ISO/IEC 19790:2025
Information security, cybersecurity and privacy protection — Security requirements for cryptographic modules
Information security, cybersecurity and privacy protection — Security requirements for cryptographic modules
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 80
- Дата публикации:
- 26 февраля 2025 г.
- Издание:
- ISO/IEC IS 19790 edition 3 version 1
- ICS:
- 35.030
This document specifies the security requirements for a cryptographic module utilized within a security system protecting sensitive information in Information and Communication Technologies (ICT). It defines four security levels for cryptographic modules to provide for a wide spectrum of data sensitivity and a diversity of application environments. This document specifies up to four security levels for each of the 11 requirement areas with each security level increasing security over the preceding level.
Abstract
Overview
ISO/IEC 19790:2025 - Information security, cybersecurity and privacy protection - Security requirements for cryptographic modules - defines a comprehensive set of security requirements for cryptographic modules used to protect sensitive information in ICT systems. The third edition establishes a layered approach with four security levels across 11 requirement areas, enabling vendors, integrators and evaluators to match cryptographic-module assurance to data sensitivity and deployment environments.
Key topics and technical requirements
ISO/IEC 19790:2025 covers functional and assurance requirements that address the full lifecycle of a cryptographic module. Major topics include:
- Cryptographic module security levels: Four increasing levels of protection to support a wide spectrum of use cases and threat models.
- Cryptographic boundary and specification: Definition of module scope, supported cryptographic functions and operational behavior.
- Interfaces and protected paths: Rules for module interfaces, categories of interfaces, and requirements for plaintext trusted paths and protected internal paths.
- Roles, services and authentication: Role-based access, services exposed by the module, and authentication mechanisms for operators and administrators.
- Software/firmware security: Requirements for secure software/firmware design, update controls and protections that scale with security level.
- Operational environment: Requirements for modifiable and fixed environments, including OS constraints for higher assurance.
- Physical security and environmental failure protection: Embodiments and tests for physical tamper resistance and environmental failure handling.
- Non-invasive attack mitigation: Protections and test metrics against side-channel and other non-invasive attacks.
- Sensitive Security Parameter (SSP) management: Generation, entry, storage, zeroization and RNG requirements for keys and other SSPs.
- Self-tests and life‑cycle assurance: Pre-operational and conditional self-tests, configuration management, secure development and vendor testing.
- Mitigation of other attacks: Measures for residual risks and high-level attack vectors at advanced security levels.
- Normative annexes: Documentation requirements, approved functions, SSP generation methods, authentication mechanisms, test metrics and development/manufacturing guidance (Annexes A–G).
Applications and who uses this standard
ISO/IEC 19790:2025 is used by:
- Cryptographic module designers and manufacturers to design hardware and software modules to meet defined security levels.
- Security architects and system integrators selecting modules for systems that protect classified, regulated or sensitive data.
- Certification labs and evaluators performing assurance assessments against the standard.
- Procurement and compliance teams specifying module security requirements in contracts and regulatory submissions.
Typical applications include HSMs, secure elements, TPMs, smart cards, VPN concentrators, cloud KMS components and embedded IoT security modules.
Related standards
ISO/IEC 19790:2025 is part of the ISO/IEC JTC 1/SC 27 family addressing cryptographic techniques and information security. It is commonly implemented alongside complementary standards for information security management and cryptographic algorithms to produce an end-to-end security solution.
Keywords: ISO/IEC 19790:2025, cryptographic modules, security requirements, cryptographic boundary, sensitive security parameter, physical security, non-invasive attacks, self-tests, life-cycle assurance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19790:2025
Похожие стандарты
Другие стандарты ISO
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…
ISO 15638-15:2014
ДействующийIntelligent transport systems — Framework for cooperative telematics applications for regulated vehicles (TAR…
Overview - ISO 15638-15:2014 (Vehicle location monitoring, TARV) ISO 15638-15:2014 is part of the ISO 15638 suite for Intelligent Transport Systems (ITS) and defines the framework and data specificat…