ISO/IEC 24759:2025
Information security, cybersecurity and privacy protection — Test requirements for cryptographic modules
Information security, cybersecurity and privacy protection — Test requirements for cryptographic modules
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 182
- Дата публикации:
- 26 февраля 2025 г.
- Издание:
- ISO/IEC IS 24759 edition 4 version 1
- ICS:
- 35.030
This document specifies the methods to be used by testing laboratories to test whether the cryptographic module conforms to the requirements specified in ISO/IEC 19790:2025. The methods are developed to provide a high degree of objectivity during the testing process and to ensure consistency across the testing laboratories. This document also specifies the information that vendors are required to provide testing laboratories as supporting evidence to demonstrate their cryptographic modules’ conformity to the requirements specified in ISO/IEC 19790:2025. Vendors can also use this document to verify whether their cryptographic modules satisfy the requirements specified in ISO/IEC 19790:2025 before applying to a testing laboratory for testing.
Abstract
Overview
ISO/IEC 24759:2025 - Information security, cybersecurity and privacy protection - Test requirements for cryptographic modules (ISO, 2025) defines the test methods that independent testing laboratories must use to verify that a cryptographic module conforms to the security requirements in ISO/IEC 19790:2025. The standard is designed to increase objectivity and consistency across laboratories, and it also specifies the supporting evidence vendors must supply. Vendors can use the document to self‑check their products before formal testing.
Key Topics and Requirements
ISO/IEC 24759:2025 organizes test requirements across the full lifecycle and internal structure of cryptographic modules. Major technical topics include:
- Cryptographic module specification and boundary - tests to confirm the defined module, its type, and physical/logical boundary.
- Interfaces and data paths - test cases for module interfaces, plaintext trusted paths, and protected internal paths.
- Roles, services, and authentication - verification of role separation, services provided, and authentication mechanisms.
- Software/firmware security and security levels - tests for modifiable/non‑modifiable firmware, and requirements mapped to security levels.
- Operational environment - evaluation of host OS and modifiable environments where applicable.
- Physical security and environmental failure protection - tests covering physical embodiments and resistance to tampering and environmental attacks.
- Non‑invasive and side‑channel resistance - test methods addressing power, timing and other non‑invasive attack vectors.
- Sensitive Security Parameter (SSP) management - verification of key generation, RNGs, storage, zeroization, and secure entry/output.
- Self‑tests and lifecycle assurance - procedures for pre‑operational and conditional self‑tests, configuration management, design/development and vendor testing.
- Documentation and cryptographic module security policy - required evidence, user and administrative documentation, and the module security policy content.
Applications and Who Uses It
ISO/IEC 24759:2025 is practical for organizations involved in the design, testing, certification and procurement of cryptographic modules:
- Testing laboratories and certification bodies - to apply consistent, objective test methods for product evaluation.
- Vendors and product engineers - to prepare evidence packages and perform pre‑testing against ISO/IEC 19790:2025.
- Security architects and compliance teams - to ensure deployed HSMs, TPMs, smart cards, encryption appliances and IoT cryptographic modules meet validated requirements.
- Procurement and risk officers - to specify testable security requirements in acquisition contracts.
Use this standard to streamline certification, reduce testing variability, and demonstrate conformity of cryptographic modules in regulated and high‑security environments.
Related Standards
- ISO/IEC 19790:2025 - cryptographic module security requirements (normative reference).
- Comparable standards and references often considered: NIST FIPS 140‑3 (US cryptographic module validation).
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24759:2025
Похожие стандарты
Другие стандарты ISO
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…
ISO 15638-15:2014
ДействующийIntelligent transport systems — Framework for cooperative telematics applications for regulated vehicles (TAR…
Overview - ISO 15638-15:2014 (Vehicle location monitoring, TARV) ISO 15638-15:2014 is part of the ISO 15638 suite for Intelligent Transport Systems (ITS) and defines the framework and data specificat…