ISO 19092:2023
Financial services — Biometrics — Security framework

Standard No.
ISO 19092:2023
Release Date
2023
Published By
International Organization for Standardization (ISO)
Latest
ISO 19092:2023
Scope
This document specifies the security framework for using biometrics for authentication of customers in financial services, focusing exclusively on retail payments. It introduces the most common types of biometric technologies and addresses issues concerning their application. This document also describes representative architectures for the implementation of biometric authentication and associated minimum control objectives. The following are within the scope of this document: — use of biometrics for the purpose of: — verification of a claimed identity; — identification of an individual; — biometric authentication threats, vulnerabilities and controls; — validation of credentials presented at enrolment to support authentication; — management of biometric information across its life cycle, comprising enrolment, transmission and storage, verification, identification and termination processes; — security requirements for hardware used in conjunction with biometric capture and biometric data processing; — biometric authentication architectures and associated security requirements. The following are not within the scope of this document: — detailed specifications for data collection, feature extraction and comparison of biometric data and the biometric decision-making process; — use of biometric technology for non-financial transaction applications, such as physical or logical system access control.

ISO 19092:2023 Referenced Document

  • ISO 11568 Financial services — Key management (retail)
  • ISO 13491-1 Financial services - Secure cryptographic devices (retail) - Part 1: Concepts, requirements and evaluation methods
  • ISO 13491-2 Financial services — Secure cryptographic devices (retail) — Part 2: Security compliance checklists for devices used in financial transactions
  • ISO/IEC 15408-3 Information security, cybersecurity and privacy protection — Evaluation criteria for IT security — Part 3: Security assurance components
  • ISO/IEC 19772 Information security -- Authenticated encryption

ISO 19092:2023 history

  • 2023 ISO 19092:2023 Financial services — Biometrics — Security framework
  • 2008 ISO 19092:2008 Financial services - Biometrics - Security framework
Financial services — Biometrics — Security framework



Copyright ©2024 All Rights Reserved