Overview
ISO 13491-2:2023 - Financial services - Secure cryptographic devices (retail) - Part 2 - provides security compliance checklists for evaluating secure cryptographic devices (SCDs) used in retail financial transactions. The standard defines auditable statements and minimum evaluation items that assess physical security, logical protection, device management and lifecycle controls for devices that implement cryptographic processes referenced in ISO 9564‑1, ISO 9564‑2, ISO 16609 and ISO 11568. Integrated circuit (IC) payment cards are covered only up to the point of issuance.
Key Topics
- Security compliance checklists: structured, auditable statements to be answered True/False/N/A by evaluators and auditors.
- Physical security characteristics: tamper-evident and tamper‑resistant design considerations, protection against probing, mechanical, thermal, chemical and radiological attacks.
- Logical security and device management: secure key storage, transfer/loading, PIN handling, access control, dual control procedures and secure operator interfaces.
- Functional checklists (Annexes A–G): common device characteristics (Annex A) plus device-specific checklists for:
- PIN entry functionality (Annex B)
- PIN management (Annex C)
- Message authentication (Annex D)
- Key generation (Annex E)
- Key transfer and loading (Annex F)
- Digital signature functionality (Annex G)
- Environment categorization (Annex H): guidance on evaluating devices relative to the deployment environment (public vs. controlled locations).
- Random number generation: conformance to ISO/IEC 18031 where device RNGs are used.
- Evaluation process: roles of auditors, evaluation agencies and sponsors; how checklists are applied and interpreted.
Applications
ISO 13491-2 is practical for:
- Financial institutions and payment processors assessing SCDs (PIN entry devices, secure modules, key loaders).
- Device manufacturers preparing products for retail payment use and audits.
- Auditors and accredited evaluation agencies performing compliance checks and producing audit records.
- Payment scheme operators and approval authorities who set acceptance criteria and approve devices for deployment.
This standard helps reduce the risk of key disclosure, PIN compromise and message tampering by ensuring devices meet minimum security characteristics and are managed securely throughout their lifecycle.
Related Standards
Keywords: ISO 13491-2, secure cryptographic devices, SCD, security compliance checklists, retail financial services, PIN entry devices, tamper-evident, tamper-resistant, device evaluation, key management.