Vážení zákazníci, v letošním roce budeme expedovat poslední objednávky ve středu 18. 12. 2024.

Těšíme se s vámi na shledanou od pondělí 06. 01. 2025.

 

Menu
0
Total price
0 €
PRICES include / exclude VAT
Homepage>BS ISO 23195:2021 Security objectives of information systems of third-party payment services
Sponsored link
sklademVydáno: 2021-06-15
BS ISO 23195:2021 Security objectives of information systems of third-party payment services

BS ISO 23195:2021

Security objectives of information systems of third-party payment services

Format
Availability
Price and currency
Anglicky Secure PDF
Immediate download
357.95 €
You can read the standard for 1 hour. More information in the category: E-reading
Reading the standard
for 1 hour
35.80 €
You can read the standard for 24 hours. More information in the category: E-reading
Reading the standard
for 24 hours
107.39 €
Anglicky Hardcopy
In stock
357.95 €
Označení normy:BS ISO 23195:2021
Počet stran:50
Vydáno:2021-06-15
ISBN:978 0 539 02106 6
Status:Standard
DESCRIPTION

BS ISO 23195:2021


This standard BS ISO 23195:2021 Security objectives of information systems of third-party payment services is classified in these ICS categories:
  • 03.060 Finances. Banking. Monetary systems. Insurance
  • 35.240.40 IT applications in banking

This document defines a common terminology to be used in the context of third-party payment (TPP). Next, it establishes two logical structural models in which the assets to be protected are clarified. Finally, it specifies security objectives based on the analysis of the logical structural models and the interaction of the assets affected by threats, organizational security policies and assumptions. These security objectives are set out in order to counter the threats resulting from the intermediary nature of TPPSPs offering payment services compared with simpler payment models where the payer and the payee directly interact with their respective account servicing payment service provider (ASPSP).

This document assumes that TPP-centric payments rely on the use of TPPSP credentials and the corresponding certified processes for issuance, distribution and renewal purposes. However, security objectives for such processes are out of the scope of this document.

NOTE

This document is based on the methodology specified in the ISO/IEC 15408 series. Therefore, the security matters that do not belong to the TOE are dealt with as assumptions, such as the security required by an information system that provides TPP services and the security of communication channels between the entities participating in a TPP business.