AS ISO 13491.2:2019
$49.40
Secure cryptographic devices (retail) – Security compliance checklists for devices used in financial transactions
Published By | Publication Date | Number of Pages |
AS | 2019-03-12 | 49 |
The objective of this Standard is to specify checklists to be used to evaluate secure cryptographic devices (SCDs) incorporating cryptographic processes as specified in ISO 9564-1, ISO 9564-2, ISO 16609, AS 2805.6.1.1 (identical adoption of ISO 11568-1), AS 2805.6.1.2 (identical adoption of ISO 11568-2), and AS 2805.6.1.4 (identical adoption of ISO 11568-4), in the financial services environment.
Scope
This document specifies checklists to be used to evaluate secure cryptographic devices (SCDs) incorporating cryptographic processes as specified in ISO 9564-1, ISO 9564-2, ISO 16609, ISO 11568-1, ISO 11568-2, and ISO 11568-4 in the financial services environment. Integrated circuit (IC) payment cards are subject to the requirements identified in this document up until the time of issue after which they are to be regarded as a āpersonalā device and outside of the scope of this document.
This document does not address issues arising from the denial of service of an SCD.
In the checklists given in Annex A to Annex H, the term ānot feasibleā is intended to convey the notion that although a particular attack might be technically possible, it would not be economically viable since carrying out the attack would cost more than any benefits obtained from a successful attack. In addition to attacks for purely economic gain, malicious attacks directed toward loss of reputation need to be considered.