ISO 19092:2023
Financial services — Biometrics — Security framework
Financial services — Biometrics — Security framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 65
- Дата публикации:
- 2 марта 2023 г.
- Издание:
- ISO IS 19092 edition 2 version 1
- ICS:
- 03.060
This document specifies the security framework for using biometrics for authentication of customers in financial services, focusing exclusively on retail payments. It introduces the most common types of biometric technologies and addresses issues concerning their application. This document also describes representative architectures for the implementation of biometric authentication and associated minimum control objectives. The following are within the scope of this document: — use of biometrics for the purpose of: — verification of a claimed identity; — identification of an individual; — biometric authentication threats, vulnerabilities and controls; — validation of credentials presented at enrolment to support authentication; — management of biometric information across its life cycle, comprising enrolment, transmission and storage, verification, identification and termination processes; — security requirements for hardware used in conjunction with biometric capture and biometric data processing; — biometric authentication architectures and associated security requirements. The following are not within the scope of this document: — detailed specifications for data collection, feature extraction and comparison of biometric data and the biometric decision-making process; — use of biometric technology for non-financial transaction applications, such as physical or logical system access control.
Abstract
Overview
ISO 19092:2023 - Financial services - Biometrics - Security framework defines a security framework for using biometrics to authenticate customers in financial services, with a specific focus on retail payments. The standard introduces common biometric technologies, describes representative implementation architectures, and sets out minimum control objectives for secure biometric authentication throughout the biometric lifecycle (enrolment, transmission, storage, verification/identification, termination).
Keywords: ISO 19092:2023, biometrics, financial services, security framework, retail payments, biometric authentication
Key topics and technical requirements
ISO 19092:2023 covers technical and security topics relevant to financial biometric systems, including:
- Biometric modalities - overview of common modalities such as fingerprints, face, voice, iris, signature, vein, palm print and keystroke patterns and their practical properties.
- Biometric lifecycle management - security controls across enrolment, transmission, storage, verification, identification, re-enrolment, refinement, suspension/reactivation, termination and archiving.
- Architectures - conceptual business and technical architectures, registration architectures and representative biometric authentication architectures (including PBP devices - Points of Biometric Presentation).
- Threats, vulnerabilities and controls - presentation attack vulnerabilities (including synthetic attacks), comparison/decision/storage subsystem risks, calibration and fault injection issues, and required mitigations.
- Security requirements - physical and logical security, identity registration controls, data storage and handling (including reference splitting), comparison/decision security, and security compliance verification.
- Usability and performance - recognition performance, performance evaluation, interoperability and presentation attack detection considerations.
Keywords: biometric modalities, biometric lifecycle, presentation attack, PBP devices, recognition performance, data storage
Practical applications and users
ISO 19092:2023 is intended for organizations implementing or governing biometric authentication for retail financial transactions, including:
- Banks, payment service providers and fintechs deploying biometric login or payment authentication
- Vendors and integrators of biometric capture devices and authentication platforms (PBP device manufacturers)
- Security architects, risk and compliance teams defining controls and policies for biometric systems
- Auditors and regulators assessing biometric security in retail payment ecosystems
Adopting ISO 19092 helps improve security posture, reduce fraud risks from biometric attacks, and align implementations with recognized minimum control objectives.
Related standards
ISO 19092 complements broader standards in identity management, payments and information security. For comprehensive compliance, implementers should also consider applicable data protection and payment-industry security requirements alongside ISO 19092:2023.
Keywords: biometric security standard, retail payment authentication, ISO biometrics, financial biometrics security
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 19092:2023
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO 19092:2023
ДействующийFinancial services. Biometrics. Security framework.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…