Information technology — Security techniques — Catalogue of architectural and design principles for secure products, systems and applications

ISO/IEC TS 19249:2017 provides a catalogue of architectural and design principles that can be used in the development of secure products, systems and applications together with guidance on how to use those principles effectively. ISO/IEC TS 19249:2017 gives guidelines for the development of secure products, systems and applications including a more effective assessment with respect to the security properties they are supposed to implement. ISO/IEC TS 19249:2017 does not establish any requirements for the evaluation or the assessment process or implementation.

Technologies de l'information — Techniques de sécurité — Catalogue des principes architecturaux et conceptuels pour la sécurisation des produits, systèmes et applications

General Information

Status
Published
Publication Date
26-Oct-2017
Current Stage
9020 - International Standard under periodical review
Start Date
15-Apr-2024
Completion Date
15-Apr-2024
Ref Project

Relations

Buy Standard

Technical specification
ISO/IEC TS 19249:2017 - Information technology -- Security techniques -- Catalogue of architectural and design principles for secure products, systems and applications
English language
26 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)

TECHNICAL ISO/IEC TS
SPECIFICATION 19249
First edition
2017-10
Information technology — Security
techniques — Catalogue of
architectural and design principles
for secure products, systems and
applications
Technologies de l'information — Techniques de sécurité — Catalogue
des principes architecturaux et conceptuels pour la sécurisation des
produits, systèmes et applications
Reference number
ISO/IEC TS 19249:2017(E)
©
ISO/IEC 2017

---------------------- Page: 1 ----------------------
ISO/IEC TS 19249:2017(E)

COPYRIGHT PROTECTED DOCUMENT
© ISO/IEC 2017, Published in Switzerland
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form
or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior
written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of
the requester.
ISO copyright office
Ch. de Blandonnet 8 • CP 401
CH-1214 Vernier, Geneva, Switzerland
Tel. +41 22 749 01 11
Fax +41 22 749 09 47
copyright@iso.org
www.iso.org
ii © ISO/IEC 2017 – All rights reserved

---------------------- Page: 2 ----------------------
ISO/IEC TS 19249:2017(E)

Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Architectural principles for secure products, systems and applications .2
4.1 General . 2
4.2 Domain separation . 3
4.2.1 General. 3
4.2.2 Principles for defining domain structures . 3
4.2.3 Principles for defining inter-domain communication . 3
4.2.4 Security policies that may be enforced using domain separation. 4
4.2.5 Examples . 4
4.2.6 Considerations for evaluation . 4
4.3 Layering. 5
4.3.1 General. 5
4.3.2 Principles for defining layers . 5
4.3.3 Principles for Interfaces exposed by a layer . 5
4.3.4 Security policies that may be enforced using layering . 5
4.3.5 Examples . 6
4.3.6 Considerations for eva
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.