Guidance for developing security and privacy functional requirements based on ISO/IEC 15408

Abstract

This document provides guidance for:
— selecting and specifying security functional requirements (SFRs) from ISO/IEC 15408-2 to protect Personally Identifiable Information (PII);
— the procedure to define both privacy and security functional requirements in a coordinated manner; and
— developing privacy functional requirements as extended components based on the privacy principles defined in ISO/IEC 29100 through the paradigm described in ISO/IEC 15408-2.

General Information

Publication date: 01 October 2018

ICT rolling plan topic: Cybersecurity

SDO: IEC