ISO 18960:2025
Security controls and implementation for third party payment service providers — Guidance and requirements
Security controls and implementation for third party payment service providers — Guidance and requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 24
- Дата публикации:
- 21 августа 2025 г.
- Издание:
- ISO IS 18960 edition 1 version 1
- ICS:
- 35.240.40
This document gives requirements and guidance on security controls and implementation for third-party payment service providers (TPPSPs). This document deals with the overall security controls of TPPSPs from developing and testing to installing, operating and auditing the system. These security controls consist of: — security governance controls; — cross-functional controls; — function-specific controls.
Abstract
Overview
ISO 18960:2025 - "Security controls and implementation for third party payment service providers - Guidance and requirements" is an ISO standard that provides requirements and practical guidance on security controls for third‑party payment service providers (TPPSPs). Published in 2025, it addresses organization‑wide security across the lifecycle of payment services: development, testing, installation, operation and audit. The standard is focused on protecting customer data (including PII) and preserving payment service integrity in fintech and payment ecosystems.
Key topics and technical requirements
ISO 18960 structures controls into three main categories and details concrete control areas:
-
Security governance controls
- Service security policies (information security, PII protection, user permissions, complaint handling)
- Roles and responsibilities and TPPSP security organization
- Risk management (process, assessment and treatment)
- Documentation, logging, monitoring, review and continual improvement
-
Cross‑functional controls
- Asset management and data security
- Access management (administrators, terminals, privileged programs)
- Supplier security and cloud service use
- TPP service continuity and incident logging
-
Function‑specific controls
- Vulnerability and incident response management (procedures, training, documentation)
- Human security (security training, NDAs, segregation of duties, access changes)
- Physical security (secure areas, access control)
- System security: server, network and application security (malware prevention, patch management, DMZ, private IPs, secure communications, web/mobile app security, data sanitization)
The standard emphasizes logging, audits, secure development lifecycle practices, and specific operational safeguards for servers, networks and TPP applications.
Practical applications
ISO 18960 is intended to be used to:
- Develop or strengthen an information security program for TPPSPs and fintechs
- Define security policies, governance and role responsibilities
- Guide secure design and operation of payment applications (web & mobile)
- Specify supplier and cloud security requirements in vendor contracts
- Implement vulnerability management, incident response and business continuity
- Support internal and external audits, regulatory compliance assessments and risk treatment plans
Who should use this standard
- Third‑party payment service providers (TPPSPs) and fintech companies
- Banks and payment institutions using or onboarding TPPSPs
- Security architects, compliance teams, and operational IT staff
- Auditors, regulators and risk managers evaluating payment security controls
- Cloud and supplier risk teams integrating payment services
Related standards
- ISO 23195 (security objectives for TPPSP systems) - Annex A of ISO 18960 maps controls to ISO 23195 objectives
- ISO/IEC 27002 - complements ISO 18960 with general information security controls; ISO 18960 tailors controls for the payment ecosystem
Keywords: ISO 18960:2025, TPPSP security, third‑party payment service providers, payment security, PII protection, vulnerability management, access management, supplier security.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 18960:2025
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO 23195:2021
ДействующийSecurity objectives of information systems of third-party payment services.
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…