Overview
ISO/TR 23576:2020 is an ISO Technical Report that provides guidance on security management for digital asset custodians operating in blockchain and distributed ledger technology (DLT) environments. It discusses threats, risks and controls for systems that offer custodian and exchange services and for the asset information those custodians manage - notably signature (private) keys. The report is intended for custodians that manage signature keys and focuses on practical security controls and incident management. Out of scope are core blockchain security controls, business risks, segregation of customers’ assets and governance/management issues.
Key technical topics and requirements
ISO/TR 23576:2020 covers a broad set of technical topics and recommended security considerations, including:
- Key management: types of keys, key generation flows, use of multiple keys, suspension of keys, and special handling for signature keys that control digital assets.
- Wallet models: distinctions between hot wallets (online), cold wallets (offline), hardware wallets/HSMs, and deterministic/hierarchical deterministic wallets.
- System model: an example online custodian architecture (interfaces, authentication, transfer validation, credential databases).
- Risk categories: signature key risks, asset data risks, platform/system risks, suspension-of-service risks, and external factors (internet infrastructure, AML/KYC databases, blockchain forks).
- Security controls and ISMS elements: information security policies, access control, asset management, physical/environmental security, operations and communications security, supplier relationships, incident response and business continuity.
- Incident management: guidance on managing security incidents involving asset compromise, including detection, containment and recovery practices specific to custodians.
Practical applications - who should use this standard
This technical report is useful for:
- Digital asset custodians and cryptocurrency exchanges designing or auditing custody/security operations.
- Security architects and engineers building key management and wallet infrastructure.
- Compliance and risk teams focusing on AML/KYC intersection with custody security.
- Service providers and suppliers (HSM vendors, cloud providers, custodial tech stacks) aligning offerings with custody security best practices.
- Auditors and regulators seeking a structured view of custody-related security risks and mitigations.
Practical uses include developing key-management policies, designing hot/cold wallet strategies, selecting HSM/cloud controls, defining incident response playbooks, and informing procurement and third‑party assessments.
Related standards
- ISO 22739 (Blockchain and distributed ledger technologies - Vocabulary) is referenced for terminology used throughout ISO/TR 23576:2020.
Keywords: blockchain security, distributed ledger technologies, digital asset custodian, key management, signature keys, HSM, hot wallet, cold wallet, ISMS, custody security, incident management.