ISO 13491-1:2024
Financial services — Secure cryptographic devices (retail) — Part 1: Concepts and requirements
Financial services — Secure cryptographic devices (retail) — Part 1: Concepts and requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 27
- Дата публикации:
- 17 июля 2024 г.
- Издание:
- ISO IS 13491 edition 4 version 1
- ICS:
- 35.240.40
This document specifies the security characteristics for secure cryptographic devices (SCDs) based on the cryptographic processes defined in the ISO 9564 series, ISO 16609 and ISO 11568. This document states the security characteristics concerning both the operational characteristics of SCDs and the management of such devices throughout all stages of their life cycle. This document does not address issues arising from the denial of service of an SCD. This document does not address software services that use multi-party computation (MPC) to achieve some security objectives and, relying on these, offer cryptographic services. NOTE These are sometimes called “soft” or software hardware security modules (HSMs) in common language, which is misleading and does not correspond to the definition of HSM in this document.
Abstract
Overview
ISO 13491-1:2024 - Financial services - Secure cryptographic devices (retail) - Part 1: Concepts and requirements defines security characteristics and lifecycle management for secure cryptographic devices (SCDs) used in retail financial services. This fourth edition (revising ISO 13491-1:2016) updates device class definitions and life‑cycle guidance. It is intended for devices that implement cryptographic processes referenced in ISO 9564, ISO 16609 and ISO 11568 and covers both operational characteristics and management throughout all life‑cycle stages. The standard explicitly excludes denial‑of‑service issues and software multi‑party computation (MPC) implementations sometimes described as “soft HSMs.”
Key topics and requirements
- Device concepts and types
- Definitions for SCDs, hardware security modules (HSMs), key loading devices and hardware management devices.
- Attack scenarios
- Threat modelling for penetration, monitoring, manipulation, modification and substitution attacks.
- Defence measures
- Requirements for device characteristics, management practices and environmental controls to mitigate attacks.
- Physical security
- Tamper‑evident, tamper‑resistant and tamper‑responsive behaviour specifications (detection, resistance and response).
- Logical security
- Dual control, unique key per device, secure device software authentication, handling of sensitive device states, and management of multiple cryptographic relationships.
- Life‑cycle management
- Protection requirements and methods across manufacturing, commissioning (initial key loading), active/inactive operation, repair, decommissioning and destruction phases.
- Accountability and audit
- Principles for device management, auditability and control to ensure traceability and compliance.
Practical applications and who uses this standard
ISO 13491-1:2024 is directly relevant to organizations involved in retail payment security and cryptographic device deployment:
- Banks and payment processors securing PINs, transaction keys and payment credentials.
- HSM and SCD manufacturers designing devices to meet retail financial security expectations.
- Key management and key loading service providers implementing secure commissioning and lifecycle controls.
- Security architects, auditors and compliance teams evaluating device security, tamper protections and lifecycle procedures.
- System integrators and card personalization centers handling device commissioning, repair and decommissioning.
Adopting ISO 13491-1 helps ensure robust, auditable cryptographic device security across the retail payment ecosystem and supports interoperability with related ISO payment standards.
Related standards
- ISO 9564 series (PIN management)
- ISO 16609 (PIN interchange and related processes)
- ISO 11568 (Key management for financial services)
- Other parts of the ISO 13491 series (device-specific parts and profiles)
For implementation details, procurement or certification, consult the full ISO 13491-1:2024 document through your national standards body or ISO.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 13491-1:2024
Похожие стандарты
Стандарты, упомянутые в описании
ISO 13491-1:2016
ОтменёнFinancial services — Secure cryptographic devices (retail) — Part 1: Concepts, requirements and evaluation me…
Overview - What ISO 13491-1:2016 covers ISO 13491-1:2016 defines the security characteristics and evaluation methods for secure cryptographic devices (SCDs) used in the retail financial services envi…
ISO 9564-2:2014
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorith…
Overview ISO 9564-2:2014 defines the approved algorithms for the encipherment of Personal Identification Numbers (PINs) used in financial services. This part of the ISO 9564 series focuses exclusivel…