Space data and information transfer systems - Requirements for bodies providing audit and certification of candidate trustworthy digital repositories

This document defines a CCSDS Recommended Practice (and ISO standard) on which to base the operations of the organization(s) which assess the trustworthiness of digital repositories using the latest version of CCSDS 652.0/ISO 16363 (reference REF R_652x0m2AuditandCertificationofTrustwor \h[1] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00360035003200780030006D0032004100750064006900740061006E006400430065007200740069006600690063006100740069006F006E006F0066005400720075007300740077006F0072000000 ) and provide the appropriate certification. This document specifies requirements for bodies providing audit and certification of digital repositories, based on the metrics contained within ISO/IEC 17021-1 (reference REF R_ISOIEC170212011ConformityAssessmentReq \h \* MERGEFORMAT [4] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00490053004F0049004500430031003700300032003100320030003100310043006F006E0066006F0072006D006900740079004100730073006500730073006D0065006E0074005200650071000000 ) and reference REF R_652x0m2AuditandCertificationofTrustwor \h[1] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00360035003200780030006D0032004100750064006900740061006E006400430065007200740069006600690063006100740069006F006E006F0066005400720075007300740077006F0072000000 . It is primarily intended to support the accreditation of bodies providing such certification. ISO/IEC 17021-1 provides the bulk of the requirements on bodies offering audit and certification for general types of management systems. However, for each specific type of system, specific additional requirements will be needed, for example, to specify the standard against which the audit is to be made and the qualifications which auditors require. This document provides the (small number of) specific additions required for bodies providing audit and certification of candidate trustworthy digital repositories. Trustworthy here means that they can be trusted to maintain, over the long-term, the understandability and usability of digitally encoded information placed into their safekeeping. In order improve readability the section numbers are kept consistent with those of ISO/IEC 17021-1. Some subsections are applicable as they stand, and these are simply enumerated; otherwise additions to subsections are explicitly given. In the former case the sections may consist of just a few sentences. As a result this document must be read in conjunction with ISO/IEC 17021-1. The requirements contained in this CCSDS Recommended Practice need to be demonstrated in terms of competence and reliability by any organization or body providing certification of digital repositories.

Systèmes de transfert des informations et données spatiales — Exigences pour les organismes d'audit et de certification des référentiels numériques potentiellement de confiance

General Information

Status
Published
Publication Date
06-Mar-2025
Current Stage
6060 - International Standard published
Start Date
07-Mar-2025
Due Date
14-Jul-2025
Completion Date
07-Mar-2025
Ref Project

Relations

Overview

ISO 16919:2025 - "Space data and information transfer systems - Requirements for bodies providing audit and certification of candidate trustworthy digital repositories" defines the specific requirements for organizations that audit and certify digital repositories (candidate Trustworthy Digital Repositories, TDRs). Published as a CCSDS Recommended Practice and an ISO international standard (second edition, 2025), it is intended to be used together with ISO/IEC 17021-1 (requirements for bodies providing audit and certification) and CCSDS 652.0 / ISO 16363 (Audit and Certification of Trustworthy Digital Repositories). The standard specifies the additional, TDR‑specific additions needed for accreditation of certification bodies.

Key topics and technical requirements

  • Scope & purpose: Establishes how certification bodies demonstrate competence and reliability when certifying candidate TDRs against CCSDS/ISO metrics.
  • Conformance approach: Sections are aligned with ISO/IEC 17021-1; users must read both standards together.
  • Principles: Emphasizes impartiality, competence, responsibility, openness, confidentiality, and responsiveness to complaints.
  • Organizational requirements:
    • Legal and contractual matters, management of impartiality, liability and financing (Section 5).
    • Structural and resource requirements for certification bodies (Sections 6–7), including personnel competence, records, outsourcing and use of external auditors/technical experts.
  • Information & process requirements:
    • Public information, certification documents, use of marks, confidentiality, and client information exchange (Section 8).
    • Audit and certification process flows and management system requirements for certification bodies (Sections 9–10).
  • Competencies: Annex A (normative) lists required Trusted Digital Repository Management System (TDRMS) competencies for certification personnel.
  • Security & implementation notes: Annex B (informative) discusses security, SANA and patent considerations; Annex C covers audits by non-conformant bodies.
  • Updates in 2025 edition: Updated references (ISO 17021, ISO 16363, ISO 14721), structure alignment with ISO/IEC 17021-1, clarification on remote audits, and added CCSDS subsections.

Practical applications - who uses ISO 16919:2025

  • Accreditation bodies assessing certification bodies for TDR auditing competence.
  • Conformity assessment bodies / certification bodies setting up or operating TDR audit programs.
  • Digital repository managers and archivists seeking objective third‑party certification of long‑term preservation practices.
  • Auditors and technical experts who need guidance on required competencies and audit processes for TDRs.
  • Space agencies and data stewards responsible for preserving mission data and ensuring long‑term usability and understandability.

Related standards

  • ISO/IEC 17021-1 - Conformity assessment: requirements for bodies providing audit and certification of management systems.
  • ISO 16363 / CCSDS 652.0 - Audit and Certification of Trustworthy Digital Repositories (metrics and criteria).
  • ISO 14721 - OAIS (Open Archival Information System) Reference Model.

Keywords: ISO 16919:2025, trustworthy digital repository, audit and certification, CCSDS, ISO/IEC 17021-1, ISO 16363, OAIS, TDR competencies, repository certification.

Standard
ISO 16919:2025 - Space data and information transfer systems — Requirements for bodies providing audit and certification of candidate trustworthy digital repositories Released:7. 03. 2025
English language
23 pages
sale 15% off
Preview
sale 15% off
Preview

Frequently Asked Questions

ISO 16919:2025 is a standard published by the International Organization for Standardization (ISO). Its full title is "Space data and information transfer systems - Requirements for bodies providing audit and certification of candidate trustworthy digital repositories". This standard covers: This document defines a CCSDS Recommended Practice (and ISO standard) on which to base the operations of the organization(s) which assess the trustworthiness of digital repositories using the latest version of CCSDS 652.0/ISO 16363 (reference REF R_652x0m2AuditandCertificationofTrustwor \h[1] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00360035003200780030006D0032004100750064006900740061006E006400430065007200740069006600690063006100740069006F006E006F0066005400720075007300740077006F0072000000 ) and provide the appropriate certification. This document specifies requirements for bodies providing audit and certification of digital repositories, based on the metrics contained within ISO/IEC 17021-1 (reference REF R_ISOIEC170212011ConformityAssessmentReq \h \* MERGEFORMAT [4] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00490053004F0049004500430031003700300032003100320030003100310043006F006E0066006F0072006D006900740079004100730073006500730073006D0065006E0074005200650071000000 ) and reference REF R_652x0m2AuditandCertificationofTrustwor \h[1] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00360035003200780030006D0032004100750064006900740061006E006400430065007200740069006600690063006100740069006F006E006F0066005400720075007300740077006F0072000000 . It is primarily intended to support the accreditation of bodies providing such certification. ISO/IEC 17021-1 provides the bulk of the requirements on bodies offering audit and certification for general types of management systems. However, for each specific type of system, specific additional requirements will be needed, for example, to specify the standard against which the audit is to be made and the qualifications which auditors require. This document provides the (small number of) specific additions required for bodies providing audit and certification of candidate trustworthy digital repositories. Trustworthy here means that they can be trusted to maintain, over the long-term, the understandability and usability of digitally encoded information placed into their safekeeping. In order improve readability the section numbers are kept consistent with those of ISO/IEC 17021-1. Some subsections are applicable as they stand, and these are simply enumerated; otherwise additions to subsections are explicitly given. In the former case the sections may consist of just a few sentences. As a result this document must be read in conjunction with ISO/IEC 17021-1. The requirements contained in this CCSDS Recommended Practice need to be demonstrated in terms of competence and reliability by any organization or body providing certification of digital repositories.

This document defines a CCSDS Recommended Practice (and ISO standard) on which to base the operations of the organization(s) which assess the trustworthiness of digital repositories using the latest version of CCSDS 652.0/ISO 16363 (reference REF R_652x0m2AuditandCertificationofTrustwor \h[1] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00360035003200780030006D0032004100750064006900740061006E006400430065007200740069006600690063006100740069006F006E006F0066005400720075007300740077006F0072000000 ) and provide the appropriate certification. This document specifies requirements for bodies providing audit and certification of digital repositories, based on the metrics contained within ISO/IEC 17021-1 (reference REF R_ISOIEC170212011ConformityAssessmentReq \h \* MERGEFORMAT [4] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00490053004F0049004500430031003700300032003100320030003100310043006F006E0066006F0072006D006900740079004100730073006500730073006D0065006E0074005200650071000000 ) and reference REF R_652x0m2AuditandCertificationofTrustwor \h[1] 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000002900000052005F00360035003200780030006D0032004100750064006900740061006E006400430065007200740069006600690063006100740069006F006E006F0066005400720075007300740077006F0072000000 . It is primarily intended to support the accreditation of bodies providing such certification. ISO/IEC 17021-1 provides the bulk of the requirements on bodies offering audit and certification for general types of management systems. However, for each specific type of system, specific additional requirements will be needed, for example, to specify the standard against which the audit is to be made and the qualifications which auditors require. This document provides the (small number of) specific additions required for bodies providing audit and certification of candidate trustworthy digital repositories. Trustworthy here means that they can be trusted to maintain, over the long-term, the understandability and usability of digitally encoded information placed into their safekeeping. In order improve readability the section numbers are kept consistent with those of ISO/IEC 17021-1. Some subsections are applicable as they stand, and these are simply enumerated; otherwise additions to subsections are explicitly given. In the former case the sections may consist of just a few sentences. As a result this document must be read in conjunction with ISO/IEC 17021-1. The requirements contained in this CCSDS Recommended Practice need to be demonstrated in terms of competence and reliability by any organization or body providing certification of digital repositories.

ISO 16919:2025 is classified under the following ICS (International Classification for Standards) categories: 03.120.20 - Product and company certification. Conformity assessment; 49.140 - Space systems and operations. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO 16919:2025 has the following relationships with other standards: It is inter standard links to ISO 16919:2014. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

You can purchase ISO 16919:2025 directly from iTeh Standards. The document is available in PDF format and is delivered instantly after payment. Add the standard to your cart and complete the secure checkout process. iTeh Standards is an authorized distributor of ISO standards.

Standards Content (Sample)


International
Standard
ISO 16919
Second edition
Space data and information transfer
2025-03
systems — Requirements for bodies
providing audit and certification
of candidate trustworthy digital
repositories
Systèmes de transfert des informations et données spatiales —
Exigences pour les organismes d'audit et de certification des
référentiels numériques potentiellement de confiance
Reference number
© ISO 2025
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national
standards bodies (ISO member bodies). The work of preparing International Standards is
normally carried out through ISO technical committees. Each member body interested in a
subject for which a technical committee has been established has the right to be represented on
that committee. International organizations, governmental and non-governmental, in liaison
with ISO, also take part in the work. ISO collaborates closely with the International
Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance
are described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria
needed for the different types of ISO document should be noted (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO takes no position concerning the evidence, validity or applicability of
any claimed patent rights in respect thereof. As of the date of publication of this document, ISO
had not received notice of (a) patent(s) which may be required to implement this document.
However, implementers are cautioned that this may not represent the latest information, which
may be obtained from the patent database available at www.iso.org/patents. ISO shall not be
held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and
does not constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms
and expressions related to conformity assessment, as well as information about ISO's adherence
to the World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT), see
www.iso.org/iso/foreword.html.
This document was prepared by the Consultative Committee for Space Data Systems (CCSDS)
(as CCSDS 652.1-M-3, December 2024) and drafted in accordance with its editorial rules. It was
assigned to Technical Committee ISO/TC 20, Aircraft and space vehicles, Subcommittee SC 13,
Space data and information transfer systems and adopted under the “fast-track procedure”.
This second edition cancels and replaces the first edition (ISO 16919:2014), which has been
technically revised.
The main changes are as follows:
— updated references to latest versions of documents, ISO 17021:2015, ISO 16363 and ISO 14721;
— updated to be consistent with the structure of the latest version of ISO 17021-1, for example,
removal of section 8.3 Directory of Certified Clients;
— clarified use of remotes audits in Section 9;
— added CCSDS required subsections in Annex B.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html.
CCSDS 652.1-M-3 Page iii December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
CONTENTS
Section Page
1 INTRODUCTION . 1-1

1.1 PURPOSE . 1-1
1.2 SCOPE . 1-1
1.3 APPLICABILITY . 1-1
1.4 RATIONALE . 1-2
1.5 STRUCTURE OF THIS DOCUMENT . 1-2
1.6 DEFINITIONS . 1-3
1.7 CONFORMANCE . 1-4
1.8 REFERENCES . 1-4

2 OVERVIEW . 2-1

3 RESERVED . 3-1

4 PRINCIPLES . 4-1

5 GENERAL REQUIREMENTS . 5-1

5.1 LEGAL AND CONTRACTUAL MATTERS. 5-1
5.2 MANAGEMENT OF IMPARTIALITY . 5-1
5.3 LIABILITY AND FINANCING . 5-1

6 STRUCTURAL REQUIREMENTS . 6-1

7 RESOURCE REQUIREMENTS . 7-1

7.1 COMPETENCE OF PERSONNEL . 7-1
7.2 PERSONNEL INVOLVED IN THE CERTIFICATION ACTIVITIES . 7-1
7.3 USE OF INDIVIDUAL EXTERNAL AUDITORS AND EXTERNAL
TECHNICAL EXPERTS . 7-1
7.4 PERSONNEL RECORDS . 7-2
7.5 OUTSOURCING . 7-2

8 INFORMATION REQUIREMENTS . 8-1

8.1 PUBLIC INFORMATION . 8-1
8.2 CERTIFICATION DOCUMENTS . 8-1
8.3 REFERENCE TO CERTIFICATION AND USE OF MARKS . 8-1
8.4 CONFIDENTIALITY . 8-1
8.5 INFORMATION EXCHANGE BETWEEN A CERTIFICATION BODY AND
ITS CLIENTS . 8-1
CCSDS 652.1-M-3 Page iv December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
CONTENTS (continued)
Section Page
9 PROCESS REQUIREMENTS. 9-1

10 MANAGEMENT SYSTEM REQUIREMENTS FOR
CERTIFICATION BODIES . 10-1

ANNEX A REQUIRED TRUSTED DIGITAL REPOSITORY
MANAGEMENT SYSTEM (TDRMS) COMPETENCIES
(NORMATIVE) . A-1
ANNEX B SECURITY, SANA, AND PATENT CONSIDERATIONS
(INFORMATIVE) . B-1
ANNEX C AUDIT BY NON-CONFORMANT BODIES (INFORMATIVE) . C-1

CCSDS 652.1-M-3 Page v December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
1 INTRODUCTION
1.1 PURPOSE
The main purpose of this document is to define a CCSDS Recommended Practice (and ISO
standard) on which to base the operations of the organization(s) which assess the
trustworthiness of digital repositories using the latest version of CCSDS 652.0/ISO 16363
(reference [1]) and provide the appropriate certification. This document specifies
requirements for bodies providing audit and certification of digital repositories, based on the
metrics contained within ISO/IEC 17021-1 (reference [4]) and reference [1]. It is primarily
intended to support the accreditation of bodies providing such certification.
ISO/IEC 17021-1 provides the bulk of the requirements on bodies offering audit and
certification for general types of management systems. However, for each specific type of
system, specific additional requirements will be needed, for example, to specify the standard
against which the audit is to be made and the qualifications which auditors require.
This document provides the (small number of) specific additions required for bodies
providing audit and certification of candidate trustworthy digital repositories. Trustworthy
here means that they can be trusted to maintain, over the long-term, the understandability and
usability of digitally encoded information placed into their safekeeping.
In order improve readability the section numbers are kept consistent with those of ISO/IEC
17021-1. Some subsections are applicable as they stand, and these are simply enumerated;
otherwise additions to subsections are explicitly given. In the former case the sections may
consist of just a few sentences. As a result this document must be read in conjunction with
ISO/IEC 17021-1.
1.2 SCOPE
The requirements contained in this CCSDS Recommended Practice need to be demonstrated
in terms of competence and reliability by any organization or body providing certification of
digital repositories.
1.3 APPLICABILITY
This document is meant primarily for those setting up and managing the organization
performing the auditing and certification of digital repositories.
It should also be of use to those who work in or are responsible for digital repositories
seeking objective measurement of the trustworthiness of their repository and wishing to
understand the processes involved.
CCSDS 652.1-M-3 Page 1-1 December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
1.4 RATIONALE
There is a hierarchy of standards concerned with good auditing practice (references [3]-[5]).
This document is positioned within this hierarchy in order to ensure that these good practices
can be applied to the evaluation of the trustworthiness of digital repositories.
ISO/IEC 17021-1 Conformity assessment — Requirements for bodies providing audit and
certification of management systems (reference [5]) is an International Standard which sets
out criteria for bodies operating audit and certification of organizations’ management
systems. If such bodies are to be accredited as complying with ISO/IEC 17021-1 with the
objective of auditing and certifying candidate trustworthy digital repositories in accordance
with reference [1], some requirements that are additional to ISO/IEC 17021-1 are necessary.
These are provided by this document.
The text in sections 4 to 10 in this document follows the structure of ISO/IEC 17021-1, with
specific additions on the application of ISO/IEC 17021-1 for certification of candidate
trustworthy digital repositories.
1.5 STRUCTURE OF THIS DOCUMENT
This document is divided into informative and normative sections and annexes.
Sections 1-2 of this document give a high-level view of the rationale, the conceptual
environment, some of the important design issues and an introduction to the terminology and
concepts.
– Section 1 gives purpose and scope, rationale, a view of the overall document
structure, and the acronym list, glossary, and reference list for this document. These
are normative.
– Section 2 provides an overview of auditing practices. This is informative.
– Section 3 is reserved for future use.
– Section 4 states the principles that apply.
– Sections 5 to 10 provide the normative rules against which an organization providing
audit and certification of candidate trustworthy digital repositories may be judged,
based on ISO/IEC 17021-1 (reference [4]).
– Annex A specifies the trusted digital repository management system competencies for
certification body personnel for specific certification functions.
– Annex B is a CCSDS-required informative discussion of the security implications of
applying this CCSDS Recommended Practice.
CCSDS 652.1-M-3 Page 1-2 December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
1.6 DEFINITIONS
1.6.1 ACRONYMS AND ABBREVIATIONS
CAB conformity assessment body
CCSDS Consultative Committee for Space Data Systems
IEC International Electrotechnical Commission
ISO International Organization for Standardization
OAIS Open Archival Information System
TDR Trustworthy Digital Repository
TDRMS Trustworthy Digital Repository management system
SANA Space Assigned Numbers Authority
1.6.2 TERMINOLOGY
1.6.2.1 General
Digital preservation interests a range of different communities, each with a distinct
vocabulary and local definitions for key terms. A glossary is included in this document, but it
is important to draw attention to the usage of several key terms.
In general, key terms in this document have been adopted from the Open Archival
Information System (OAIS) Reference Model (reference [2]). One of the great strengths of
the OAIS Reference Model has been to provide a common terminology made up of terms
‘not already overloaded with meaning so as to reduce conveying unintended meanings’.
Because the OAIS has become a foundational document for digital preservation, the common
terms are well understood and are therefore used within this document.
The OAIS Reference Model uses ‘digital archive’ to mean the organization responsible for
digital preservation. In this document, the term ‘repository’ or phrase ‘digital repository’ is
used to convey the same concept in all instances except when quoting from the OAIS, and is
used to denote any type of digital repository; it may be a Trustworthy Digital Repository
(TDR), a candidate TDR, a lapsed TDR, or one not seeking certification. It is important to
understand that in all instances in this document, ‘repository’ and ‘digital repository’ are used
to convey digital repositories and archives that have, or contribute to, long-term preservation
responsibilities and functionality.
1.6.2.2 Glossary
For the purposes of this document, the terms and definitions given in ISO/IEC 17021-1
(reference [4]), references [1], [2], and [3], and the following apply.
Trustworthy Digital Repository, TDR: A repository which has a current certification.
CCSDS 652.1-M-3 Page 1-3 December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
1.6.3 NOMENCLATURE
The following conventions apply throughout this Recommended Practice:
a) the words ‘shall’ and ‘must’ imply a binding and verifiable specification;
b) the word ‘should’ implies an optional, but desirable, specification;
c) the word ‘may’ implies an optional specification;
d) the words ‘is’, ‘are’, and ‘will’ imply statements of fact.
1.7 CONFORMANCE
An organization which provides audit and certification for TDRs conforms to this
recommended practice if it fulfils all the binding and verifiable specifications in this document.
1.8 REFERENCES
The following publications contain provisions which, through reference in this text,
constitute provisions of this document. At the time of publication, the editions indicated
were valid. All publications are subject to revision, and users of this document are
encouraged to investigate the possibility of applying the most recent editions of the
publications indicated below. The CCSDS Secretariat maintains a register of currently valid
CCSDS publications.
[1] Audit and Certification of Trustworthy Digital Repositories. Issue 2. Recommendation
for Space Data System Practices (Magenta Book), CCSDS 652.0-M-2. Washington,
D.C.: CCSDS, December 2024 or later. [Equivalent to ISO 16363:2012 or later]
[2] Reference Model for an Open Archival Information System (OAIS). Issue 3.
Recommendation for Space Data System Practices (Magenta Book), CCSDS 650.0-M-
3. Washington, D.C.: CCSDS, December 2024 or later. [Equivalent to ISO 14721:2012
or later]
[3] Quality Management Systems—Fundamentals and Vocabulary. 4th ed. International
Standard, ISO 9000:2015. Geneva: ISO, 2015.
[4] Conformity Assessment—Requirements for Bodies Providing Audit and Certification of
Management Systems—Part 1: Requirements. International Standard, ISO/IEC 17021-
1:2015. Geneva: ISO, 2015.
[5] Conformity Assessment—Vocabulary and General Principles. 2nd ed. International
Standard, ISO/IEC 17000:2020. Geneva: ISO, 2020.
CCSDS 652.1-M-3 Page 1-4 December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
2 OVERVIEW
This document addresses issues arising from applying good audit practice to auditing and
certifying whether and to what extent digital repositories can be trusted to look after digitally
encoded information for the long-term, or at least for the period of their custodianship of that
digitally encoded information.
It covers principles needed to inspire confidence that third party certification of the
management of the digital repository has been performed with
– impartiality,
– competence,
– responsibility,
– openness,
– confidentiality, and
– responsiveness to complaints.
This document specifies the ways of ensuring that the body providing such third party
certification can inspire this confidence. It does this by building on the more general
specifications of references [3]-[5].
Section 5 deals with the legal aspects and guarantees of impartiality and avoidance of
conflicts of interest.
The structure and management of the organization is specified in section 6, which is
supported by the competences of the management and personnel, specified in section 7.
Section 8 sets out how the information about which organizations have been certified is made
available.
The requirements in the procedures for defining the scope and performance of the audit, the
initial certification decision, and the ways in which that certification may be confirmed,
reduced in scope, suspended, or withdrawn are given in section 9. This section also specifies
how complaints are dealt with.
The management system of the auditing body itself is specified in section 10.

CCSDS 652.1-M-3 Page 2-1 December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
3 RESERVED
This section is reserved for future use.

CCSDS 652.1-M-3 Page 3-1 December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
4 PRINCIPLES
The principles from ISO/IEC 17021-1:2015, Clause 4 apply.
The term ‘management system’ used in ISO/IEC 17021-1 shall be replaced by ‘trusted digital
repository management system’ in the context of this document.
The following notes are added:
– The organization shall determine whether climate change is a relevant issue.
– Relevant interested parties can have requirements related to climate change.

CCSDS 652.1-M-3 Page 4-1 December 2024
REQUIREMENTS FOR BODIES PROVIDING AUDIT AND CERTIFICATION
OF CANDIDATE TRUSTWORTHY DIGITAL REPOSITORIES
5 GENERAL REQUIREMENTS
5.1 LEGAL AND CONTRACTUAL MATTERS
All the requirements from ISO/IEC 17021-1:2015, Clause 5.1 apply.
5.2 MANAGEMENT OF IMPARTIALITY
5.2.1 GENERAL
The requirements from ISO/IEC 17021-1:2015, Clause 5.2 apply. In addition, the following
TDR audit and certification specific requirements and guidance apply.
5.2.2 CONFLICTS OF INTEREST
Members of certification bodies can carry out the following duties without their being
considered as consultancy or having a potential conflict of interest:
a) arranging and participating as a l
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.

Loading comments...

ISO 16919:2025は、信頼できるデジタルリポジトリの監査と認証を提供する機関に対する要件を定義した文書であり、CCSDSの推奨手法に基づいています。この標準は、デジタルリポジトリの信頼性を評価するための重要な指針を提供しており、ISO/IEC 17021-1の基準に従って、各種管理システムの監査と認証を行う機関向けの要件が盛り込まれています。 この文書の強みは、その明確な範囲と業界での関連性にあります。特に、デジタル情報の長期的な理解可能性と使用可能性を維持することができる信頼性のあるリポジトリの確保を目的としている点が評価されます。標準には、監査を実施するための具体的な項目が示されており、それぞれの機関が適切な認証を行うために必要な基準が整えられています。 また、ISO 16919:2025は、読みやすさを考慮して、ISO/IEC 17021-1の章番号と整合性を持たせています。この工夫により、利用者が必要な情報を素早く見つけやすくなり、効率的に標準を使用できるようになっています。さらに、文書内の必要な要素については、明示的に追加要件として示されているため、各機関は自組織の特定のニーズに応じて、監査と認証の質を向上させることが可能です。 この標準が持つ重要性は、デジタルリポジトリの監査と認証において、信頼性と能力の証明を求める組織にとって不可欠であることを示しています。信頼性のあるデジタルリポジトリの確保は、デジタル情報の管理や保存における課題を克服するための鍵となるため、ISO 16919:2025の適用はますます重要性を増しています。

Die Norm ISO 16919:2025 bietet eine umfassende Grundlage für die Auditierung und Zertifizierung von vertrauenswürdigen digitalen Repositorien. Ihr Anwendungsbereich ist klar definiert und fokussiert sich auf Organisationen, die die Vertrauenswürdigkeit digitaler Repositorien bewerten und entsprechend zertifizieren. Die Norm fungiert als CCSDS empfohlene Praxis sowie als ISO-Norm, was ihre Relevanz und Akzeptanz in der Branche unterstreicht. Eine der stärksten Eigenschaften dieser Norm ist die Verbindung zu ISO/IEC 17021-1, die als Basis für die Anforderungen an die auditierenden und zertifizierenden Stellen dient. Dies gewährleistet, dass die Norm sowohl allgemein anwendbare als auch spezifische Anforderungen für digitale Repositorien abdeckt. Dadurch wird eine klare Richtlinie für Auditoren etabliert, um die Qualifikationen zu definieren, die erforderlich sind, um die Vertrauenswürdigkeit von digitalen Repositorien zu bewerten und zu bescheinigen. Ein weiterer Pluspunkt ist die Beibehaltung konsistenter Abschnittsnummern mit ISO/IEC 17021-1, was die Lesbarkeit und das Verständnis der Norm erhöht. Die Norm hebt hervor, dass vertrauenswürdige digitale Repositorien in der Lage sind, die Verständlichkeit und Benutzbarkeit der dort gespeicherten, digital codierten Informationen langfristig zu gewährleisten. Dies ist besonders wichtig in einer Zeit, in der die Verwaltung von digitalen Informationen in zunehmend komplexen Umgebungen stattfindet. Die spezifischen Ergänzungen, die für die Auditierung und Zertifizierung dieser Repositorien erforderlich sind, sind gut strukturiert und ermöglichen eine einfache Integration der Norm in bestehende Audit- und Zertifizierungsprozesse. Zusammenfassend lässt sich sagen, dass ISO 16919:2025 von erheblicher Bedeutung ist, um die Integrität und Zuverlässigkeit von digitalen Repositorien sicherzustellen, indem sie klare Anforderungen für Auditoren und Zertifizierungsstellen bereitstellt. Die Norm ist ein essenzieller Rahmen für alle Organisationen, die sich mit der Langzeitarchivierung und der Verantwortlichkeit für digitale Inhalte beschäftigen.

Le document ISO 16919:2025 établit une norme cruciale pour les systèmes de transfert de données et d'informations spatiales, en définissant les exigences pour les organismes fournissant des audits et des certifications de dépôts numériques fiables. Cette norme est basée sur la pratique recommandée CCSDS et joue un rôle significatif dans l'assurance de la confiance envers les dépôts numériques, notamment ceux qui préservent des informations encodées numériquement sur le long terme. L'un des points forts de cette norme est sa capacité à s'intégrer avec les exigences d'ISO/IEC 17021-1, fournissant ainsi un cadre solide pour l'évaluation de la conformité des organismes. Cela permet de garantir que les critères d'audit et de certification des dépôts numériques reposent sur des fondations bien établies, favorisant la crédibilité des évaluations menées par les organismes accrédités. En détaillant les exigences spécifiques pour les auditeurs et en spécifiant la norme applicable, ISO 16919:2025 renforce la rigueur et la précision des processus d'audit et de certification. La pertinence de cette norme dans le contexte actuel est indéniable, car la gestion des dépôts numériques devient de plus en plus essentielle à mesure que les institutions et les organisations s'appuient fortement sur ces systèmes pour la conservation des données. Sa capacité à assurer la maintenabilité, l'intelligibilité et l'utilisabilité des informations numériques fait d'ISO 16919:2025 un document incontournable pour toute organisation impliquée dans la certification de dépôts numériques. Enfin, la structure du document, qui maintient une correspondance avec les sections d'ISO/IEC 17021-1, améliore sa lisibilité et facilite sa mise en œuvre par les organismes concernés. En somme, cette norme est un outil fondamental pour établir et maintenir la confiance dans les dépôts numériques, garantissant que ceux-ci répondent aux exigences de compétence et de fiabilité nécessaires à leur certification.

ISO 16919:2025 serves as a pivotal standard in the realm of space data and information transfer systems, specifically focusing on the requirements for organizations tasked with auditing and certifying candidate trustworthy digital repositories. The scope of this document is aptly designed to support the accreditation of bodies involved in such critical tasks, emphasizing the necessity of maintaining the trustworthiness of digital repositories over the long term. One of the stand-out strengths of ISO 16919:2025 lies in its detailed alignment with existing frameworks, particularly referencing CCSDS 652.0 and ISO 16363. By incorporating the latest practices established by these documents, the standard enhances its relevance for organizations aiming to ensure that digital information remains understandable and usable for future stakeholders. This dual emphasis on adherence to established protocols and the introduction of specific requirements for trustworthy digital repository certification indicates a comprehensive approach to maintaining data integrity. Additionally, the standard underscores the importance of competency and reliability for bodies providing certification. This focus not only elevates the benchmark for digital repository evaluation but also encourages organizations to demonstrate their own qualifications through rigorous adherence to ISO/IEC 17021-1. The well-structured layout of ISO 16919:2025, which maintains consistent section numbering with ISO/IEC 17021-1, further facilitates its use and understanding, making it easier for organizations to implement its requirements alongside established practices. The inclusion of specific additions tailored for trustworthy digital repositories showcases the forward-thinking nature of ISO 16919:2025, acknowledging that general auditing standards may require modifications to address the unique challenges associated with digital information stewardship. This thoughtful customization strengthens the standard’s applicability and effectiveness in ensuring that digital repositories are not only certified but are also equipped to handle the nuances of digital data retention. Overall, the scope, strengths, and relevance of ISO 16919:2025 collectively reinforce its position as a critical tool for enhancing the trustworthiness of digital repositories, ultimately contributing to the preservation of valuable data in the context of space data and information transfer systems.

ISO 16919:2025는 디지털 저장소의 신뢰성 평가 및 인증을 제공하는 기관에 대한 요구사항을 정의한 표준으로, CCSDS 권장 관행을 기반으로 하여 디지털 정보의 안전한 유지 및 장기적 사용 가능성을 보장합니다. 이 표준은 ISO/IEC 17021-1을 참조하여, 각각의 관리 시스템 유형에 대한 특정 요구사항을 명확히 하며, 디지털 저장소의 감사 및 인증을 수행하는 기관에 대한 요구사항을 구체적으로 명시하고 있습니다. 이 문서는 신뢰할 수 있는 디지털 저장소의 감사를 위한 소수의 특정 추가 요구사항을 제공하여 중요성이 높은 신뢰성 평가를 가능하게 합니다. 신뢰성 있는 저장소란 디지털 정보의 이해 가능성과 사용 가능성을 장기간 유지할 수 있는 기관을 의미하며, 이러한 신뢰성을 보장하는 기관은 엄격한 기준을 준수해야 합니다. ISO 16919:2025의 강점 중 하나는 ISO/IEC 17021-1의 섹션 번호와 일관성을 유지하여, 사용자들이 쉽게 참조할 수 있도록 구성되어 있다는 점입니다. 특정 하위 섹션은 그대로 적용 가능하며, 필요한 추가 사항이 명확하게 제시되어 있어 문서의 가독성을 높이고 있습니다. 또한, 디지털 저장소 인증을 제공하는 기관의 적격성과 신뢰성을 입증해야 하는 요구사항이 포함되어 있어, 궁극적으로 높은 표준을 충족하는 인증 제공을 위한 기초를 마련합니다. 결론적으로, ISO 16919:2025는 디지털 저장소 인증의 필수적인 요구사항을 종합적으로 전달하며, 디지털 정보의 장기적인 보존과 접근성을 보장하기 위한 중요한 기준으로 활용될 수 있습니다. 이 표준은 디지털 저장소의 신뢰성과 무결성을 보장하는 데 필수적인 역할을 수행하여, 관련 기관들이 보다 효과적으로 감사 및 인증 작업을 수행할 수 있도록 지원합니다.