Overview
ISO/IEC 20243-2:2023 - Part 2 of the Open Trusted Technology Provider Standard (O‑TTPS) - defines the assessment procedures used to evaluate conformity to the O‑TTPS mandatory requirements. Published in 2023 as the second edition, this document standardizes how assessors gather evidence, run assessments, and report results to ensure repeatability, reproducibility, and objectivity when checking COTS ICT product integrity and supply chain security.
Key topics and technical requirements
The standard focuses on assessor activities and evidence collection for supply‑chain and product integrity controls defined in O‑TTPS Part 1. Major technical topics include:
- Assessment framework and concepts: scope of assessment, representative products, and provider categories.
- General assessor requirements: evidence of conformance, impartiality, and documentation practices.
- Product development and life‑cycle controls:
- PD_DES (Design process), PD_CFM (Configuration management), PD_MPP (Development methods)
- PD_QAT (Quality and test management), PD_PSM (Product sustainment)
- Security engineering and response:
- SE_TAM (Threat analysis and mitigation), SE_VAR (Vulnerability analysis and response)
- SE_PPR (Patching and remediation), SE_SEP (Secure engineering), SE_MTL (Threat landscape monitoring)
- Supply‑chain and organizational controls:
- SC_RSM (Risk management), SC_PHS (Physical security), SC_ACC (Access controls)
- SC_ESS (Employee and supplier security), SC_BPS (Business partner security)
- SC_TTC (Trusted technology components), SC_STH (Secure transmission/handling), SC_CTM (Counterfeit mitigation), SC_MAL (Malware detection)
- Supporting materials: Annex A (assessment guidance) and Annex B (assessment report template).
The standard was revised from the 2018 edition with clarified definitions (e.g., “component” includes hardware and software), new mandatory items, and reorganized vulnerability and transmission requirements.
Practical applications and users
ISO/IEC 20243-2:2023 is primarily aimed at:
- Assessors and conformity bodies - to perform objective, repeatable O‑TTPS audits and produce consistent reports.
- COTS ICT providers - to prepare for assessments, align processes (design, configuration, patching, vulnerability response) and demonstrate conformance to customers.
- Purchasers, integrators, and procurement teams - to evaluate vendor integrity and reduce supply‑chain risk by requiring O‑TTPS assessment evidence.
- Security and compliance teams - to map internal controls to internationally recognized assessment procedures.
Benefits include clearer auditability, demonstrable supply‑chain integrity, and improved procurement confidence.
Related standards
- ISO/IEC 20243-1 (O‑TTPS Part 1): mandatory requirements and guidelines for mitigating maliciously tainted and counterfeit products.
- The Open Group O‑TTPF (Open Trusted Technology Provider Framework / Guide) - supporting guidance and best practices.
Keywords: ISO/IEC 20243-2:2023, O‑TTPS assessment procedures, supply chain security, conformity assessment, COTS ICT, vulnerability response, counterfeit mitigation.