ISO/IEC 19896-2:2018
IT security techniques — Competence requirements for information security testers and evaluators — Part 2: Knowledge, skills and effectiveness requirements for ISO/IEC 19790 testers
IT security techniques — Competence requirements for information security testers and evaluators — Part 2: Knowledge, skills and effectiveness requirements for ISO/IEC 19790 testers
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 34
- Дата публикации:
- 24 августа 2018 г.
- Издание:
- ISO/IEC IS 19896 edition 1 version 1
- ICS:
- 35.030
This document provides the minimum requirements for the knowledge, skills and effectiveness requirements of individuals performing testing activities for a conformance scheme using ISO/IEC 19790 and ISO/IEC 24759.
Abstract
Overview
ISO/IEC 19896-2:2018 specifies competence requirements for individuals who test and evaluate cryptographic modules under conformance schemes based on ISO/IEC 19790 and ISO/IEC 24759. It defines minimum knowledge, skills, experience, education and effectiveness criteria to ensure consistent, comparable results across validation and certification projects involving cryptographic module security.
Key Topics
- Scope and structure: Organized around Knowledge, Skills, Experience, Education and Effectiveness to align personnel competence with conformance testing needs.
- Tertiary education / equivalent experience: Testers should have an associate, bachelor or higher degree in IT-related disciplines or demonstrate equivalent practical experience (minimum equivalent of 3 years study or experience).
- Technical specialities: Testers must have qualifications in at least one speciality; testing laboratories should cover all specialties across staff. Examples include:
- Cryptographic concepts and algorithms
- Software/firmware development (programming, compilers, debugging, unit/integration/regression testing)
- Operating systems (installation, configuration, hardening, virtual machines)
- Hardware development and manufacturing (single/multi-chip designs, packaging, manufacturing integrity)
- Physical security testing, side-channel analysis, algorithm testing
- Standards knowledge: Explicit requirement to know ISO/IEC 19790 (security requirements for cryptographic modules), ISO/IEC 24759 (test requirements), and related standards such as ISO/IEC 17025, ISO/IEC 17825, ISO/IEC 18367, and test tool standards (ISO/IEC 20085 series).
- Supporting materials: Annexes include an example testers’ log, ontology of technology types, specific cryptographic module knowledge, and validator competence guidance.
Applications
- Validation and certification programs: Use the standard to define minimum tester qualifications for cryptographic module conformance testing.
- Accreditation and laboratory management: Establish personnel criteria to comply with ISO/IEC 17025 and to demonstrate technical competence during audits.
- Hiring and training: HR and training teams can map job descriptions, professional development, and credential requirements to the standard’s knowledge and skills areas.
- Test project staffing: Ensure appropriate mix of specialists (software, hardware, cryptography, physical security) to meet ISO/IEC 24759 test requirements and ISO/IEC 19790 objectives.
- Credentialing bodies: Design certification schemes and recognition programs for information security testers and evaluators.
Related Standards
- ISO/IEC 19790 - Security requirements for cryptographic modules (primary subject)
- ISO/IEC 24759 - Test requirements for cryptographic modules
- ISO/IEC 17025 - Competence of testing and calibration laboratories
- ISO/IEC 17825, 18367, 20085, 20543 - Complementary test and analysis methods
ISO/IEC 19896-2 is essential for organizations involved in cryptographic module testing, accreditation bodies, validators, certification authorities and security testing professionals seeking standardized, auditable competence criteria. Keywords: ISO/IEC 19896-2, cryptographic module testing, competence requirements, ISO/IEC 19790, ISO/IEC 24759, information security testers.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19896-2:2018
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO/IEC 19790:2020
ДействующийInformation technology. Security techniques. Security requirements for cryptographic modules.
BS ISO/IEC 24759:2025
ДействующийInformation security, cybersecurity and privacy protection. Test requirements for cryptographic modules.
BS EN ISO/IEC 17025:2017
ДействующийGeneral requirements for the competence of testing and calibration laboratories.
BS ISO/IEC 17825:2024
ДействующийInformation technology. Security techniques. Testing methods for the mitigation of non-invasive attack classe…
BS ISO/IEC 18367:2016
ДействующийInformation technology. Security techniques. Cryptographic algorithms and security mechanisms conformance tes…
ISO/IEC 20085-2:2020
ДействующийIT Security techniques — Test tool requirements and test tool calibration methods for use in testing non-inva…
Overview ISO/IEC 20085-2:2020 - "IT Security techniques - Test tool requirements and test tool calibration methods ... Part 2: Test calibration methods and apparatus" specifies how to calibrate non‑i…