ISO 19092:2008
Financial services -- Biometrics -- Security framework
Media and price
| Language | Format | Add to basket |
|---|---|---|
| English | PDF (509 kB) | CHF 180,00 |
| English | Paper | CHF 180,00 |
General information
Number of Pages: 77
| Edition: 1 (Monolingual) | ICS: 03.060; 35.240.40 |
| Status: Published | Stage: 60.60 (2008-01-07) |
| TC/SC: TC 68/SC 2 |
Abstract
ISO 19092:2008 describes the security framework for using biometrics for authentication of individuals in financial services. It introduces the types of biometric technologies and addresses issues concerning their application. ISO 19092:2008 also describes the architectures for implementation, specifies the minimum security requirements for effective management, and provides control objectives and recommendations suitable for use by a professional practitioner.
The following are within the scope of ISO 19092:2008:
- usage of biometrics for the authentication of employees and persons seeking financial services by:
- verification of a claimed identity;
- identification of an individual;
- validation of credentials presented at enrolment to support authentication as required by risk management;
- management of biometric information across its life cycle comprised of the enrolment, transmission and storage, verification, identification and termination processes;
- security of biometric information during its life cycle, encompassing data integrity, origin authentication and confidentiality;
- application of biometrics for logical and physical access control;
- surveillance to protect the financial institution and its customers;
- security of the physical hardware used throughout the biometric information life cycle.
ISO 19092:2008 provides the mandatory means whereby biometric information may be encrypted for data confidentiality or other reasons.
Revision information
Revises: ISO 19092-1:2006
These standards could also interest you
-
ISO 15782-1:2009
Certificate management for financial services -- Part 1: Public key certificates -
ISO 13491-1:2007
Banking -- Secure cryptographic devices (retail) -- Part 1: Concepts, requirements and evaluation methods -
ISO 13492:2007
Financial services -- Key management related data element -- Application and usage of ISO 8583 data elements 53 and 96


