Information technology — Open Trusted Technology ProviderTM Standard (O-TTPS) — Part 1: Requirements and recommendations for mitigating maliciously tainted and counterfeit products

ISO/IEC 20243-1:2018 (O-TTPS) is a set of guidelines, requirements, and recommendations that address specific threats to the integrity of hardware and software COTS ICT products throughout the product life cycle. This release of the Standard addresses threats related to maliciously tainted and counterfeit products. The provider's product life cycle includes the work it does designing and developing products, as well as the supply chain aspects of that life cycle, collectively extending through the following phases: design, sourcing, build, fulfillment, distribution, sustainment, and disposal. While this Standard cannot fully address threats that originate wholly outside any span of control of the provider ? for example, a counterfeiter producing a fake printed circuit board assembly that has no original linkage to the Original Equipment Manufacturer (OEM) ? the practices detailed in the Standard will provide some level of mitigation. An example of such a practice would be the use of security labeling techniques in legitimate products.

Titre manque — Partie 1: Titre manque

General Information

Status
Published
Publication Date
23-Nov-2023
Current Stage
6060 - International Standard published
Start Date
24-Nov-2023
Due Date
11-Jan-2025
Completion Date
24-Nov-2023
Ref Project

Relations

Buy Standard

Standard
ISO/IEC 20243-1:2023 - Information technology — Open Trusted Technology ProviderTM Standard (O-TTPS) — Part 1: Requirements and recommendations for mitigating maliciously tainted and counterfeit products Released:24. 11. 2023
English language
31 pages
sale 15% off
Preview
sale 15% off
Preview
Draft
ISO/IEC PRF 20243-1 - Information technology — Open Trusted Technology ProviderTM Standard (O-TTPS) — Part 1: Requirements and recommendations for mitigating maliciously tainted and counterfeit products Released:11. 10. 2023
English language
31 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)

INTERNATIONAL ISO/IEC
STANDARD 20243-1
Second edition
2023-11
Information technology — Open
TM
Trusted Technology Provider
Standard (O-TTPS) —
Part 1:
Requirements and recommendations
for mitigating maliciously tainted and
counterfeit products
Reference number
ISO/IEC 20243-1:2023(E)
© ISO/IEC 2023

---------------------- Page: 1 ----------------------
ISO/IEC 20243-1:2023(E)
COPYRIGHT PROTECTED DOCUMENT
© ISO/IEC 2023
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
  © ISO/IEC 2023 – All rights reserved

---------------------- Page: 2 ----------------------
ISO/IEC 20243-1:2023(E)
Contents Page
Foreword . iv
Preface . vi
Trademarks . viii
Introduction . ix
1 Scope . 1
1.1 Conformance . 2
1.2 Future Directions . 2
2 Normative references . 2
3 Terms and definitions . 2
4 Business Context and Overview. 9
4.1 Business Environment Summary . 9
4.1.1 Operational Scenario . 9
4.2 Business Rationale . 11
4.2.1 Business Drivers . 11
4.2.2 Objectives and Benefits . 12
4.3 Recognizing the COTS ICT Context . 13
4.4 Overview . 14
4.4.1 O-TTPF Overview . 14
4.4.2 O-TTPS Overview . 15
4.4.3 Relationship with Other Standards . 15
5 O-TTPS – Tainted and Counterfeit Risks . 16
6 O-TTPS – Requirements for Addressing the Risks of Tainted and Counterfeit Products . 17
6.1 Technology Development . 18
6.1.1 PD: Product Development
...

INTERNATIONAL ISO/IEC
STANDARD 20243-1
Second edition
2023-10
Information technology — Open
Trusted Technology ProviderTM
Standard (O-TTPS) —
Part 1:
Requirements and recommendations
for mitigating maliciously tainted and
counterfeit products
PROOF/ÉPREUVE
Reference number
ISO/IEC 20243-1:2023(E)
© ISO/IEC 2023

---------------------- Page: 1 ----------------------
ISO/IEC 20243-1:2023(E)
COPYRIGHT PROTECTED DOCUMENT
© ISO/IEC 2023
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
PROOF/ÉPREUVE © ISO/IEC 2023 – All rights reserved

---------------------- Page: 2 ----------------------
ISO/IEC 20243-1:2023(E)
Contents Page
Foreword . iv
Preface . vi
Trademarks . viii
Introduction . ix
1 Scope . 1
1.1 Conformance . 2
1.2 Future Directions . 2
2 Normative references . 2
3 Terms and definitions . 2
4 Business Context and Overview. 9
4.1 Business Environment Summary . 9
4.1.1 Operational Scenario . 9
4.2 Business Rationale . 11
4.2.1 Business Drivers . 11
4.2.2 Objectives and Benefits . 12
4.3 Recognizing the COTS ICT Context . 13
4.4 Overview . 14
4.4.1 O-TTPF Overview . 14
4.4.2 O-TTPS Overview . 15
4.4.3 Relationship with Other Standards . 15
5 O-TTPS – Tainted and Counterfeit Risks . 16
6 O-TTPS – Requirements for Addressing the Risks of Tainted and Counterfeit Products . 17
6.1 Technology Development . 18
6.1.
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.