Security target

from Wikipedia, the free encyclopedia

In the context of IT security guidelines (e.g. Common Criteria or ITSEC ), security requirements are defined as a product-specific set of security requirements for an IT system to be examined ( TOEs ).

The concept of the security target is used to describe the security situation of an evaluation object (TOE) on the basis of security objectives, possible threats and assumptions about the IT operating environment. Security targets can refer to one (or more) generic protection profiles and specify them.