ISO 21188:2006 Preview

Public key infrastructure for financial services -- Practices and policy framework

ISO 21188:2006 sets out a framework of requirements to manage a PKI through certificate policies and certification practice statements and to enable the use of public key certificates in the financial services industry. It also defines control objectives and supporting procedures to manage risks.

ISO 21188:2006 draws a distinction between PKI systems used in open, closed and contractual environments. It further defines the operational practices relative to financial services industry accepted information systems control objectives. ISO 21188:2006 is intended to help implementers to define PKI practices that can support multiple certificate policies that include the use of digital signature, remote authentication and data encryption.

ISO 21188:2006 facilitates the implementation of operational, baseline PKI control practices that satisfy the requirements for the financial services industry in a contractual environment. While the focus of ISO 21188:2006 is on the contractual environment, application of this document to other environments is not specifically precluded. For the purposes of this document, the term "certificate" refers to public key certificates. Attribute certificates are outside the scope of ISO 21188:2006.


General information

  • Current status : Published
    Publication date : 2006-05
  • Edition : 1
    Number of pages : 107
  • :
    ISO/TC 68/SC 2
    Financial Services, security
  • 35.240.40
    IT applications in banking

Buy this standard

Format Language
PDF
Paper
  • CHF198

Got a question?

Check out our FAQs


Customer care
+41 22 749 08 88

Opening hours:
Monday to Friday - 09:00-12:00, 14:00-17:00 (UTC+1)

You may be interested in:

Keep up to date with ISO

Sign up to our newsletter for the latest news, views and product information