ISO/IEC TS 20540:2018 PDF

ISO/IEC TS 20540:2018 PDF

Name:
ISO/IEC TS 20540:2018 PDF

Published Date:
06/01/2018

Status:
Active

Description:

Information technology - Security techniques - Testing cryptographic modules in their operational environment

Publisher:
International Organization for Standardization/International Electrotechnical Commission

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
$66.9
Need Help?

This document provides recommendations and checklists which can be used to support the specification and operational testing of cryptographic modules in their operational environment within an organization's security system.

The cryptographic modules have four security levels which ISO/IEC 19790 defines to provide for a wide spectrum of data sensitivity (e.g. low-value administrative data, million-dollar funds transfers, life-protecting data, personal identity information, and sensitive information used by government) and a diversity of application environments (e.g. a guarded facility, an office, removable media, and a completely unprotected location).

This document includes:

a) recommendations to perform secure assessing for cryptographic module installation, configuration and operation;

b) recommendations to inspecting the key management system, protection of authentication credentials, and public and critical security parameters in the operational environment;

c) recommendations for identifying cryptographic module vulnerabilities;

d) checklists for the cryptographic algorithm policy, security guidance and regulation, security manage requirements, security level for each of the 11 requirement areas, the strength of the security function, etc.; and

e) recommendations to determine that the cryptographic module's deployment satisfies the security requirements of the organization.

This document assumes that the cryptographic module has been validated as conformant with ISO/IEC 19790.

It can be used by an operational tester along with other recommendations if needed.

This document is limited to the security related to the cryptographic module. It does not include assessing the security of the operational or application environment. It does not define techniques for the identification, assessment and acceptance of the organization's operational risk.

The organization's accreditation, deployment and operation processes, shown in Figure 1, is not included to the scope of this document.

This document addresses operational testers who perform the operational testing for the cryptographic modules in their operational environment authorizing officials of cryptographic modules.


File Size : 1 file , 1.6 MB
Note : This product is unavailable in Russia, Ukraine, Belarus
Published : 06/01/2018

History


Related products

ISO/IEC 10118-2:2010
Published Date: 10/15/2010
Information technology - Security techniques - Hash-functions - Part 2: Hash-functions using an n-bit block cipher
$58.2
ISO/IEC 27050-3:2020
Published Date: 02/01/2020
Information technology - Electronic discovery - Part 3: Code of practice for electronic discovery
$58.2
ISO/IEC 20085-2:2020
Published Date: 03/01/2020
IT Security techniques - Test tool requirements and test tool calibration methods for use in testing non-invasive attack mitigation techniques in cryptographic modules - Part 2: Test calibration methods and apparatus
$37.2

Best-Selling Products

NBBI NB23-2004
Published Date: 01/01/2005
National Board Inspection Code - NBIC, 2004 Edition
NBBI NB23-2007 Part 2
Published Date: 12/31/2007
National Board Inspection Code - NBIC, 2007 Edition - Part 2 - Inspection
NBBI NB23-2011 Part 1
Published Date: 2011
National Board Inspection Code - NBIC, 2011 Edition - Part 1 - Installation
NBBI NB23-2015
Published Date: 2015
National Board Inspection Code - NBIC, 2015 Edition (Three Volumes)
NBBI NB23-2019 Part 1
Published Date: 2019
National Board Inspection Code - NBIC, 2019 Edition - Part 1 - Installation
NBBI NB23-2019 Part 2
Published Date: 2019
National Board Inspection Code - NBIC, 2019 Edition - Part 2 - Inspection