ISO/IEC TR 14516:2002 PDF
Information technology — Security techniques — Guidelines for the use and management of Trusted Third Party services
Information technology — Security techniques — Guidelines for the use and management of Trusted Third Party services
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 33
- Дата публикации:
- 27 июня 2002 г.
- Издание:
- ISO/IEC TR 14516 edition 1 version 1
- ICS:
- 35.030
Associated with the provision and operation of a Trusted Third Party (TTP) are a number of security-related issues for which general guidance is necessary to assist business entities, developers and providers of systems and services, etc. This includes guidance on issues regarding the roles, positions and relationships of TTPs and the entities using TTP services, the generic security requirements, who should provide what type of security, what the possible security solutions are, and the operational use and management of TTP service security. This Recommendation | Technical Report provides guidance for the use and management of TTPs, a clear definition of the basic duties and services provided, their description and their purpose, and the roles and liabilities of TTPs and entities using their services. It is intended primarily for system managers, developers, TTP operators and enterprise users to select those TTP services needed for particular requirements, their subsequent management, use and operational deployment, and the establishment of a Security Policy within a TTP. It is not intended to be used as a basis for a formal assessment of a TTP or a comparison of TTPs. This Recommendation | Technical Report identifies different major categories of TTP services including: time stamping, non-repudiation, key management, certificate management, and electronic notary public. Each of these major categories consists of several services which logically belong together.
Abstract
Overview
ISO/IEC TR 14516:2002 - "Information technology - Security techniques - Guidelines for the use and management of Trusted Third Party services" - is a Technical Report that provides practical guidance on the provision, operation and management of Trusted Third Party (TTP) services. Published jointly by ISO/IEC and identical to ITU‑T Recommendation X.842, the report clarifies TTP roles, duties, service categories and the security, legal and operational issues that businesses, developers and TTP operators should consider. It is intended for system managers, developers, TTP operators and enterprise users seeking to select and manage TTP services; it is not intended as a formal assessment or comparison framework for TTPs.
Key topics and technical requirements
The report covers both conceptual and operational aspects, including:
- Roles, positions and relationships between TTPs and entities using services.
- Generic security requirements and guidance on who should provide specific protections.
- Management and operational aspects: legal issues, contractual obligations, responsibilities, and ethics.
- Security policy elements: standards, directives, procedures, risk management, safeguards (physical, organizational and IT-specific), awareness and training.
- Assurance and trust: trustworthiness, accreditation of certification bodies, audits, incident handling, contingency planning and quality of service.
- Interworking: TTP–user, user–user, TTP–TTP and interfaces with law enforcement.
- Major categories of TTP services:
- Time stamping
- Non‑repudiation
- Key management (generation, registration, certification, distribution, storage, archiving, revocation, destruction)
- Certificate management (public key certificates, attribute/privilege services, revocation)
- Electronic notary public (evidence generation, storage, arbitration)
- Digital archiving, directories, identification & authentication, recovery, personalisation, access control, alert management
- Annexes: security requirements for TTP management and aspects of Certification Authority (CA) management (registration, CPS examples).
Applications and who uses it
ISO/IEC TR 14516:2002 is practical for organizations that need to design, procure or operate TTP-enabled services, including:
- Enterprise security architects selecting key management, certificate or timestamping services
- TTP operators and Certification Authorities developing operational security policies and procedures
- System and network managers implementing non‑repudiation, authentication or electronic notary workflows
- Developers integrating TTP services into applications and digital transaction systems
- Legal and compliance teams assessing contractual and legal considerations for outsourced trust services
Related standards
- Identical text: ITU‑T Recommendation X.842
- Relevant to the work of ISO/IEC JTC 1/SC 27 (IT security techniques) and interoperates conceptually with standards addressing PKI, CA practices and information security management.
Keywords: ISO/IEC TR 14516:2002, Trusted Third Party, TTP services, time stamping, non‑repudiation, key management, certificate management, electronic notary, security policy, IT security.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC TR 14516:2002
Похожие стандарты
Другие стандарты ISO
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…
ISO/ASTM52901-17(2023)
ДействующийStandard Guide for Additive Manufacturing – General Principles – Requirements for Purchased AM Parts
Scope 1.1 This document defines and specifies requirements for purchased parts made by additive manufacturing. 1.2 It gives guidelines for the elements to be exchanged between the customer and the pa…