Overview
ISO/IEC 19792:2025 - Information security, cybersecurity and privacy protection - General principles, requirements and guidance for security evaluation of biometric systems - defines the high‑level principles and requirements for assessing the security of biometric systems. This second edition (replacing ISO/IEC 19792:2009) harmonizes the structure with general security evaluation methodology and focuses on biometric‑specific aspects such as recognition performance, presentation attack detection (PAD) and privacy. It is intentionally methodology‑neutral: the document specifies what to consider in a security evaluation rather than prescribing a single test procedure.
Key topics and technical requirements
- Scope and purpose: Principles for security evaluation of complete biometric systems (verification and identification) and relevant subsystems. Non‑biometric system elements (e.g., databases, network channels) are not covered here.
- Threat and vulnerability analysis: Comprehensive overview of biometric‑specific threats (performance limitations, hostile environments, enrolment process weaknesses, data leakage/alteration, synthesized samples, PAIs, related‑person similarity, characteristic modification).
- Recognition performance evaluation: Guidance on assessing security‑relevant error rates and the impact of those errors on system security; role of independent testing is emphasised.
- Presentation attack detection (PAD): Principles for evaluating PAD effectiveness and vulnerabilities to presentation attacks.
- Privacy and data protection: High‑level guidance on privacy risks, de‑enrolment and account deactivation rights for biometric reference data.
- Evaluation approach: Harmonized with general security evaluation methodology to support integration into certification schemes or bespoke evaluation programs.
Practical applications
ISO/IEC 19792:2025 is intended to:
- Guide developers in designing biometric systems with evaluability and security controls for recognition and PAD.
- Help evaluators create or refine security evaluation criteria and test plans for biometric solutions.
- Support procurers and system integrators in specifying security and privacy requirements for biometric purchases and deployments.
- Serve as a framework for organizations implementing or adapting certification and testing methodologies for biometric products.
Who should use this standard
- Biometric system developers and vendors
- Independent evaluators and testing laboratories
- Procurement officers and system integrators specifying biometric requirements
- Security architects, privacy officers and compliance teams
- Certification bodies and standards writers
Related standards
ISO/IEC 19792:2025 references and complements other biometric and evaluation standards, including:
Keywords: ISO/IEC 19792:2025, biometric security evaluation, presentation attack detection, recognition performance, biometric privacy, biometric vulnerabilities, security evaluation methodology.