logo

Standards Manage Your Business

We Manage Your Standards

CSA

CSA ISO/IEC TS 9569:25

Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Patch Management Extension for the ISO/IEC 15408 series and ISO/IEC 18045 (Adopted ISO/IEC TS 9569:2023, first edition, 2023-11)

Standard Details

CSA Preface Standards development within the Information Technology sector is harmonized with international standards development. Through the CSA Technical Committee on Information Technology (TCIT), Canadians serve as the SCC Mirror Committee (SMC) on ISO/IEC Joint Technical Committee 1 on Information Technology (ISO/IEC JTC1) for the Standards Council of Canada (SCC), the ISO member body for Canada and sponsor of the Canadian National Committee of the IEC. For brevity, this Standard will be referred to as "CSA ISO/IEC TS 9569" throughout. The International Standard was reviewed by the CSA Technical Committee on Cybersecurity under the jurisdiction of the CSA Strategic Steering Committee on Information and Communications Technology Systems and deemed acceptable for use in Canada. This Standard has been formally approved, without modification, by the Technical Committee and has been developed in compliance with Standards Council of Canada requirements for National Standards of Canada. It has been published as a National Standard of Canada by CSA Group. Scope This document specifies patch management (PAM) security assurance requirements and is intended to be used as an extension of the ISO/IEC 15408 series and ISO/IEC 18045. The security assurance requirements specified in this document do not include evaluation or test activities on the final target of evaluation (TOE), but focus on the initial TOE and on the life cycle processes used by manufacturers. Additionally, this document gives guidance to facilitate the evaluation of the TOE, including the patch and development processes which support the patch management. This document lists options for evaluation authorities (or mutual recognition agreements) on how to utilize the additional assurance and additional evidence in their processes to enable the developer to consistently re-certify their updated or patched TOEs to the benefit of the users. The implementation of these options using an evaluation scheme is out of the scope of this document.

General Information

Status : ACTIVE
Standard Type: Main
Document No: CSA ISO/IEC TS 9569:25
Document Year: 2025
Pages: 52
Adopted: Yes

Life Cycle

Currently Viewing

ACTIVE
CSA ISO/IEC TS 9569:25
Knowledge Corner

Expand Your Knowledge and Unlock Your Learning Potential - Your One-Stop Source for Information!

© Copyright 2025 BSB Edge Private Limited.

Enquire now +