ISO/IEC 19989-1:2020 PDF
Information security — Criteria and methodology for security evaluation of biometric systems — Part 1: Framework
Information security — Criteria and methodology for security evaluation of biometric systems — Part 1: Framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 62
- Дата публикации:
- 29 сентября 2020 г.
- Издание:
- ISO/IEC IS 19989 edition 1 version 1
- ICS:
- 35.030
For security evaluation of biometric recognition performance and presentation attack detection for biometric verification systems and biometric identification systemsthis document specifies: — extended security functional components to SFR Classes in ISO/IEC 15408-2; — supplementary activities to methodology specified in ISO/IEC 18045 for SAR Classes of ISO/IEC 15408-3. This document introduces the general framework for the security evaluation of biometric systems, including extended security functional components, and supplementary activities to methodology, which is additional evaluation activities and guidance/recommendations for an evaluator to handle those activities. The supplementary evaluation activities are developed in this document while the detailed recommendations are developed in ISO/IEC 19989-2 (for biometric recognition aspects) and in ISO/IEC 19989-3 (for presentation attack detection aspects). This document is applicable only to TOEs for single biometric characteristic type. However, the selection of a characteristic from multiple characteristics in SFRs is allowed.
Abstract
Overview - ISO/IEC 19989-1:2020 (Framework)
ISO/IEC 19989-1:2020 defines a general framework for the security evaluation of biometric systems. It specifies extended security functional components and supplementary evaluation activities to be used when assessing:
- biometric recognition performance (verification and identification), and
- presentation attack detection (PAD) for biometric systems.
This part (Part 1: Framework) introduces the evaluation structure, vulnerability categorization, and the additional evaluator guidance. Detailed recommendations for biometric recognition and PAD evaluation are provided in companion documents ISO/IEC 19989-2 and ISO/IEC 19989-3.
Key technical topics and requirements
- Extended Security Functional Components - Adds biometric-specific components to Common Criteria SFR classes (notably Class FPT: protection of the TSF, and Class FIA: identification and authentication). Examples in the standard include FPT_PAD, FPT_BCP, FIA_EBR, FIA_BVR, and FIA_BID (see standard for full definitions and component levelling).
- Supplementary Activities to ISO/IEC 18045 - Provides additional evaluation activities and guidance for methodology classes (e.g., APE, ASE, ADV, AGD, ALC, ATE, AVA) to address biometric-specific concerns.
- Vulnerability Categorization - Describes common biometric system vulnerabilities, categorization of Targets of Evaluation (TOEs), and how those relate to recognition and PAD evaluation.
- Evaluation Scope - Applicable to TOEs implementing a single biometric characteristic type (selection from multiple characteristics in SFRs is allowed).
- Guidance for Evaluators - Recommends extra evaluator activities, audit items, and management considerations (e.g., capture quality checks, failure-to-enrol/performance requirements, PAD management and audit).
Practical applications
- Use ISO/IEC 19989-1 when planning or performing security evaluations of biometric verification and identification systems to ensure:
- Consistent, repeatable evaluation against Common Criteria SFRs augmented for biometric functions.
- PAD assessment is incorporated into security testing and lifecycle activities.
- Vulnerability analysis and attack potential specific to biometric modalities are considered.
Practical settings:
- Certification laboratories and Common Criteria evaluation teams
- Biometric product vendors and developers preparing security targets
- Procurement teams specifying evaluation criteria for biometric systems
- System integrators and risk managers validating biometric component security
Who should use this standard
- Evaluators and test laboratories performing Common Criteria evaluations of biometric TOEs
- Product developers creating biometric systems seeking evaluated assurance levels
- Certification bodies and auditors that need consistent biometric evaluation frameworks
- Procurement and security architects specifying biometric security requirements
Related standards and keywords
- Related: ISO/IEC 15408 (Common Criteria), ISO/IEC 18045 (evaluation methodology), ISO/IEC 19989-2, ISO/IEC 19989-3
- Keywords: biometric security, biometric evaluation, presentation attack detection (PAD), security functional requirements (SFR), Common Criteria, TOE evaluation, biometric recognition performance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19989-1:2020
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 19989-2:2020
ДействующийInformation security — Criteria and methodology for security evaluation of biometric systems — Part 2: Biomet…
Overview ISO/IEC 19989-2:2020 - "Information security - Criteria and methodology for security evaluation of biometric systems - Part 2: Biometric recognition performance" defines requirements and rec…
ISO/IEC 19989-3:2020
ДействующийInformation security — Criteria and methodology for security evaluation of biometric systems — Part 3: Presen…
Overview ISO/IEC 19989-3:2020 specifies criteria and methodology for security evaluation of presentation attack detection (PAD) in biometric systems. It supplements the ISO/IEC 15408 evaluation frame…
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…