Search
×
FR

Placeholder headline

This is just a placeholder headline

API STD 521: Guide for Pressure-relieving and Depressuring Systems – Edition 6

$

682

BUY NOW

Placeholder headline

This is just a placeholder headline

API STD 653: Tank Inspection, Repair, Alteration, and Reconstruction – Edition 4

$

507

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z662:19 – Oil and gas pipeline systems

$

1197

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z341 Series-18: Storage of hydrocarbons in underground formations

$

878

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z246.2-14 – Emergency preparedness and response for petroleum and natural gas industry systems

$

596

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z341 Series:22 – Storage of hydrocarbons in underground formations

$

878

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z731-09 (R2014) – Emergency Preparedness and Response

$

177

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z662:23 – Oil and gas pipeline systems

$

1197

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z341 Series:26 – Storage of Hydrocarbons in underground formations

$

878

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA B51:24 Boiler, Pressure Vessel, and Pressure Piping Code

$

389

BUY NOW

ISO 23195:2021

ISO 23195:2021 Security objectives of information systems of third-party payment services

CDN $336.00

SKU: ee02a19126d2 Categories: ,

Description

This document defines a common terminology to be used in the context of third-party payment (TPP). Next, it establishes two logical structural models in which the assets to be protected are clarified. Finally, it specifies security objectives based on the analysis of the logical structural models and the interaction of the assets affected by threats, organizational security policies and assumptions. These security objectives are set out in order to counter the threats resulting from the intermediary nature of TPPSPs offering payment services compared with simpler payment models where the payer and the payee directly interact with their respective account servicing payment service provider (ASPSP).

This document assumes that TPP-centric payments rely on the use of TPPSP credentials and the corresponding certified processes for issuance, distribution and renewal purposes. However, security objectives for such processes are out of the scope of this document.

NOTE       This document is based on the methodology specified in the ISO/IEC 15408 series. Therefore, the security matters that do not belong to the TOE are dealt with as assumptions, such as the security required by an information system that provides TPP services and the security of communication channels between the entities participating in a TPP business.

Edition

1

Published Date

2021-06-11

Status

PUBLISHED

Pages

40

Language Detail Icon

English

Format Secure Icon

Secure PDF

Abstract

This document defines a common terminology to be used in the context of third-party payment (TPP). Next, it establishes two logical structural models in which the assets to be protected are clarified. Finally, it specifies security objectives based on the analysis of the logical structural models and the interaction of the assets affected by threats, organizational security policies and assumptions. These security objectives are set out in order to counter the threats resulting from the intermediary nature of TPPSPs offering payment services compared with simpler payment models where the payer and the payee directly interact with their respective account servicing payment service provider (ASPSP).

This document assumes that TPP-centric payments rely on the use of TPPSP credentials and the corresponding certified processes for issuance, distribution and renewal purposes. However, security objectives for such processes are out of the scope of this document.

NOTE       This document is based on the methodology specified in the ISO/IEC 15408 series. Therefore, the security matters that do not belong to the TOE are dealt with as assumptions, such as the security required by an information system that provides TPP services and the security of communication channels between the entities participating in a TPP business.

Previous Editions

Can’t find what you are looking for?

Please contact us at: