业、林业 >> 植物保护 >> 植物检疫、病虫害防治
ICS分类: 农业 >> 农业和林业
发布日期:2007-04-06
实施日期:2007-10-16
首发日期:
作废日期:
起草单位:国家认证认可监督管理委员会
出版日期:
页数:8
适用范围

本标准规定了植物检疫中美澳型核果褐腐病菌的检疫鉴定方法。本标准适用于针对美澳型核果褐腐病菌的核果类等蔷薇科果实和苗木的检疫。

前言

没有内容

目录

没有内容

引用标准

没有内容

所属分类: 农业 林业 植物保护 植物检疫 病虫害防治 农业 农业和林业
【英文标准名称】:TestMethodforUsingaPortableArticulatedStrutSlipTester(PAST)
【原文标准名称】:便携式铰链支杆滑动测试仪(PAST)使用试验方法
【标准号】:ANSI/ASTMF1678-1997
【标准状态】:现行
【国别】:美国
【发布日期】:1997-03
【实施或试行日期】:
【发布单位】:美国国家标准学会(US-ANSI)
【起草单位】:
【标准类型】:()
【标准水平】:()
【中文主题词】:鞋靴;试验;滑动防护
【英文主题词】:slippingsecurity;testing;footwear
【摘要】:Thistestmethodcoverstheoperationalproceduresforusingaportablearticulatedstrutsliptester(PAST)fordeterminingtheslipresistanceoffootwearsole,heel,orrelatedmaterials(testfeet)againstplanarwalkwaysurfacesorwalkwaysurrogates(testsurfaces)ineitherthelaboratoryorfieldunderdryconditions.Thistestmethoddoesnotaddressallmethodologicalissues(forexample,testsurfaceandtestfootmaterialselectionandpreparation,experimentaldesign,orreportpreparation).Thevaluesstatedininch-poundunitsaretoberegardedasthestandard.Thevaluesgiveninparenthesesareforinformationonly.Thisstandarddoesnotpurporttoaddressallofthesafetyconcerns,ifany,associatedwithitsuse.Itistheresponsibilityoftheuserofthisstandardtoestablishappropriatesafetyandhealthpracticesanddeterminetheapplicabilityofregulatorylimitationspriortouse.
【中国标准分类号】:P94
【国际标准分类号】:61_060
【页数】:
【正文语种】:英语