ISO 9564-1:2017
Financial services — Personal Identification Number (PIN) management and security — Part 1: Basic principles and requirements for PINs in card-based systems
Financial services — Personal Identification Number (PIN) management and security — Part 1: Basic principles and requirements for PINs in card-based systems
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 32
- Дата публикации:
- 2 ноября 2017 г.
- Издание:
- ISO IS 9564 edition 4 version 1
- ICS:
- 35.240.40
ISO 9564-1:2017 specifies the basic principles and techniques which provide the minimum security measures required for effective international PIN management. These measures are applicable to those institutions responsible for implementing techniques for the management and protection of PINs during their creation, issuance, usage and deactivation. ISO 9564-1:2017 is applicable to the management of cardholder PINs for use as a means of cardholder verification in retail banking systems in, notably, automated teller machine (ATM) systems, point-of-sale (POS) terminals, automated fuel dispensers, vending machines, banking kiosks and PIN selection/change systems. It is applicable to issuer and interchange environments. The provisions of ISO 9564-1:2017 are not intended to cover: a) PIN management and security in environments where no persistent cryptographic relationship exists between the transaction-origination device and the acquirer, e.g. use of a browser for online shopping (for these environments, see ISO 9564-4); b) protection of the PIN against loss or intentional misuse by the customer; c) privacy of non-PIN transaction data; d) protection of transaction messages against alteration or substitution; e) protection against replay of the PIN or transaction; f) specific key management techniques; g) offline PIN verification used in contactless devices; h) requirements specifically associated with PIN management as it relates to multi-application functionality in an ICC.
Abstract
Overview
ISO 9564-1:2017 - Financial services - Personal Identification Number (PIN) management and security - Part 1 defines the basic principles and minimum security requirements for effective PIN management in card-based systems. The standard covers the PIN life cycle (creation, issuance, activation, entry, transmission, verification, storage, deactivation and disposal) and applies to issuers and interchange environments that support cardholder verification in retail banking channels such as ATMs, POS terminals, fuel dispensers, vending machines, banking kiosks and PIN selection/change systems.
Key topics and technical requirements
- PIN lifecycle protections: Guidance for secure establishment, issuance, activation, change, replacement, deactivation and destruction of PINs to minimize fraud risk.
- PIN handling devices: Security requirements and physical protection for PIN entry devices (PEDs) and integrated circuit (IC) readers, including device characteristics and keypad considerations.
- PIN entry and transmission: Controls for secure PIN entry and for protecting the PIN during transmission to the issuer or to an ICC for offline verification.
- PIN encipherment and PIN blocks: Use of protected PIN block formats (compact and extended formats, including Formats 0–4) and constraints on PIN block translation and journalizing.
- PIN verification modes: Differences between online PIN verification (host-based) and offline PIN verification (card/ICC-based) and related protection measures.
- Operational controls: Recording media handling, oral and telephone PIN controls, storage, mailer handling and secure disposal of sensitive material.
- Scope exclusions: The standard explicitly does not cover browser-based environments without persistent cryptographic relationships (see ISO 9564-4), customer misuse, privacy of non-PIN data, message integrity or replay protection, specific key-management techniques, offline PIN in contactless devices or multi-application ICC specifics.
Practical applications - who uses ISO 9564-1:2017
- Card issuers and payment processors implementing PIN issuance and verification systems
- Acquirers, interchange operators and banks managing PIN flows across networks
- ATM and POS manufacturers, PED vendors and IC reader designers
- Security architects, compliance officers and auditors responsible for retail payment security and fraud mitigation
- Service providers operating PIN selection/change systems, mailer production and secure PIN delivery
Related standards
- ISO 9564-2 (approved encipherment algorithms for PIN protection)
- ISO 9564-4 (PIN security in environments without persistent cryptographic relationships)
- Other retail banking security standards: ISO 11568, ISO 13491 and ISO 16609
By following ISO 9564-1:2017, organizations can align PIN management and PIN security practices with internationally recognized requirements for card-based payment systems, reducing operational risk and fraud exposure.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 9564-1:2017
Похожие стандарты
Стандарты, упомянутые в описании
ISO 9564-4:2016
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 4: Requirements for…
Overview ISO 9564-4:2016 - "Financial services - PIN management and security - Part 4: Requirements for PIN handling in eCommerce for Payment Transactions" defines minimum security requirements and p…
ISO 9564-2:2014
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorith…
Overview ISO 9564-2:2014 defines the approved algorithms for the encipherment of Personal Identification Numbers (PINs) used in financial services. This part of the ISO 9564 series focuses exclusivel…
BS ISO 11568:2023
ДействующийFinancial services. Key management (retail).
ISO 13491-1:2016
ОтменёнFinancial services — Secure cryptographic devices (retail) — Part 1: Concepts, requirements and evaluation me…
Overview - What ISO 13491-1:2016 covers ISO 13491-1:2016 defines the security characteristics and evaluation methods for secure cryptographic devices (SCDs) used in the retail financial services envi…