ISO 21188:2018
Public key infrastructure for financial services — Practices and policy framework

Standard No.
ISO 21188:2018
Release Date
2018
Published By
International Organization for Standardization (ISO)
Latest
ISO 21188:2018
Scope
This document sets out a framework of requirements to manage a PKI through certificate policies and certification practice statements and to enable the use of public key certificates in the financial services industry. It also defines control objectives and supporting procedures to manage risks. While this document addresses the generation of public key certificates that might be used for digital signatures or key establishment, it does not address authentication methods, non-repudiation requirements or key management protocols. This document draws a distinction between PKI systems used in closed, open and contractual environments. It further defines the operational practices relative to financial-services-industry- accepted information systems control objectives. This document is intended to help implementers to define PKI practices that can support multiple certificate policies that include the use of digital signature, remote authentication, key exchange and data encryption. This document facilitates the implementation of operational, baseline PKI control practices that satisfy the requirements for the financial services industry in a contractual environment. While the focus of this document is on the contractual environment, application of this document to other environments is not specifically precluded. For the purposes of this document, the term “certificate” refers to public key certificates. Attribute certificates are outside the scope of this document This document is targeted for several audiences with different needs and therefore the use of this document will have a different focus for each. Business managers and analysts are those who require information regarding using PKI technology in their evolving businesses (e.g. electronic commerce); see Clauses 1 to 6. Technical designers and implementers are those who are writing their certificate policies and certification practice statement(s); see Clauses 6 to 7 and Annexes A to G. Operational management and auditors are those who are responsible for day-to-day operations of the PKI and validating compliance to this document; see Clauses 6 to 7.

ISO 21188:2018 Referenced Document

  • ISO 13491-1 Financial services - Secure cryptographic devices (retail) - Part 1: Concepts, requirements and evaluation methods
  • ISO/IEC 18032 Information security -- Prime number generation*2020-12-02 Update
  • ISO/IEC 18033-1 Information security — Encryption algorithms — Part 1: General*2021-09-10 Update
  • ISO/IEC 18033-2 Amendment 1 - Information technology - Security techniques - Encryption algorithms - Part 2: Asymmetric ciphers - FACE
  • ISO/IEC 18033-3 Information technology — Security techniques — Encryption algorithms — Part 3: Block ciphers — Amendment 2: SM4
  • ISO/IEC 18033-4 Amendment 1 - Information technology - Security techniques - Encryption algorithms - Part 4: Stream ciphers - ZUC*2020-08-05 Update
  • ISO/IEC 19790 Corrigendum 1 - Information technology - Security techniques - Security requirements for cryptographic modules
  • ISO/IEC 9594-8 Information technology-Open systems interconnection-Part 8: The Directory: Public-key and attribute certificate frameworks*2024-04-01 Update

ISO 21188:2018 history

  • 2018 ISO 21188:2018 Public key infrastructure for financial services — Practices and policy framework
  • 2006 ISO 21188:2006 Public key infrastructure for financial services - Practices and policy framework
Public key infrastructure for financial services — Practices and policy framework



Copyright ©2024 All Rights Reserved