ISO/IEC 19790:2012
Information technology — Security techniques — Security requirements for cryptographic modules
Information technology — Security techniques — Security requirements for cryptographic modules
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 72
- Дата публикации:
- 9 августа 2012 г.
- Издание:
- ISO/IEC IS 19790 edition 2 version 1
- ICS:
- 35.030
ISO/IEC 19790:2012 the security requirements for a cryptographic module utilised within a security system protecting sensitive information in computer and telecommunication systems. This International Standard defines four security levels for cryptographic modules to provide for a wide spectrum of data sensitivity (e.g. low value administrative data, million dollar funds transfers, life protecting data, personal identity information, and sensitive information used by government) and a diversity of application environments (e.g. a guarded facility, an office, removable media, and a completely unprotected location). This International Standard specifies four security levels for each of 11 requirement areas with each security level increasing security over the preceding level. ISO/IEC 19790:2012 specifies security requirements specifically intended to maintain the security provided by a cryptographic module and compliance with this International Standard is not sufficient to ensure that a particular module is secure or that the security provided by the module is sufficient and acceptable to the owner of the information that is being protected.
Abstract
Overview
ISO/IEC 19790:2012 - "Information technology - Security techniques - Security requirements for cryptographic modules" specifies security requirements for cryptographic modules used to protect sensitive information in computer and telecommunication systems. The standard defines four security levels across a spectrum of data sensitivity and deployment environments and organizes requirements into 11 requirement areas. It is focused on maintaining the security provided by a cryptographic module; compliance does not alone guarantee a module is secure or that it meets a particular owner’s protection needs.
Key topics and technical requirements
ISO/IEC 19790:2012 covers practical, testable security controls for cryptographic modules. Major technical topics include:
- Cryptographic module specification: module types, cryptographic boundary, and modes of operation
- Interfaces: definitions of logical and physical interfaces and requirements for trusted channels
- Roles, services and authentication: role definitions, services offered, and authentication mechanisms
- Software/firmware security: integrity, update controls and authorized code requirements
- Operational environment: requirements for modifiable vs non‑modifiable environments
- Physical security: embodiments, tamper-resistance, and environmental failure protection/testing
- Non‑invasive security: side-channel attack mitigation and related test metrics
- Sensitive security parameter (SSP) management: generation, establishment, storage, entry/output, zeroisation, and random bit generators
- Self‑tests: pre‑operational and conditional self‑tests to verify correct operation
- Life‑cycle assurance: configuration management, secure development, testing, delivery, and end‑of‑life handling
- Mitigation of other attacks: additional protections for unforeseen threats
The standard also includes normative annexes for documentation, an approved security policy structure, approved security functions, approved methods for SSP generation, approved authentication mechanisms, and test metrics for non‑invasive attack mitigation.
Practical applications and users
ISO/IEC 19790 is applied by organizations that design, build, evaluate, procure, or operate cryptographic modules:
- Hardware Security Module (HSM) and smart card manufacturers
- Cryptographic module vendors and firmware developers
- Security architects and system integrators embedding cryptography in products
- Evaluators, auditors and certification bodies assessing module compliance
- Regulated sectors (finance, government, telecom, healthcare) requiring validated cryptographic protection
Benefits include clear, repeatable security requirements for module design, testable controls for certification, and guidance for selecting modules appropriate to data sensitivity and deployment environments.
Related standards
ISO/IEC 19790 aligns with other national and international cryptographic module and IT security standards and is commonly used alongside complementary evaluation and certification frameworks in industry and government procurement.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19790:2012
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO/IEC 19790:2020
ДействующийInformation technology. Security techniques. Security requirements for cryptographic modules.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…