
ISO/IEC TS 20540:2025
ISO/IEC TS 20540:2025 Information security, cybersecurity and privacy protection — Testing cryptographic modules in their field
CDN $337.00
This publication was last reviewed and confirmed in 2025.
Information security, cybersecurity and privacy protection — Testing cryptographic modules in their field
Description
This document provides recommendations, requirements and checklists which can be used to support the specification and field testing of cryptographic modules in their field within an organization’s security system. The cryptographic modules have an overall security rating commensurate with the four security levels defined in ISO/IEC 19790:2025, to provide for:
— a wide spectrum of data sensitivity (e.g. low-value administrative data, million-dollar funds transfers, life-protecting data, personal identity information, and sensitive information used by government), and
— a diversity of application environments (e.g. a guarded facility, an office, removable media, and a completely unprotected location).
This document is limited to the security related to the cryptographic module. It does not include assessing the security of the field or application environment. It does not define techniques for the identification, assessment and acceptance of the organization’s operational risk.
This document applies to the field testers who perform the field testing for the cryptographic modules in their field and the authorizing officials of cryptographic modules.
Edition
2
Published Date
2026-06-18
Status
PUBLISHED
Pages
44
Format 
Secure PDF
Secure – PDF details
- Save your file locally or view it via a web viewer
- Viewing permissions are restricted exclusively to the purchaser
- Device limits - 3
- Printing – Enabled only to print (1) copy
See more about our Environmental Commitment
Abstract
This document provides recommendations, requirements and checklists which can be used to support the specification and field testing of cryptographic modules in their field within an organization’s security system. The cryptographic modules have an overall security rating commensurate with the four security levels defined in ISO/IEC 19790:2025, to provide for:
— a wide spectrum of data sensitivity (e.g. low-value administrative data, million-dollar funds transfers, life-protecting data, personal identity information, and sensitive information used by government), and
— a diversity of application environments (e.g. a guarded facility, an office, removable media, and a completely unprotected location).
This document is limited to the security related to the cryptographic module. It does not include assessing the security of the field or application environment. It does not define techniques for the identification, assessment and acceptance of the organization’s operational risk.
This document applies to the field testers who perform the field testing for the cryptographic modules in their field and the authorizing officials of cryptographic modules.
Previous Editions
Can’t find what you are looking for?
Please contact us at:
Related Documents
-

ISO/IEC 27001:2022/Amd 1:2024 Information security, cybersecurity and privacy protection – Information security management systems – Requirements – Amendment 1: Climate action changes
CDN $0.00 Add to cart -

ISO 20008:2024 Information security – Anonymous digital signatures – Part 3: Mechanisms using multiple public keys
CDN $263.00 Add to cart -

ISO 27033:2023 Information technology ‚Äì Network security – Part 7: Guidelines for network virtualization security
CDN $263.00 Add to cart -

ISO 20648:2024 Information technology – TLS specification for storage systems
CDN $195.00 Add to cart







