ISO/IEC 24759:2017
Information technology — Security techniques — Test requirements for cryptographic modules
Information technology — Security techniques — Test requirements for cryptographic modules
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 135
- Дата публикации:
- 4 апреля 2017 г.
- Издание:
- ISO/IEC IS 24759 edition 3 version 1
- ICS:
- 35.030
ISO/IEC 24759:2017 specifies the methods to be used by testing laboratories to test whether the cryptographic module conforms to the requirements specified in ISO/IEC 19790:2012. The methods are developed to provide a high degree of objectivity during the testing process and to ensure consistency across the testing laboratories. This document also specifies the requirements for information that vendors provide to testing laboratories as supporting evidence to demonstrate their cryptographic modules' conformity to the requirements specified in ISO/IEC 19790:2012. Vendors can use this document as guidance in trying to verify whether their cryptographic modules satisfy the requirements specified in ISO/IEC 19790:2012 before they apply to the testing laboratory for testing.
Abstract
Overview
ISO/IEC 24759:2017 - Information technology - Security techniques - Test requirements for cryptographic modules - defines the standardized test methods and evidence requirements used by testing laboratories to determine whether a cryptographic module conforms to the security requirements in ISO/IEC 19790:2012. The standard is intended to provide objective, repeatable test procedures and to ensure consistent results across laboratories. It also specifies what vendors must supply as supporting evidence and can be used by vendors as pre-test guidance.
Key topics and technical requirements
ISO/IEC 24759:2017 organizes testing around the security areas defined in ISO/IEC 19790 and maps those requirements into explicit testable assertions and vendor/tester actions. Major topics covered include:
- Assertions and test structure
- Security requirements are broken into assertions (AS...). Each assertion lists applicable security levels and is followed by vendor evidence (VE...) and tester (TE...) requirements.
- Cryptographic module specification
- Includes tests for module type, cryptographic boundary, and operational modes.
- Interfaces, roles, services and authentication
- Test methods for module interfaces, trusted channels, role-based services and authentication mechanisms.
- Software/firmware and operational environment
- Examination and testing of firmware integrity and operational environment constraints (modifiable vs non‑modifiable).
- Physical and non-invasive security
- Tests for physical embodiments, tamper resistance and non-invasive attack mitigation.
- Sensitive security parameter (SSP) management
- Requirements and tests for random bit generators, key generation, storage, entry/output, and zeroisation.
- Self-tests and life‑cycle assurance
- Pre-operational and conditional self-tests, development and configuration management, vendor testing, delivery, operation and end-of-life considerations.
- Documentation and supporting evidence
- Specific vendor documentation required to demonstrate conformity (design, test vectors, procedures).
- Mapping to security levels
- Assertions specify which security levels (1–4) they apply to, guiding scope and rigor of testing.
Practical applications and users
ISO/IEC 24759:2017 is used by:
- Testing laboratories and certification bodies to execute objective cryptographic module testing and produce consistent conformity assessments.
- Vendors and product developers as a pre-test checklist and to prepare the required vendor evidence and documentation prior to formal evaluation.
- Procurement officers and security architects to understand what certified cryptographic modules have been tested against and which security levels apply.
- Regulators and auditors seeking standardized test evidence for cryptographic module compliance.
Related standards
- ISO/IEC 19790:2012 - Security requirements for cryptographic modules (normative reference and the primary requirements tested by ISO/IEC 24759).
- Prepared by ISO/IEC JTC 1/SC 27 (Information security techniques).
Keywords: ISO/IEC 24759:2017, cryptographic modules, cryptographic module testing, security requirements, ISO/IEC 19790, testing laboratories, vendor evidence, conformity assessment.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24759:2017
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO/IEC 19790:2020
ДействующийInformation technology. Security techniques. Security requirements for cryptographic modules.
BS ISO/IEC 24759:2025
ДействующийInformation security, cybersecurity and privacy protection. Test requirements for cryptographic modules.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…