ISO 19092:2023 PDF
Financial services — Biometrics — Security framework
Financial services — Biometrics — Security framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 65
- Дата публикации:
- 2 марта 2023 г.
- Издание:
- ISO IS 19092 edition 2 version 1
- ICS:
- 03.060
This document specifies the security framework for using biometrics for authentication of customers in financial services, focusing exclusively on retail payments. It introduces the most common types of biometric technologies and addresses issues concerning their application. This document also describes representative architectures for the implementation of biometric authentication and associated minimum control objectives. The following are within the scope of this document: — use of biometrics for the purpose of: — verification of a claimed identity; — identification of an individual; — biometric authentication threats, vulnerabilities and controls; — validation of credentials presented at enrolment to support authentication; — management of biometric information across its life cycle, comprising enrolment, transmission and storage, verification, identification and termination processes; — security requirements for hardware used in conjunction with biometric capture and biometric data processing; — biometric authentication architectures and associated security requirements. The following are not within the scope of this document: — detailed specifications for data collection, feature extraction and comparison of biometric data and the biometric decision-making process; — use of biometric technology for non-financial transaction applications, such as physical or logical system access control.
Abstract
Overview
ISO 19092:2023 - Financial services - Biometrics - Security framework defines a security framework for using biometrics to authenticate customers in financial services, with a specific focus on retail payments. The standard introduces common biometric technologies, describes representative implementation architectures, and sets out minimum control objectives for secure biometric authentication throughout the biometric lifecycle (enrolment, transmission, storage, verification/identification, termination).
Keywords: ISO 19092:2023, biometrics, financial services, security framework, retail payments, biometric authentication
Key topics and technical requirements
ISO 19092:2023 covers technical and security topics relevant to financial biometric systems, including:
- Biometric modalities - overview of common modalities such as fingerprints, face, voice, iris, signature, vein, palm print and keystroke patterns and their practical properties.
- Biometric lifecycle management - security controls across enrolment, transmission, storage, verification, identification, re-enrolment, refinement, suspension/reactivation, termination and archiving.
- Architectures - conceptual business and technical architectures, registration architectures and representative biometric authentication architectures (including PBP devices - Points of Biometric Presentation).
- Threats, vulnerabilities and controls - presentation attack vulnerabilities (including synthetic attacks), comparison/decision/storage subsystem risks, calibration and fault injection issues, and required mitigations.
- Security requirements - physical and logical security, identity registration controls, data storage and handling (including reference splitting), comparison/decision security, and security compliance verification.
- Usability and performance - recognition performance, performance evaluation, interoperability and presentation attack detection considerations.
Keywords: biometric modalities, biometric lifecycle, presentation attack, PBP devices, recognition performance, data storage
Practical applications and users
ISO 19092:2023 is intended for organizations implementing or governing biometric authentication for retail financial transactions, including:
- Banks, payment service providers and fintechs deploying biometric login or payment authentication
- Vendors and integrators of biometric capture devices and authentication platforms (PBP device manufacturers)
- Security architects, risk and compliance teams defining controls and policies for biometric systems
- Auditors and regulators assessing biometric security in retail payment ecosystems
Adopting ISO 19092 helps improve security posture, reduce fraud risks from biometric attacks, and align implementations with recognized minimum control objectives.
Related standards
ISO 19092 complements broader standards in identity management, payments and information security. For comprehensive compliance, implementers should also consider applicable data protection and payment-industry security requirements alongside ISO 19092:2023.
Keywords: biometric security standard, retail payment authentication, ISO biometrics, financial biometrics security
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 19092:2023
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 19092-1:2006
ОтменёнFinancial services — Biometrics — Part 1: Security framework
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…