ISO 23195:2021
Security objectives of information systems of third-party payment services
Security objectives of information systems of third-party payment services
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 40
- Дата публикации:
- 11 июня 2021 г.
- Издание:
- ISO IS 23195 edition 1 version 1
- ICS:
- 03.060
This document defines a common terminology to be used in the context of third-party payment (TPP). Next, it establishes two logical structural models in which the assets to be protected are clarified. Finally, it specifies security objectives based on the analysis of the logical structural models and the interaction of the assets affected by threats, organizational security policies and assumptions. These security objectives are set out in order to counter the threats resulting from the intermediary nature of TPPSPs offering payment services compared with simpler payment models where the payer and the payee directly interact with their respective account servicing payment service provider (ASPSP). This document assumes that TPP-centric payments rely on the use of TPPSP credentials and the corresponding certified processes for issuance, distribution and renewal purposes. However, security objectives for such processes are out of the scope of this document. NOTE This document is based on the methodology specified in the ISO/IEC 15408 series. Therefore, the security matters that do not belong to the TOE are dealt with as assumptions, such as the security required by an information system that provides TPP services and the security of communication channels between the entities participating in a TPP business.
Abstract
Overview
ISO 23195:2021 - Security objectives of information systems of third‑party payment services - defines a common terminology, two logical structural models, and a set of security objectives for information systems used by third‑party payment service providers (TPPSPs). The standard addresses the specific risks introduced by the intermediary role of TPPSPs (TPP), emphasizing protection of payment data integrity, confidentiality and non‑repudiation in open payment ecosystems. It is based on the ISO/IEC 15408 (Common Criteria) methodology and is independent of any specific payment instrument.
Key topics and requirements
- Terminology and scope: Clear definitions for TPP, TPPSP, ASPSP (account servicing payment service provider), PSU and related business terms to ensure consistent interpretation across stakeholders.
- Logical structural models: Two TPP‑centric models that clarify how assets flow and interact in an open ecosystem and where threats arise.
- Asset identification: Categorization of protected assets including user data, business configuration data, transaction input and transmitting data, and TPPSP technical security function (TSF) data.
- Threat analysis: Threat classes tied to the intermediary nature of TPPSPs - e.g., customer impersonation, data tampering, unauthorized disclosure, repudiation risks.
- Security objectives: Objectives to prevent unauthorized disclosure/change of business and transaction data; prevent counterfeiting and repudiation of inputs and transmissions; protect authentication data supplied by ASPSPs; generate auditable security logs.
- Assumptions and boundaries: The document treats some aspects (e.g., the security of communication channels and the TPPSP credential issuance lifecycle) as assumptions or out of scope while requiring implementers to address them in the operating environment.
Applications - who should use it
- TPPSPs and fintechs designing or operating third‑party payment platforms to define security requirements.
- Security architects and developers implementing transaction flows, authentication and logging.
- Banks / ASPSPs that integrate with TPPSPs and assess intermediary risks.
- Auditors, assessors and regulators evaluating compliance and risk mitigation measures for TPP services.
- Vendors and integrators producing middleware, gateways or APIs for TPP ecosystems.
Practical uses include threat modelling, specification of security controls for integrity, confidentiality and non‑repudiation, procurement requirements, conformity assessments and building auditable transaction trails.
Related standards
- ISO/IEC 15408 (Common Criteria) - methodology basis for security objectives and evaluation.
- ISO references cited in the standard include ISO 12812‑1 and ISO/TR 21941 for related payment terminology and concepts.
Keywords: ISO 23195:2021, third‑party payment, TPP, TPPSP, ASPSP, payment security, security objectives, information systems, payment data integrity, non‑repudiation, ISO/IEC 15408.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 23195:2021
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC TR 20004:2012
ОтменёнInformation technology — Security techniques — Refining software vulnerability analysis under ISO/IEC 15408 a…
BS ISO 12812-1:2017
ДействующийCore banking. Mobile financial services. General framework.
ISO/TR 21941:2017
ДействующийFinancial services — Third-party payment service providers
Overview ISO/TR 21941:2017 is a Technical Report from ISO that documents research into the interface between third‑party payment service providers (TPPs) and account servicing payment service provide…