What is ISO 20085‑2 about?
The ISO 20085 series discusses IT security techniques. ISO 20085‑2 specifies the test calibration methods and apparatus used when calibrating test tools for cryptographic modules under ISO 19790 and ISO 24759 against the test metrics defined in ISO 17825 for mitigation of non-invasive attack classes.
ISO 20085-2 covers two aspects of the calibration process:
- Definition of a method for calibration
- Requirement of a reference cryptographic module (called an artefact) to define a clear threshold between test results, in terms of fail or pass
Who is ISO 20085‑2 for?
ISO 20085‑2 on IT security techniques is useful for:
- Cybersecurity teams
- Software teams
- IT-based organizations who are looking to improve their security
- Any organization that wants to protect its data
Why should you use ISO 20085‑2?
Cryptographic modules provide cryptographic services and protect critical security parameters. Information such as knowledge of critical security parameters can leak out of the cryptographic module during operation if the module is not designed to mitigate such leakage.
ISO 20085‑2 focuses on the calibration of the side-channel measurement tool. This calibration process enables two measurement tools to record measurements equally usable in terms of side-channel analysis. ISO 20085‑2 also provides you with calibration requirements that need to be met before non-invasive testing. This will ensure that the quality of the non-invasive attack technique is of the same level as the cryptographic module and the attack won’t compromise the module. The non-invasive attack mitigation techniques described in ISO 20085‑2 ensure that your data remains secure.