Showing posts with label ISO. Show all posts
Showing posts with label ISO. Show all posts

Thursday, April 21, 2016

Cryptographic module related work in ISO/IEC JTC 1/SC 27/WG 3

Last updated: 2019-03-04

For several years the value of conformance testing against the FIPS 140-2 specification has been well accepted, and the assurance gained through validated conformance has been specified (with varying degrees of rigor) in several other markets. For example:
  • Other governments that use either FIPS 140-2 or ISO/IEC 19790: These include: 
    • Canada, who partners with NIST in operating the CMVP as a joint endeavor between NIST and the Canadian Centre for Cyber Security (CCCS), a branch of the Communications Security Establishment (CSE); 
    • Japan CMVP which is part of the  Information-technology Promotion Agency (IPA). JCMVP developed and operate a validation program (similar to that used in the US and Canada) in support of procurement in compliance with the Japanese Standards for Information Security Measures for the Central Government Computer Systems;
    • Korea Cryptographic Module Validation Program (KCMVP)
    • Spain (CCN)
    • Turkey (TSE)

  • Several Common Criteria national schemes who may often draw from cryptographic module or cryptographic algorithm validations in their own assurance work. These include:
    • US: NIAP who specify that NIST crypto algorithm validation program certificates be obtained in support of CC evaluations.

  • In 2013, an ENISA survey shows that 89% of respondents report using at least some product with a NIST FIPS certification, while 80% of use at least one Common Criteria certified product. 
  • The UK’s information commissioner’s office and Treasury Solicitor’s Department, both of which recommend using FIPS 140-2 validated encryption products.
  • The Health industry. For example, the HITECH act provides for "safe harbor" from the costs of patient notification as well as the reputational risk if the data was protected  using encryption. The approved encryption processes to claim safe harbor are those that comply with the requirements of the Federal Information Processing Standards (FIPS) 140-2.
  • The Financial industry. This industry has long referenced use of FIPS 140-2 and its predecessors as a best practice. More recently, the Payment Card Industry has drawn heavily from FIPS 140-2 in their endeavors to obtain cryptography assurance within PCI environments and systems in several of their standards.
  • Voting Systems. The Electoral Assistance Commission’s Voluntary Voting System Guidelines recommend the use of FIPS 140-2 for cryptography in voting systems.
  •  Digital Cinema. FIPS 140-2 is specified in the digital cinema specification, V1.2.
Despite the obvious usefulness of the standard and the assurance that is gained from programmatic testing and validation of the results, it has been long recognized that a US government-produced standard (and US government validations) may not be appropriate for scenarios beyond the US Government regulation and so, in 2003, a project was initiated by ISO/IEC JTC 1 sub-committee 27 which focuses on IT security techniques. The project was allocated to Working Group 3, and the assigned editors and experts from the US, France and Japan led the international coordination to produce the first edition of ISO/IEC 19790 which was published in 2006.

A comparison of FIPS 140-2 and ISO/IEC 19790 is given in the blog "ISO's cryptographic module work".

A similar blog on ISO's work related to ISO/IEC 15408 (Common Criteria)  is also avilable. There is some overlap.

Work from ISO/IEC JTC 1/SC 27/WG 3 related to cryptographic modules

The work in ISO is not restricted to the specification and the associated test requirements. There are several other work items that have been published or are currently being developed in SC 27/WG 3. These include:

Requirements and testing

IS 19790:2012: Security requirements for cryptographic modules

Specifies security requirements specified intended to maintain the security provided by a cryptographic module.

This core standard is currently in it's second edition,  Note that the standard has been updated with a corrigendum in 2015.

IS 24759:2014: Test requirements for cryptographic modules

Specifies the methods to be used by testing laboratories to test whether the cryptographic module conforms to the requirements specified in ISO/IEC 19790:2012/Cor.1:2015. It also specifies the requirements for information that vendors provide to testing laboratories as supporting evidence for conformance testing.

This standard is currently in it's second edition,  Note that the standard has been updated with a corrigendum in 2015.

Deployed Modules 

DRAFT ISO/IEC TS 20540 Guidelines for testing cryptographic modules in their operational environment  

Describes the guidelines that may be used in operational testing of cryptographic
modules which are deployed as part of a security system. The operational tests are performed to determine the suitability and proper usage of a cryptographic module in its intended environment.

Non-Invasive attacks

IS 17825:2016: Testing methods for the mitigation of non-invasive attack classes against cryptographic modules

Specifies the non-invasive attack mitigation test metrics for determining conformance to the requirements specified in ISO/IEC 19790 for Security Levels 3 and 4. The test metrics are associated with the security functions specified in ISO/IEC 19790. Testing will be conducted at the defined boundary of the cryptographic module and I/O available at its defined boundary.

The test methods used by testing laboratories to test whether the cryptographic module conforms to the requirements specified in ISO/IEC 19790 and the test metrics specified in this International Standard for each of the associated security functions specified in ISO/IEC 19790 are specified in ISO/IEC 24759. The test approach employed in this International Standard is an efficient "push-button" approach: the tests are technically sound, repeatable and have moderate costs.

DRAFT ISO/IEC TR 20085-1: Test tool requirements and test tool calibration methods for use in testing non-invasive attack mitigation techniques in cryptographic modules — Part 1: Test tools and techniques.

DRAFT ISO/IEC TR 20085-2: Test tool requirements and test tool calibration methods for use in testing non-invasive attack mitigation techniques in cryptographic modules — Part 2: Test calibration methods and apparatus

TR 30104:2015: Physical Security Attacks, Mitigation Techniques and Security Requirements

This technical report provides guidance and addresses the following topics:
  • a survey of physical security attacks directed against different types of hardware embodiments including a description of known physical attacks, ranging from simple attacks that require little skill or resource, to complex attacks that require trained, technical people and considerable resources;
  • guidance on the principles, best practices and techniques for the design of tamper protection mechanisms and methods for the mitigation of those attacks; and
  • guidance on the evaluation or testing of hardware tamper protection mechanisms and references to current standards and test programs that address hardware tamper evaluation and testing.

Cryptographic functions, algorithms and protocols

Note that the specification of cryptography and security mechanisms  is handled in WG 2: I have not listed their related work here. A full list of SC 27 work can be found in the ISO Standards Catalogue.

DRAFT IS 18367: Cryptographic algorithms and security mechanisms conformance testing

Intended to provide the basis for testing the implementation correctness of cryptographic algorithms published by ISO.
Conformance testing assures that an implementation of a cryptographic algorithm or security mechanism implementation is correct whether implemented in hardware, software or firmware or in a specific operating environment. Testing may consist of known-answer or Monte Carlo testing, or a combination of test methods. Testing may be performed on the actual implementation or modeled in a simulation environment.

2016: This document is in the late stages of development and is expected to be published before the end of 2016.

IS 29128:2011: Verification of cryptographic protocols: 

Establishes a technical base for the security proof of the specification of cryptographic protocols. It specifies design evaluation criteria for these protocols, as well as methods to be applied in a verification process for such protocols. It also provides definitions of different protocol assurance levels consistent with evaluation assurance components in ISO/IEC 15408.

DRAFT ISO/IEC 20543: Test and analysis methods for random bit generators within ISO/IEC 19790 and ISO/IEC 15408

Describes testing and evaluation methods for determining the acceptable randomness of non-deterministic and deterministic random bit generators for use in cryptographic applications.

Physically unclonable functions (PUFs)

DRAFT: ISO/IEC  20897:Security requirements, test and evaluation methods for physically unclonable functions (PUFs) for generating non-stored security parameters

2016: This standard is currently under development.

Competence


DRAFT ISO/IEC TR 19896-1: Competence requirements for information security testers and evaluators: Part 1: Introduction, concepts and general requirements

Provide the fundamental concepts related to the topic of the competence of the individuals responsible for performing IT product security evaluations and conformance testing. Provides the framework and the specialised requirements that specify the minimum competence of individuals performing IT product security evaluation and conformance testing using established standards.
This will support the goals of ISO CASCO conformity assessment by contributing standardized requirements for competency supporting ISO/IEC 17024.


 DRAFT ISO/IEC TR 19896-2: Competence requirements for information security testers and evaluators: Part 2: Knowledge, skills and effectiveness requirements for 19790 testers

This standard will establish  a baseline for the competence of ISO/IEC 19790 testers and validators with the goal of establishing conformity in the requirements for the training of ISO/IEC 19790 testing and validator professionals associated with cryptographic module conformance testing programs.

About testing and validation of conformance to ISO/IEC 19790

Now that there is an internationally recognized set of standards for the specification and testing of cryptographic modules, a base set of cryptographic standards and fundamentals, as well as a means of testing their implementation correctness, all the needed tools are in place for various authorities to develop validation programs - and use of the tools provide for consistent testing, validation, and certification of conformance to the ISO standard.

This is already happening.
  • In Japan, IPA operates a cryptographic module validation program with ISO/IEC 19790 as a basis known as the JCMVP.  At the ICMC in 2013, Japan announced that a memorandum of understanding between the JCMVP and the CMVP.
  • in Korea, the Korean Cryptographic Module Validation Program (KCMVP ) was established in 2005 and uses ISO/IEC 19790 as a basis for their program specifying the Korean approved set of cryptographic algorithms and security functions.
  • A validation program in Spain for cryptographic modules is based on the ISO standards
  • A validation program in Turkey for cryptographic modules is based on the ISO standards
  • Other national programs are under consideration 
With the development of validation programs using the standards -- and perhaps even one day mutual recognition by different programs -- the needs of the commercial sector around the world can be addressed. This would help developers and vendors of cryptographic modules to address markets on a multi-national basis (and may even help address some of the issues apparent in the critical infrastructures and the international supply chain).

To successfully offer such a service, a validation program must define the operational activities that are vital to a successful program. These activities include:
  • accrediting test laboratories
  • making program policies
  • defining the approved cryptographic functions,
  • establishing algorithm implementation testing and validation
  • establishing a management system for validating and certifying the testing results
  • providing any necessary interpretations of the standards
  • dealing with comments, requests, and issues from labs and vendors
  • policing the certificate and logo usage 
WG3 have produced a document that provides additional guidance on this topic:

ISO/IEC 15443  ("FRITSA")

ISO/IEC TR 15443-1:2012:  Security assurance framework -- Part 1: Introduction and concepts

ISO/IEC TR 15443-2:2012: Security assurance framework -- Part 2: Analysis

Substantially revised in 2012. Part one gives a discussion of the nature of security assurance, providing a framework for further discussions and documents. Part 2 of this technical report describes the "criteria for criteria". It discusses security assurance schemes, and how these themselves can be evaluated. While some schemes are of high quality, others may not be. What criteria can be used to tell?



By Fiona Pattinson

Monday, April 29, 2013

Report on the work in ISO/IEC JTC 1/SC 27/WG 3 related to ISO/IEC 15408

Last week I was once again privileged to be able to  join ISO/IEC JTC 1/SC 27/WG 3 during the latest of their bi-annual working sessions held in April and October.

Convened by Miguel Bañón, this working group is of particular interest to atsec since it includes work on the international standards and guidance documents relating to ISO/IEC 15408, ISO/IEC 19790 and other documents closely related to evaluation and testing and the provision of assurance.

I have written in more detail on these standards in:

A little history on the relationship between ISO/IEC 15408 and the Common Criteria reveals that in the early 1990's, as the various national criteria , including Europe's ITSEC, The Canadian Criteria (CTCPEC) and the US Federal criteria, were brought together in order to create a single set of harmonized criteria, the intention was to publish the new set of "Common Criteria" as an ISO standard. A decision was made to create a more agile  technical community that could produce the work and present it to ISO. This was not done using the "PAS" process, but aimed to produce and submit  a substantially complete work that would allow expeditious instantiation of the work with the full involvement of the ISO community,which could then support the standard's future maintenance within ISO.

Hence the CCDB and ISO established a close liaison relationship, the Common Criteria were submitted to ISO by the CCDB and the first edition of  ISO/IEC 15408 was published in December of 1999.  Since then the CCDB have continued to liaise with ISO enabling the content  ISO/IEC 15408 and the "Common Criteria" to remain synchronized. It's a two way relationship allowing for changes and innovations to be brought to WG 3, and vice versa.

ISO brings to the table a breadth and depth of constituents far beyond that of the CCDB. SC 27 (Security Techniques) currently brings together 50 participating nations, a further 27 observing nation and is in liaison with many industry groups and standards organizations.
(At the SC 27 level these currently include CCDB, CCETT, Cloud security alliance, ECBS, ENISA, EPC, ETSI, Ecma International, ISACA/ITGI, ISSEA, ITU, MasterCard, and Visa, and organizations in direct liaison with WG 3 include the CCDB, CSNISG, ENISA, FIRST, ISCI, ISA99, ITU-T, ISO SC 7, ISO SC 37, ISO TC 65/WG 10, ISO TC 247. TCG and The Open Group.)

The various national bodies and liaison organizations represented in WG 3 work closely within their home fields to garner the participation of, and to  represent the interests of, their own constituents.

The CCDB was initially comprised of representatives from those  countries contributing their own national criteria, today the CCDB is still a subset of  the  13 members of the CCRA certificate issuing signatory nations and development efforts  focus on the needs of the government agencies which they represent. From the perspective of commercial industry and the wider group of CCRA it is a closed group, a little disconcerting when you realize that at least in the U.S., the stated policy is to adopt COTS products as a means of making government systems, more timely and cost-effective  and the US government emphasizes the benefits of public-private partnership.

What does this mean in practice? WG 3 have focused on the open development of supporting standards and guidance. My earlier blogs detailed much of the work the WG 3 has established or that in progress. During  our  last WG 3 meeting  we heard from both The Open Group Real Time Embedded Systems forum and from our hosts at ETSI that work on High-assurance is an important topic to them and so WG 3 has initiated a study period on High-assurance - asking for contributions on this topic from it's national bodies and liaison organizations. WG 3 is also calling for contributions on the study period for predictive assurance, in which we hope to  understand the needs of industry and the  nations for this important topic.

As a result of  our last meeting WG 3:
  • Proposed a new work item - A Catalogue of Architectural and Design Principles for Secure products, Systems and Applications 
  • Resolved  to revise the existing standard ISO/IEC 19791: Security assessment of operational systems in the light of progress that has been made in the few years since it was published and expected findings from the study of predictive assurance
  • Resolved to send the final corrigenda for  ISO/IEC 15408 and ISO/IEC 18045 for ballot by the ISO members. (These corrections to the standards reflect the changes that were introduced by Common Criteria V3.1 release 4.)
  • Initiated a study period on high-assurance
  • Extended the study period on predictive assurance
If you are interested in contributing to these or other developments within SC 27 then you can do so either through your national body, or through one of the liaison organizations to SC 27.

By, Fiona Pattinson

Monday, November 26, 2012

ISO's work related to The Common Criteria

Updated November 9th, 2016

In 1990  ISO/IEC JTC 1 sub committee 27 was formed in order to deal with ICT security, Not long afterwards SC 27 initiated Working Group 3 "Security Evaluation Criteria". This working group focuses on security evaluation, testing and specification. 

At that time, Common Criteria was in development and the need to have these standards internationally recognised was an important point of the strategy. The goal, which has been achieved, was that the standards should be available to the world, regardless of the formal Common Criteria Recognition Arrangement which was the formal arrangement between nations.

SC27's business plan mentions that "The CCDB and SC 27/WG 3 have had a long-standing technical liaison on projects related to IT Security Evaluation Criteria. Thus, Working Group 3 has been working in close co-operation with the CCDB on the development of the Common Criteria, which has been simultaneously published as ISO/IEC 15408. The co-operation has been extended to also involve the work on 18045 “Evaluation methodology for IT security”.

This liaison allows ISO's member national bodies, especially those not represented directly in the CCDB, an opportunity to review, comment and contribute to the project. In many cases it also provides a vehicle for industry experts from the commercial sector (vendor) community to have a place to contribute more directly.


Both ISO/IEC JTC 1/SC 27/WG 3 and the CCDB produce supporting documents, those produced by the CCDB are listed on the CC portal at the bottom of the supporting publications page and cover smartcard and IC technology as well as documents directly related to supporting the CCRA.
   
Additional documents related to ISO/IEC 15408 produced by WG 3 are described below.

2016 Study Period on Information Assurance

2016: The Study Period, which has been run by ISO, in close liaison with the CCDB, in regard to determining appropriate future developments of ISO/IEC 15408, ISO/IEC 18045 and other IT Assurance standards closed after a year. 

The Fall  2016 WG 3 meeting enjoyed a summary of the two calls for comments and the rapporteurs presented a proposal for revising the ISO/IEC 15408 and ISO/IEC 18045 standards, as well as proposing some changes to the structure of ISO/IEC 15408.

The proposed changes are shown in the diagram below. They include the specification of two new parts to ISO/IEC 15408 and an additional document that will be guidance supporting the transition and explaining the changes to the standard.




 

Evaluation criteria and Methodology for IT security evaluation

These are the "equivalent standards" to those published by the CCDB on the CC Portal. Minor revisions of the CC standards are usually addressed in ISO through the publication of corrigenda.

These ISO standards are available from ISO for free (as in beer). The first three are equivalent to the first three parts of the CC, the fourth in the list is the equivalent of the CEM.

ISO/IEC 15408-1:2009: Evaluation criteria for IT security -- Part 1: Introduction and general model

ISO/IEC 15408-2:2008: Evaluation criteria for IT security -- Part 2: Security functional components

ISO/IEC 15408-3:2008: Evaluation criteria for IT security -- Part 3: Security assurance components

ISO/IEC 18045:2008: Methodology for IT security evaluation

Developing security and privacy functional requirements based on ISO/IEC 15408

ISO/IEC TS 19608: Guidance for developing security and privacy functional requirements based on ISO/IEC 15408

This Technical Report provides guidance for developing privacy functional requirements as extended components based on privacy principles defined in ISO/IEC 29100 through the paradigm described in ISO/IEC 15408-2, for selecting and specifying Security Functional Requirements from ISO/IEC 15408-2 to protect Personally Identifiable Information and to specify a procedure to define both privacy and security functional requirements in a coordinated manner.
 2016/11: This new Technical Specification is currently being published by ISO.

Guidance for the production of Protection Profiles and Security Targets

ISO/IEC TR 15446: Guide for the production of Protection Profiles and Security Targets

This technical report provides much needed guidance to PP authors and ST writers. Although ISO/IEC 15408-1 provides the technical information about writing a PP or an ST, The member nations of ISO supported that some practical guidance in writing these documents was needed and that this work should be completed. 

2016/11: The third edition of ISO/IEC 15446 is currently being published by ISO. 

Security assessment of operational systems

ISO/IEC TR 19791: Security assessment of operational systems.

ISO/IEC TR 19791:2010 provides guidance and criteria for the security evaluation of operational systems. It provides an extension to the scope of ISO/IEC 15408 by taking into account a number of critical aspects of operational systems not addressed in ISO/IEC 15408 evaluation. The principal extensions that are required address evaluation of the operational environment surrounding the target of evaluation, and the decomposition of complex operational systems into security domains that can be separately evaluated.
ISO/IEC TR 19791:2010 provides:
  1. a definition and model for operational systems;
  2. a description of the extensions to ISO/IEC 15408 evaluation concepts needed to evaluate such operational systems;
  3. a methodology and process for performing the security evaluation of operational systems;
  4. additional security evaluation criteria to address those aspects of operational systems not covered by the ISO/IEC 15408 evaluation criteria.
ISO/IEC TR 19791:2010 permits the incorporation of security products evaluated against ISO/IEC 15408 into operational systems evaluated as a whole using ISO/IEC TR 19791:2010.
ISO/IEC TR 19791:2010 is limited to the security evaluation of operational systems and does not consider other forms of system assessment. It does not define techniques for the identification, assessment and acceptance of operational risk.

This document was initially produced as a technical report with the goal of gaining experience in the subject sufficient to be able to codify a standard. It defines extensions to ISO/IEC 15408 in order to enable the security assessment (evaluation) of operational systems. Since ISO/IEC 15408, does not capture certain critical aspects of an operational system that must be precisely specified in order to effectively evaluate such a system

The contents are fairly exhaustive with discussions of
  • The technical approach to operational systems assessment used in this Technical Report.
  • The extension of ISO/IEC 15408 evaluation concepts for use in operational system evaluation.
  • The relationship between this Technical Report and other security standards which have been used in its development.
  • requirements for specification of security problems, security objectives, security requirements, SST contents and periodic reassessment which are needed in order to evaluate operational systems.
Annexes provide further supportive material including operational system:
  • Security Targets and System Protection Profiles, which defines the security requirement specifications needed for operational systems.
  • Functional control requirements, which defines the additional security functional requirements needed for operational systems
  • Assurance requirements, which defines the additional security assurance requirements needed for operational systems.
  • evaluation methodology, which defines additional actions to be performed by an evaluator conducting the evaluation of an operational system.
This TR has been used in practice, with an early trial evaluation being reported from Japan.

Competence requirements for information security testers and evaluators

DRAFT ISO/IEC TR 19896-1: Competence requirements for information security testers and evaluators: Part 1: Introduction, concepts and general requirements.

Provides the fundamental concepts related to the topic of the competence of the individuals responsible for performing IT product security evaluations and conformance testing. Provides the framework and the specialised requirements that specify the minimum competence of individuals performing IT product security evaluation and conformance testing using established standards.
This will support the goals of ISO CASCO conformity assessment by contributing standardized requirements for competency supporting ISO/IEC 17024.

DRAFT ISO/IEC TR 19896-3: Competence requirements for information security testers and evaluators: Part 3: Knowledge, skills and effectiveness requirements for ISO/IEC 15408 evaluator.

Provides the specialised requirements to demonstrate competence of individuals in performing IT product security evaluations in accordance with ISO/IEC 15408 and ISO/IEC 18045.

Vulnerability analysis and penetration testing for ISO/IEC 15408

ISO/IEC TR 20004-1:2016: Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045

ISO/IEC TR 20004-2:Detailing software penetration testing under ISO/IEC 15408 and ISO/IEC 18045 vulnerability analysis

Vulnerability Handling

ISO/IEC 30111  Vulnerability handling processes 

Describes processes for vendors to handle reports of potential vulnerabilities in products and online services. It is related to ISO/IEC 29147. It interfaces with elements described in ISO/IEC 29147 at the point of receiving potential vulnerability reports, and at the point of distributing vulnerability resolution information.This standard takes into consideration the relevant elements of ISO/IEC 15408-3, 13.5 Flaw remediation (ALC_FLR).

ISO/IEC 29147 Vulnerability disclosure

Gives guidelines for the disclosure of potential vulnerabilities in products and online services. It details the methods a vendor should use to address issues related to vulnerability disclosure.  This standard
  1. provides guidelines for vendors on how to receive information about potential vulnerabilities in their products or online services,
  2. provides guidelines for vendors on how to disseminate resolution information about vulnerabilities in their products or online services,
  3. provides the information items that should be produced through the implementation of a vendor's vulnerability disclosure process, and
  4. provides examples of content that should be included in the information items.
ISO/IEC 29147 has recently been published and is currently available for free.

Biometrics 

Delving into technology specific areas of evaluation, biometrics were seen by the community as an area in need of standardization. So far WG 3 has produced two standards in this area.

ISO/IEC 19792 Security evaluation of biometrics

Relevant to both evaluator and developer communities as it addresses biometric-specific aspects and principles to be addressed during a security evaluation of a biometric system.
It does not address the non-biometric aspects which might form part of the overall security
evaluation of a system using biometric technology (e.g. requirements on databases or communication channels).
Neither does this standard aim to define any concrete methodology for the security evaluation of biometric systems but instead focuses on the principal requirements. 

As such, the requirements in this International Standard are independent of any evaluation or certification scheme and will need to be incorporated into and adapted before being used in the context of a concrete scheme. The standard includes:
  • an overview of all terms, definitions and acronyms used,
  • an introduction of the overall concept for a security evaluation of a biometric system,
  • a description of the statistical aspects of security-relevant error rates,
  • vulnerability assessment of biometric systems and
  • the evaluation of privacy aspects.

 ISO/IEC 24745: Biometric information protection

Provides guidance for the protection of biometric information under various requirements for confidentiality, integrity and renewability/revocability during storage and transfer. Additionally, ISO/IEC 24745 provides requirements and guidelines for the secure and privacy-compliant management and processing of biometric information. ISO/IEC 24745 specifies the following:
  • analysis of the threats to and countermeasures inherent in a biometric and biometric system application models;
  • security requirements for secure binding between a biometric reference and an identity reference;
  • biometric system application models with different scenarios for the storage of biometric references and comparison; and
  • guidance on the protection of an individual's privacy during the processing of biometric information.
ISO/IEC 24745: does not include general management issues related to physical security, environmental security and key management for cryptographic techniques.

DRAFT IS 19989-1: Criteria and methodology for security evaluation of biometric systems: Part 1: Framework

DRAFT IS 19989-2: Criteria and methodology for security evaluation of biometric systems: Part 2: Biometric recognition performance

DRAFT IS 19989-3: Criteria and methodology for security evaluation of biometric systems: Part 3: Presentation attack detection

Test and analysis methods for random bit generators within ISO/IEC 19790 and ISO/IEC 15408

DRAFT ISO/IEC  TR 20543:Test and analysis methods for random bit generators within ISO/IEC 19790 and ISO/IEC 15408.

Physically unclonable functions (PUFs)

DRAFT: ISO/IEC  20897:Security requirements, test and evaluation methods for physically unclonable functions (PUFs) for generating non-stored security parameters

Cryptographic Protocols 

IS 29128: Verification of cryptographic protocols: 

Establishes a technical base for the security proof of the specification of cryptographic protocols. It specifies design evaluation criteria for these protocols, as well as methods to be applied in a verification process for such protocols. It also provides definitions of different protocol assurance levels consistent with evaluation assurance components in ISO/IEC 15408.

Physical Security Attacks, Mitigation Techniques and Security Requirements

ISO/IEC  30104:2015 Physical Security Attacks, Mitigation Techniques and Security Requirements

This technical report provides guidance and addresses the following topics:
  • a survey of physical security attacks directed against different types of hardware embodiments including a description of known physical attacks, ranging from simple attacks that require little skill or resource, to complex attacks that require trained, technical people and considerable resources;
  • guidance on the principles, best practices and techniques for the design of tamper protection mechanisms and methods for the mitigation of those attacks; and
  • guidance on the evaluation or testing of hardware tamper protection mechanisms and references to current standards and test programs that address hardware tamper evaluation and testing.

Secure System Engineering

ISO/IEC TS 19249: Catalogue of Architectural and Design Principles for Secure Products, Systems, and Applications

Provides a catalogue of architectural and design principles that can be used in the development of secure products, systems, and applications together with guidance on how to use those principles effectively. Each architectural and design principle is described using a common structure, identifying the purpose and advantage of the design principle, how it can contribute to develop a secure product, system, or application, its dependency on other principles described in the catalogue.

Examples are provided for each principle on how it may be implemented, how it may contribute to security properties and functions and what other aspects have to be taken into account in the example provided to also address non-security related requirements like usability and performance.

It gives guidelines for the development of secure products, systems and applications and is aiming for a more effective assessment with respect to the security properties they are supposed to implement.

ISO/IEC TS 19249 is related to IS 15408 and IS 18045 and addresses both developers and evaluators of secure products, systems, and applications.

This Technical Specification does not establish any requirements for the evaluation or the assessment process or implementation.

ISO/IEC TR 29193: Secure system engineering principles and techniques

This  technical report, ISO/IEC TR 29193 offers guidance on secure system engineering for Information and Communication Technology systems or products, and emphasizes security engineering aspects within the scope of the development stages of the system lifecycle described in ISO/IEC 15288.

Drawing on the notion that it is better to build a system or product securely in the first place than to spend much resource after its instantiation this technical report begins to offer guidance on how the use of these principles and techniques will support a system engineering process to obtain results consistent with the system security characteristics and objectives determined for the ICT system or product. 

ISO/IEC 21827:2008: Systems Security Engineering -- Capability Maturity Model® (SSE-CMM®). 

This standard was submitted through the Publicly Available Specification (PAS) process by ISSEA and remains in the ISO catalogue.

ISO/IEC 15443  ("FRITSA")

ISO/IEC TR 15443-1:2012:  Security assurance framework -- Part 1: Introduction and concepts

ISO/IEC TR 15443-2:2012: Security assurance framework -- Part 2: Analysis

Substantially revised in 2012. Part one gives a discussion of the nature of security assurance, providing a framework for further discussions and documents. Part 2 of this technical report describes the "criteria for criteria". It discusses security assurance schemes, and how these themselves can be evaluated. While some schemes are of high quality, others may not be. What criteria can be used to tell?

Study Period on the Security requirements, test and evaluation methods for White Box Cryptography (WBC).

WG 3 is currently investigating the above topic.




~By Fiona Pattinson.