ISO 13491-1:2016
Financial services — Secure cryptographic devices (retail) — Part 1: Concepts, requirements and evaluation methods
Financial services — Secure cryptographic devices (retail) — Part 1: Concepts, requirements and evaluation methods
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 33
- Дата публикации:
- 17 марта 2016 г.
- Издание:
- ISO IS 13491 edition 3 version 1
- ICS:
- 35.240.40
ISO 13491-1:2016 specifies the security characteristics for secure cryptographic devices (SCDs) based on the cryptographic processes defined in ISO 9564, ISO 16609, and ISO 11568. ISO 13491-1:2016 has two primary purposes: - to state the security characteristics concerning both the operational characteristics of SCDs and the management of such devices throughout all stages of their life cycle; ? to provide guidance for methodologies to verify compliance with those requirements. This information is contained in Annex A. ISO 13491-2 specifies checklists to be used to evaluate secure cryptographic devices (SCDs) incorporating cryptographic processes as specified in ISO 9564-1, ISO 9564-2, ISO 16609, ISO 11568-1, ISO 11568-2, ISO 11568-3, ISO 11568-4, ISO 11568-5, and ISO 11568-6 in the financial services environment. Annex A provides an informative illustration of the concepts of security levels described in this part of ISO 13491 as being applicable to SCDs. ISO 13491-1:2016 does not address issues arising from the denial of service of an SCD. Specific requirements for the security characteristics and management of specific types of SCD functionality used in the retail financial services environment are contained in ISO 13491‑2.
Abstract
Overview - What ISO 13491-1:2016 covers
ISO 13491-1:2016 defines the security characteristics and evaluation methods for secure cryptographic devices (SCDs) used in the retail financial services environment. It addresses both the operational characteristics of SCDs and the management of devices across their life cycle, and provides guidance (Annex A) on methodologies to verify compliance. The standard is based on cryptographic processes referenced in ISO 9564, ISO 16609, and ISO 11568 and is complemented by ISO 13491-2, which supplies compliance checklists.
Key topics and technical requirements
ISO 13491-1 focuses on measurable security properties and management controls rather than implementation details. Major technical topics include:
- Attack scenarios - identification of threats such as penetration, monitoring, manipulation, modification and substitution.
- Physical security requirements - device construction and environmental protection to resist tampering.
- Tamper properties:
- Tamper-evident: indicators that reveal unauthorized access.
- Tamper-resistant: design measures that increase effort needed to attack.
- Tamper-responsive: mechanisms that detect tampering and protect or erase sensitive material.
- Logical security requirements - cryptographic and administrative controls, including:
- Dual control and separation of duties.
- Unique key per device and proper handling of cryptographic keys.
- Device software authentication and assurance of genuine devices.
- Protection of sensitive device states and support for multiple cryptographic relationships.
- Device management and life cycle - requirements and protection methods across phases such as manufacturing, commissioning (initial key loading), active/inactive operation, repair, decommissioning and destruction.
- Accountability, audit and control - traceability and processes to detect and respond to compromise.
- Evaluation methods - informative guidance in Annex A to help verify compliance (note: ISO 13491-2 provides formal checklists).
Important exclusion: ISO 13491-1 does not address denial-of-service (DoS) issues.
Practical applications and who uses this standard
ISO 13491-1 is used to design, qualify and manage SCDs in retail payment systems. Typical users include:
- Device manufacturers (PIN pads, secure modules, payment terminals)
- Payment processors, banks and card issuers
- Security architects and integrators implementing payment solutions
- Certifiers, auditors and conformity assessment bodies
- Regulators and risk managers assessing payment-device controls
Adoption helps reduce fraud, protect PINs, MACs, cryptographic keys and other sensitive data, and supports demonstrable compliance during procurement and certification.
Related standards
- ISO 13491-2 - Security compliance checklists for retail SCDs
- ISO 9564 - PIN management and security
- ISO 16609 - (cryptographic processes referenced)
- ISO 11568 series - Key management for devices in retail financial services
Keywords: ISO 13491-1, secure cryptographic devices, SCDs, retail financial services, tamper-evident, tamper-resistant, tamper-responsive, device life cycle, cryptographic key management, evaluation methods.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 13491-1:2016
Похожие стандарты
Стандарты, упомянутые в описании
ISO 9564-2:2014
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorith…
Overview ISO 9564-2:2014 defines the approved algorithms for the encipherment of Personal Identification Numbers (PINs) used in financial services. This part of the ISO 9564 series focuses exclusivel…