Name:
DANSK DSF/PREN ISO 19299 PDF
Published Date:
Status:
[ Draft-Obsolete ]
Publisher:
Dansk Standard
The overall scope of this document is the definition of an information security framework for all organizational and technical entities of an EFC scheme and for the related interfaces, based on the system architecture defined in ISO 17573-1. The security framework describes a set of requirements and associated security measures. The scope of this document comprises the following: – definition of a trust model (Clause 5): basic assumptions and principles for establishing trust between the stakeholders. – security requirements (Clause 6): security requirements to support actual EFC system implementations; – security measures – countermeasures (Clause 7); – security specifications for interface implementation (Clause 8): security add-on to EFC standards, as shown in Figure 6; – key management (Clause 9): initial setup of key exchange between stakeholders and several operational procedures like key renewal, certificate revocation, etc.; – security profiles (Annex A); – implementation conformance statement (Annex B): checklist to be used by an equipment supplier, a system implementation, or an actor of a role declaring his conformity to this document; – general information security objectives of the stakeholders (Annex C) which provide a basic motivation for the security requirements; – threat analysis (Annex D) on the EFC system model and its assets using two different complementary methods, an attack-based analysis, and an asset-based analysis; – security policy examples (Annex E and Annex F); – recommendations for privacy-focused implementation (Annex G); – proposal for end-entity certificates (Annex H).
| Edition : | 19 |
| File Size : | 1 file , 1.9 MB |
| Number of Pages : | 162 |
| Product Code(s) : | DSF-121, DSF-121 |