Overview
ISO/IEC 19989-2:2020 - "Information security - Criteria and methodology for security evaluation of biometric systems - Part 2: Biometric recognition performance" defines requirements and recommendations for the security evaluation of biometric recognition performance. Intended for biometric verification and identification systems, it supplements the ISO/IEC 15408 evaluation framework and ISO/IEC 19989-1 by providing concrete guidance to developers and evaluators on planning, testing, analysing and documenting biometric performance from a security viewpoint. Evaluation of presentation-attack detection techniques is largely out of scope, except for impostor presentation scenarios covered under the TOE guidance.
Key Topics and Requirements
- Security-oriented performance testing: Guidance for supplementary evaluation activities (ATE tests) that extend ISO/IEC 18045 methodology to biometric-specific metrics.
- Evaluation planning: Requirements for test planning, including estimation of test sizes, test documentation and selection of capture devices and test cohorts.
- Data collection and test execution: Best practices for acquiring representative test data and performing reproducible tests for biometric recognition performance.
- Performance metrics: Use and interpretation of biometric error rates such as FAR, FRR, FPIR, FNIR and detection error trade-off (DET) analyses for security assessment.
- Assessment of developer tests: Criteria for reviewing developer-supplied tests, repeating subsets of tests, and conducting independent testing (ATE_IND).
- Vulnerability assessment (AVA): Supplementary activities to identify potential vulnerabilities, define the target of evaluation (TOE) for testing, and rate attack potential.
- Practical examples: Informative annexes provide sample computations, test examples and assessment strategies to support implementers.
Applications
ISO/IEC 19989-2:2020 is practical for:
- Security evaluation labs performing certification and conformity assessment of biometric systems.
- Biometric system developers preparing evidence and test documentation for formal evaluations.
- Procurement and risk teams specifying security evaluation criteria for biometric products used in access control, border control, e‑ID and authentication.
- System integrators and auditors who need to interpret biometric recognition performance in a security context.
Who Should Use This Standard
- Biometric engineers and product developers
- Independent evaluators and testing laboratories
- Certification bodies and security assessors
- Procurement officers and security architects specifying biometric requirements
Related Standards
Normative and complementary references include:
Using ISO/IEC 19989-2:2020 helps align biometric performance testing with formal security evaluation processes and supports robust, defensible decisions when procuring or certifying biometric systems.