Using the templates in Part 1 of the PDF, you write a . This document is the contract between you and the evaluator. It lists:
ISO/IEC 15408, often called the , is the global benchmark for evaluating the security of IT products. It provides a structured framework for vendors to implement security and for consumers to verify it. 🛡️ Core Functionality iso iec 15408 pdf
The PDF is your checklist. The "Evaluation Methodology" (a separate but related document) tells you exactly how to prove a product meets FAU_GEN.1 (Audit data generation). Using the templates in Part 1 of the PDF, you write a