Graphic technology - Management of security printing processes

This document specifies requirements for a security printing management system for security printers.
This document specifies a minimum set of security printing management system requirements. Organizations ensure that customer security requirements are met as appropriate, provided these do not conflict with the requirements of this document.

Technologie graphique - Management des procédés d'impression de sécurité

Grafična tehnologija - Upravljanje procesov v varnostnem tisku

Ta dokument določa zahteve za sisteme upravljanja varnostnega tiska za varnostne tiskalnike.
Ta dokument določa minimalni sklop zahtev za sisteme upravljanja varnostnega tiska. Organizacije zagotovijo, da so varnostne zahteve strank ustrezno izpolnjene, pod pogojem, da te niso v nasprotju z zahtevami tega dokumenta.

General Information

Status
Published
Publication Date
22-Mar-2022
Technical Committee
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
09-Mar-2022
Due Date
14-May-2022
Completion Date
23-Mar-2022

Relations

Standard
ISO 14298:2022
English language
26 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day
Standard
ISO 14298:2021 - Graphic technology -- Management of security printing processes
English language
21 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)


SLOVENSKI STANDARD
01-maj-2022
Nadomešča:
SIST ISO 14298:2020
Grafična tehnologija - Upravljanje procesov v varnostnem tisku
Graphic technology - Management of security printing processes
Technologie graphique - Management des procédés d'impression de sécurité
Ta slovenski standard je istoveten z: ISO 14298:2021
ICS:
37.100.01 Grafična tehnologija na Graphic technology in
splošno general
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

INTERNATIONAL ISO
STANDARD 14298
Second edition
2021-08
Graphic technology — Management of
security printing processes
Technologie graphique — Management des procédés d'impression de
sécurité
Reference number
©
ISO 2021
© ISO 2021
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address
below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii © ISO 2021 – All rights reserved

Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Context of the organization . 5
4.1 Understanding the organization and its context . 5
4.2 Understanding the needs and expectations of interested parties . 5
4.3 Determining the scope of the security printing management system . 6
4.4 Security printing management system . 6
5 Leadership . 7
5.1 Leadership and commitment . 7
5.2 Policy . 8
5.3 Organization roles, responsibilities and authorities . 8
6 Planning . 8
6.1 Actions to address risk and opportunities . 8
6.2 Security objectives and planning to achieve them . 9
6.3 Security printing management system planning . 9
7 Support .10
7.1 Resources .10
7.2 Competence .10
7.3 Awareness .10
7.4 Communication .11
7.5 Documented information .11
7.5.1 General.11
7.5.2 Creating and updating .12
7.5.3 Control of documented information .12
8 Operation .13
9 Performance evaluation .13
9.1 Monitoring, measurement, analysis and evaluation .13
9.2 Internal audit .14
9.3 Management review .14
10 Improvement .15
10.1 Nonconformity, security breaches and corrective actions .15
10.2 Preventive actions .15
10.3 Continual improvement .16
Annex A (normative) Determination of security requirements related to the security
printing management system .17
Bibliography .21
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out
through ISO technical committees. Each member body interested in a subject for which a technical
committee has been established has the right to be represented on that committee. International
organizations, governmental and non-governmental, in liaison with ISO, also take part in the work.
ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of
electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the
different types of ISO documents should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www .iso .org/ directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. ISO shall not be held responsible for identifying any or all such patent rights. Details of
any patent rights identified during the development of the document will be in the Introduction and/or
on the ISO list of patent declarations received (see www .iso .org/ patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and
expressions related to conformity assessment, as well as information about ISO's adherence to the
World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www .iso .org/
iso/ foreword .html.
This document was prepared by Technical Committee ISO/TC130, Graphic technology.
This second edition cancels and replaces the first edition (ISO 14298:2013), which has been technically
revised.
The main changes compared to the previous edition are as follows:
— definitions have been updated according to the latest version of ISO/IEC Directives, Part 1,
Consolidated ISO Supplement;
— editorial changes have been applied;
— the lay-out has been updated.
A list of all parts in the ISO 14298 series can be found on the ISO website.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www .iso .org/ members .html.
iv © ISO 2021 – All rights reserved

Introduction
0.1 General
This document specifies requirements for a security printing management system for security printers.
Current security printing management practices lack sufficient guarantees that effective security
controls are maintained to protect the interest of the customer as well as the general public. Using this
document, the organization establishes, documents, implements and maintains a security printing
management system. This security printing management system is regularly reviewed to continually
improve its effectiveness. It is recognized that customer requirements sometimes exceed the
requirements of this document, so the security printing management system also addresses customer
requirements that are beyond the scope of this document.
The adoption of a security printing management system is a strategic decision of an organization. The
design and implementation of an organization’s security printing management system is influenced by
varying needs, particular objectives, products provided, processes employed, security environment,
cultural issues, legal limitations, risk assessment and by size and structure of the organization.
To achieve the objectives of this security printing management system standard, measures are taken to
mitigate all of the security threats determined by an organizational risk assessment. Such controls focus
upon reducing, eliminating and preventing acts that compromise the security printing management
system of the organization.
It is not the intent of this document to obtain uniformity in the structure of the security printing
management system or uniformity of documented information. The security printing management
system complies with laws and regulations in force. The requirements specified in this document are
supplementary to requirements for products and processes of an organization and allow for additional
specific requirements from the customer.
This document is intended to apply to security printers. It contains requirements that when
implemented by a security printer may be objectively audited for certification/registration purposes.
0.2 Process approach
This document promotes the adoption of a process approach when developing, implementing and
improving the effectiveness of a security printing management system.
The application of a system of processes within an organization, together with the identification
and interaction of these processes, and their management, is referred to as a “process approach”. An
advantage of a “process approach” is the ongoing control that it provides over the interaction between
individual processes within the system of processes, as well as over their combination.
0.3 Basic principles
When implemented, the security printing management system:
a) achieves the security of products, processes, means of production, premises, i
...


INTERNATIONAL ISO
STANDARD 14298
Second edition
2021-08
Graphic technology — Management of
security printing processes
Technologie graphique — Management des procédés d'impression de
sécurité
Reference number
©
ISO 2021
© ISO 2021
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address
below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii © ISO 2021 – All rights reserved

Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Context of the organization . 5
4.1 Understanding the organization and its context . 5
4.2 Understanding the needs and expectations of interested parties . 5
4.3 Determining the scope of the security printing management system . 6
4.4 Security printing management system . 6
5 Leadership . 7
5.1 Leadership and commitment . 7
5.2 Policy . 8
5.3 Organization roles, responsibilities and authorities . 8
6 Planning . 8
6.1 Actions to address risk and opportunities . 8
6.2 Security objectives and planning to achieve them . 9
6.3 Security printing management system planning . 9
7 Support .10
7.1 Resources .10
7.2 Competence .10
7.3 Awareness .10
7.4 Communication .11
7.5 Documented information .11
7.5.1 General.11
7.5.2 Creating and updating .12
7.5.3 Control of documented information .12
8 Operation .13
9 Performance evaluation .13
9.1 Monitoring, measurement, analysis and evaluation .13
9.2 Internal audit .14
9.3 Management review .14
10 Improvement .15
10.1 Nonconformity, security breaches and corrective actions .15
10.2 Preventive actions .15
10.3 Continual improvement .16
Annex A (normative) Determination of security requirements related to the security
printing management system .17
Bibliography .21
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out
through ISO technical committees. Each member body interested in a subject for which a technical
committee has been established has the right to be represented on that committee. International
organizations, governmental and non-governmental, in liaison with ISO, also take part in the work.
ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of
electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the
different types of ISO documents should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www .iso .org/ directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. ISO shall not be held responsible for identifying any or all such patent rights. Details of
any patent rights identified during the development of the document will be in the Introduction and/or
on the ISO list of patent declarations received (see www .iso .org/ patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and
expressions related to conformity assessment, as well as information about ISO's adherence to the
World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www .iso .org/
iso/ foreword .html.
This document was prepared by Technical Committee ISO/TC130, Graphic technology.
This second edition cancels and replaces the first edition (ISO 14298:2013), which has been technically
revised.
The main changes compared to the previous edition are as follows:
— definitions have been updated according to the latest version of ISO/IEC Directives, Part 1,
Consolidated ISO Supplement;
— editorial changes have been applied;
— the lay-out has been updated.
A list of all parts in the ISO 14298 series can be found on the ISO website.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www .iso .org/ members .html.
iv © ISO 2021 – All rights reserved

Introduction
0.1 General
This document specifies requirements for a security printing management system for security printers.
Current security printing management practices lack sufficient guarantees that effective security
controls are maintained to protect the interest of the customer as well as the general public. Using this
document, the organization establishes, documents, implements and maintains a security printing
management system. This security printing management system is regularly reviewed to continually
improve its effectiveness. It is recognized that customer requirements sometimes exceed the
requirements of this document, so the security printing management system also addresses customer
requirements that are beyond the scope of this document.
The adoption of a security printing management system is a strategic decision of an organization. The
design and implementation of an organization’s security printing management system is influenced by
varying needs, particular objectives, products provided, processes employed, security environment,
cultural issues, legal limitations, risk assessment and by size and structure of the organization.
To achieve the objectives of this security printing management system standard, measures are taken to
mitigate all of the security threats determined by an organizational risk assessment. Such controls focus
upon reducing, eliminating and preventing acts that compromise the security printing management
system of the organization.
It is not the intent of this document to obtain uniformity in the structure of the security printing
management system or uniformity of documented information. The security printing management
system complies with laws and regulations in force. The requirements specified in this document are
supplementary to requirements for products and processes of an organization and allow for additional
specific requirements from the customer.
This document is intended to apply to security printers. It contains requirements that when
implemented by a security printer may be objectively audited for certification/registration purposes.
0.2 Process approach
This document promotes the adoption of a process approach when developing, implementing and
improving the effectiveness of a security printing management system.
The application of a system of processes within an organization, together with the identification
and interaction of these processes, and their management, is referred to as a “process approach”. An
advantage of a “process approach” is the ongoing control that it provides over the interaction between
individual processes within the system of processes, as well as over their combination.
0.3 Basic principles
When implemented, the security printing management system:
a) achieves the security of products, processes, means of production, premises, information, raw
material supplies;
b) is used to continue to meet demonstrably the requirements, and naturally, the needs of customers;
c) affords management the confidence that the targeted degree of security is actually achieved and
remains effective;
d) affords the customers the confidence that the agreed nature and degree of security is or will be
attained.
This document prescribes which elements a security printing management system contains and not
how a specific organization implements these elements.
INTERNATIONAL STANDARD ISO 14298:2021(E)
Graphic technology — Management of security printing
processes
1 Scope
This document specifies requirements for a security printing
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.