ISO 13491-2:2023
Financial services — Secure cryptographic devices (retail) — Part 2: Security compliance checklists for devices used in financial transactions
Financial services — Secure cryptographic devices (retail) — Part 2: Security compliance checklists for devices used in financial transactions
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 39
- Дата публикации:
- 11 января 2023 г.
- Издание:
- ISO IS 13491 edition 5 version 1
- ICS:
- 35.240.40
This document specifies checklists to be used to evaluate secure cryptographic devices (SCDs) incorporating cryptographic processes as specified in ISO 9564‑1, ISO 9564‑2, ISO 16609, and ISO 11568 in the financial services environment. Integrated circuit (IC) payment cards are subject to the requirements identified in this document up until the time of issue, after which they are to be regarded as a “personal” device and outside of the scope of this document.
Abstract
Overview
ISO 13491-2:2023 - Financial services - Secure cryptographic devices (retail) - Part 2 - provides security compliance checklists for evaluating secure cryptographic devices (SCDs) used in retail financial transactions. The standard defines auditable statements and minimum evaluation items that assess physical security, logical protection, device management and lifecycle controls for devices that implement cryptographic processes referenced in ISO 9564‑1, ISO 9564‑2, ISO 16609 and ISO 11568. Integrated circuit (IC) payment cards are covered only up to the point of issuance.
Key Topics
- Security compliance checklists: structured, auditable statements to be answered True/False/N/A by evaluators and auditors.
- Physical security characteristics: tamper-evident and tamper‑resistant design considerations, protection against probing, mechanical, thermal, chemical and radiological attacks.
- Logical security and device management: secure key storage, transfer/loading, PIN handling, access control, dual control procedures and secure operator interfaces.
- Functional checklists (Annexes A–G): common device characteristics (Annex A) plus device-specific checklists for:
- PIN entry functionality (Annex B)
- PIN management (Annex C)
- Message authentication (Annex D)
- Key generation (Annex E)
- Key transfer and loading (Annex F)
- Digital signature functionality (Annex G)
- Environment categorization (Annex H): guidance on evaluating devices relative to the deployment environment (public vs. controlled locations).
- Random number generation: conformance to ISO/IEC 18031 where device RNGs are used.
- Evaluation process: roles of auditors, evaluation agencies and sponsors; how checklists are applied and interpreted.
Applications
ISO 13491-2 is practical for:
- Financial institutions and payment processors assessing SCDs (PIN entry devices, secure modules, key loaders).
- Device manufacturers preparing products for retail payment use and audits.
- Auditors and accredited evaluation agencies performing compliance checks and producing audit records.
- Payment scheme operators and approval authorities who set acceptance criteria and approve devices for deployment.
This standard helps reduce the risk of key disclosure, PIN compromise and message tampering by ensuring devices meet minimum security characteristics and are managed securely throughout their lifecycle.
Related Standards
- ISO 13491-1 (concepts, requirements and evaluation methods)
- ISO 9564-1 / ISO 9564-2 (PIN management and security)
- ISO 16609 (message authentication using symmetric techniques)
- ISO 11568 (key management - retail)
- ISO/IEC 18031 (random bit generation)
Keywords: ISO 13491-2, secure cryptographic devices, SCD, security compliance checklists, retail financial services, PIN entry devices, tamper-evident, tamper-resistant, device evaluation, key management.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 13491-2:2023
Похожие стандарты
Стандарты, упомянутые в описании
ISO 9564-1:2017
ДействующийFinancial services — Personal Identification Number (PIN) management and security — Part 1: Basic principles…
Overview ISO 9564-1:2017 - Financial services - Personal Identification Number (PIN) management and security - Part 1 defines the basic principles and minimum security requirements for effective PIN…
ISO 9564-2:2014
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorith…
Overview ISO 9564-2:2014 defines the approved algorithms for the encipherment of Personal Identification Numbers (PINs) used in financial services. This part of the ISO 9564 series focuses exclusivel…
BS ISO 16609:2022
ДействующийFinancial services. Requirements for message authentication using symmetric techniques.
BS ISO 11568:2023
ДействующийFinancial services. Key management (retail).
ISO/IEC 18031:2025
ДействующийInformation technology — Security techniques — Random bit generation
Overview ISO/IEC 18031:2025 - "Information technology - Security techniques - Random bit generation" defines a conceptual model and security requirements for random bit generators (RBGs) used for cry…
BS ISO 13491-2:2023
ДействующийFinancial services. Secure cryptographic devices (retail). Security compliance checklists for devices used in…
ISO 13491-1:2016
ОтменёнFinancial services — Secure cryptographic devices (retail) — Part 1: Concepts, requirements and evaluation me…
Overview - What ISO 13491-1:2016 covers ISO 13491-1:2016 defines the security characteristics and evaluation methods for secure cryptographic devices (SCDs) used in the retail financial services envi…