What is ISO 13491-1 - SCD cryptographic security about?
The security of retail electronic payment systems is largely dependent upon the security of secure cryptographic devices. The risk of financial loss is reduced through the appropriate use of cryptographic devices that have proper characteristics and are properly managed.
ISO 13491-1 specifies the security characteristics and requirements for secure cryptographic devices (SCDs) based on the cryptographic processes.
The purpose of ISO 13491-1 to state the security characteristics concerning both the operational characteristics of SCDs and the management of such devices throughout all stages of their life cycle. ISO 13491-1 provides guidance for methodologies to verify compliance with those requirements.
Note: ISO 13491-1 does not address issues arising from the denial of service of secure cryptographic devices.
Who is ISO 13491-1 - SCD cryptographic security for?
ISO 13491-1 on SCD cryptographic security is useful for:
- IT firms / software engineers
- Government bodies
- Businesses and public administrations providing online services or managing electronic transactions
- Regulatory authorities
Why should you use ISO 13491-1 - SCD cryptographic security?
Cryptographic security depends upon each life cycle phase of the SCD and the complementary combination of appropriate management procedures and secure cryptographic characteristics. These management procedures implement preventive measures to reduce the opportunity for a breach of SCD security. This aims for a high probability of detection of any unauthorized access to sensitive or confidential data should device characteristics fail to prevent or detect the security compromise.
ISO 13491-1 provides you with the physical and logical characteristics and the management of the secure cryptographic devices (SCDs) which are used to protect messages, cryptographic keys, and other sensitive information used in a retail financial services environment.
ISO 13491-1 provides you with tamper evident requirements. Tamper evidence provides an indication that an attack has been attempted. ISO 13491-1 also covers tamper resistant requirements. Tamper resistance provides passive physical protection against attacks.
ISO 13491-1 guidelines help you to secure your financial online transactions and services with cryptographic security of SCD devices.

