说明:收录全球国际标准 提供单次或批量下载
ISO/TS TECHNICAL SPECIFICATION 12812-2 First edition 2017-03 Core banking Mobile financial services Part 2: Security and data protection for mobile financial services Opérationsbancaires debase-Services financiersmobiles- Partie 2: Sécurite et protection des donnees pour les services financiers mobiles Reference number IS0/TS12812-2:2017(E) Intemational Organization for Standardization @IS02017 ZHEJIANG INSTOFSTANDARDIZATIONC15956617 ed without license from IHS IS0/TS12812-2:2017(E) COPYRIGHTPROTECTEDDOCUMENT IS02017,Published inSwitzerland All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or ISO's member body in the country of the requester. ISOcopyrightoffice Ch. de Blandonnet 8. CP 401 CH-1214 Vernier, Geneva, Switzerland Tel. +41 22 749 01 11 Fax +41 22 749 09 47 [email protected] www.iso.org Intematinaibr PrganizationfoStandardization Licensee-ZHEJIANG INST OF STANDARDIzoISQ0a7 -All rights reserved networking permited without license from IHS Notfor Resale, 2017/5/16 00:51:06 IS0/TS12812-2:2017(E) Contents Page Foreword .. Introduction.. ..i. 1 Scope.... 2 Normative references 3 Terms and definitions 4 Abbreviatedterms ..4 5 Summaryofthetechnicalnatureoftheclauses ..5 6 Securitymanagementconsiderations .7 6.1 General ..7 6.2 Three-layer model to manage security for mobile financial services. 6.2.1 Process layer. 9 6.2.2 Applicationlayer ..10 6.2.3 Infrastructurelayer .10 Securityprinciples and minimum requirements for mobilefinancial services .11 7.1 Security architecture aspects to be considered. .11 7.2 Mobile financial services hardening techniques overview. ..13 7.2.1 General. .13 7.2.2 Mobile device hardening techniques overview .13 7.2.3 Wireless networks hardeningtechniques overview ..13 7.2.4 Secure remote management ofmobile device components using OTA ..14 7.2.5 Mobile financial applications hardening techniques. ..14 7.2.6 Platform security services. ..15 7.2.7 Application level security services for mobile financial applications. .16 7.2.8 Application managementsecurityservices. ..17 7.3 Minimum set of security requirements for mobile financial services. ..17 7.3.1 General ..17 7.3.2 Remote MFS access requirements ..17 7.3.3 Transaction processing requirements .18 7.3.4 Protection of sensitive data .19 7.3.5 Mobiledevicerequirements. .20 7.3.6 Customereducation. .20 7.4 Minimum set of security requirements for mobile application management .21 7.4.1 Customer enrolment and provisioning requirements. 21 7.4.2 Key management 21 7.4.3 Mobilefinancial serviceproviderandtrusted servicemanagerexchanges 22 7.4.4 Application downloading 22 7.4.5 Application deactivation 22 7.5 Summary:Requirements forsecurity servicesfor mobile financial services 22 8 SecurityrequirementsforcryptographiccomponentsusedforMFs .23 8.1 Mobiledevicesecureenvironments 23 8.1.1 MobileDevicerequirementsforMFS .23 8.1.2 Software-based secure environment .24 8.1.3 Trusted execution environment (TEE) .24 8.1.4 Secureelementrequirements .26 8.1.5 Secureelement requirementsfordigital signatureservices. 28 8.2 Security requirements for cryptographic modules used for MFS 30 8.2.1 General ..30 8.2.2 Listofrequirementsforcryptographichardwaremodules 30 8.2.3 Requirementsforcryptographic softwaremodules ..31 9 Security evaluation and certification aspects ..31 9.1 General recommendation .31 ntemainal oganzation @S7 -All rights reserved iii 8e=ZHEJIANG INST OF STANDARDIZATION C1 5956617 vithoutlicense from IHS Not for Resale, 2017/5/16 00:51:06 No reproduction or networking permi

.pdf文档 ISO TS 12812-2 2017 Core banking — Mobile financial services — Part 2 Security and data protection for mobile financial services

文档预览
中文文档 66 页 50 下载 1000 浏览 0 评论 309 收藏 3.0分
温馨提示:本文档共66页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
ISO TS 12812-2 2017 Core banking — Mobile financial services — Part 2  Security and data protection for mobile financial services 第 1 页 ISO TS 12812-2 2017 Core banking — Mobile financial services — Part 2  Security and data protection for mobile financial services 第 2 页 ISO TS 12812-2 2017 Core banking — Mobile financial services — Part 2  Security and data protection for mobile financial services 第 3 页
下载文档到电脑,方便使用
本文档由 人生无常 于 2024-08-26 08:45:34上传分享
友情链接
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。