Overview
ISO/TS 9546:2024 - "Guidelines for security framework of information systems of third-party payment services" is a Technical Specification from ISO that provides guidance for designing and implementing security mechanisms in technical infrastructures used by third‑party payment (TPP) service providers (TPPSPs). Aligned with the security objectives defined in ISO 23195 and following the ISO/IEC 15408 methodology, this document defines a pragmatic security framework and security functional recommendations (SFCs) to protect critical systems and assets within TPP environments, whether operated by TPPSPs or by other entities (e.g., banks).
Key Topics
- TPP logical structural models: Two reference models (with and without TPP-AIS) describing typical component interactions and the Target of Evaluation (TOE).
- Component‑specific recommendations: Security functions for key components:
- TPPSP credentials carrier (C2) - encryption, user authentication, access control.
- TPP payment terminal (C3) - encryption, logical security, transaction security, protection of payment‑sensitive information.
- TPPSP gatekeeper (C5) - access control, transaction security, audit logging.
- TPP‑BIS (C6) - user authentication, transaction security, risk control.
- TPP‑AIS (C15) - encryption, identity verification, transaction security.
- Core security functions: Identification & authentication, authorization, audit logging, asset protection, encryption, transaction integrity.
- Three‑layer security framework:
- Process layer - policies, identity, authorization, logging.
- Application layer - component‑level security measures for C2, C3, C5, C6, C15.
- Infrastructure layer - deployment, network and platform controls.
- Implementation guidance: Practical steps - identify SPD elements, determine security objectives, select/adapt SFCs; plus real‑world practices and Annex A examples.
Applications
ISO/TS 9546:2024 is useful for:
- TPPSPs and fintechs designing secure payment platforms (mobile wallets, e‑commerce, open banking payments).
- System architects and developers building or integrating TPP components (credentials carriers, payment terminals, gatekeepers).
- Security engineers and risk managers implementing authentication, encryption, logging, transaction security and asset protection.
- Banks and service providers evaluating third‑party integrations and compliance with TPP security objectives.
- Auditors and regulators assessing the security posture of TPP ecosystems against ISO guidance.
Practical uses include designing secure TPP architectures, selecting appropriate SFCs per component, documenting TOE boundaries, and adopting the three‑layer model to align technical controls with business processes and risk controls.
Related standards
- ISO 23195 - defines security objectives for TPP services (ISO/TS 9546 maps SFCs to these objectives).
- ISO/IEC 15408 - Common Criteria methodology referenced for the TOE concept and SFR/SFC approach.
Keywords: ISO/TS 9546:2024, third‑party payment, TPP security framework, TPPSP, ISO 23195, payment terminal security, authentication, encryption, audit logging.