首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 X9 X9.84-2018
到馆提醒
收藏跟踪
购买正版
Biometric Information Management and Security for the Financial Services Industry 金融服务业的生物特征信息管理和安全
发布日期: 2018-04-20
X9 X9。84-2018描述了使用生物识别技术对金融服务中的个人进行身份验证的安全框架。它介绍了生物识别技术的类型,并解决了有关其应用的问题。本标准还描述了实施架构,规定了有效管理的最低安全要求,并提供了适合专业从业者使用的控制目标和建议。在本标准的范围内,讨论了以下主题:生物特征数据收集、分发和处理的安全性,包括数据完整性、数据保密性、来源真实性和不可否认性。在整个生命周期内管理生物特征数据,包括注册、传输和存储、验证、识别和终止过程。生物识别技术的使用,包括- 一对一和一对多匹配,用于识别和认证银行客户和员工。生物识别技术在内部和外部以及逻辑和物理访问控制中的应用。生物特征信息的封装和加密保护,以实现安全性、互操作性和数据保密性。加密、签密、标记化方法和生物特征政策,用于在生物特征信息的生命周期内安全传输和存储生物特征信息。在整个生物特征数据生命周期中使用的物理硬件的安全性。用于生物特征信息的数据完整性、来源真实性和数据保密性的加密技术。根据风险管理的要求,验证注册时出示的凭证,以支持认证;监督以保护金融机构及其客户。
X9 X9.84-2018 describes the security framework for using biometrics for authentication of individuals in financial services. It introduces the types of biometric technologies and addresses issues concerning their application. This standard also describes the architectures for implementation, specifies the minimum security requirements for effective management, and provides control objectives and recommendations suitable for use by a professional practitioner. Within the scope of this standard the following topics are addressed:Security for the collection, distribution, and processing, of biometric data, encompassing data integrity, data confidentiality, origin authenticity, and non-repudiation.Management of biometric data across its life cycle comprised of the enrollment, transmission and storage, verification, identification, and termination processes.Usage of biometric technology, including one-to-one and one-to-many matching, for the identification and authentication of banking customers and employees.Application of biometric technology for internal and external, as well as logical and physical access control.Encapsulation and cryptographic protection of biometric information for security, interoperability, and data confidentiality.Encryption, signcryption, tokenization methods, and biometric policy for privacySecure transmission and storage of biometric information during its life cycle.Security of the physical hardware used throughout the biometric data life cycle.Cryptographic techniques for data integrity, origin authenticity, and data confidentiality of biometric information.Validation of credentials presented at enrollment to support authentication as required by risk management;Surveillance to protect the financial institution and its customers.
分类信息
发布单位或类别: 未知国家-其他未分类
关联关系
研制信息
相似标准/计划/法规
现行
KS X 9092
금융 서비스 — 바이오정보 분산관리
金融服务.分离生物识别信息的管理
2020-12-16
现行
GB/T 27912-2011
金融服务 生物特征识别 安全框架
Financial services—Biometrics—Security framework
2011-12-30
现行
ISO 19092-2023
Financial services — Biometrics — Security framework
金融服务-生物识别-安全框架
2023-03-02
现行
BS PD ISO/TR 13569-2005
Financial services. Information security guidelines
金融服务 信息安全指南
2006-01-23
现行
GOST R ISO/TR 13569-2007
Финансовые услуги. Рекомендации по информационной безопасности
金融服务 信息安全准则
现行
GB/T 27910-2011
金融服务 信息安全指南
Financial services - Information security guidelines
2011-12-30
现行
GB/T 36618-2018
信息安全技术 金融信息服务安全规范
Information security technology—Specification for financial information service security
2018-09-17
现行
ISO/TR 24374-2023
Financial services — Security information for PKI in blockchain and DLT implementations
金融服务-区块链和分布式账本技术实现中PKI的安全信息
2023-04-19
现行
JR/T 0073-2012
金融行业信息安全等级保护测评服务安全指引
Testing and evaluation service security guide for c1assified protection of information security of financial industry
2012-07-06
现行
GA/T 556.10-2007
金融治安保卫管理信息代码 第10部分:安全防范设施合格证编码规则
The codes for finance security manage information-Part 10:The codes for certificate of financial security equipments
2007-03-08
现行
GA/T 556.5-2007
金融治安保卫管理信息代码 第5部分:金融单位编码规则
The codes for finance security manage information-Part 5:The codes for financial institution
2007-03-08
现行
GB/T 32926-2016
信息安全技术 政府部门信息技术服务外包信息安全管理规范
Information security technology—Information security management specification for government information technology service outsourcing
2016-08-29
现行
MZ/T 108-2018
居民家庭经济状况核对信息安全管理规范
Verification service for the family economy information-Security Management
2018-01-09
现行
GA/T 556.1-2005
金融治安保卫管理信息代码 第1部分:金融单位保卫工作相关人员职务分类与代码
The codes for finance security manage information-Part 1:The codes for functionary sort in financial
2005-10-24
现行
GA/T 556.4-2007
金融治安保卫管理信息代码 第4部分:金融单位类别代码
The codes for finance security manage information-Part 4:The codes for financial institution sort
2007-03-08
现行
GA/T 556.6-2007
金融治安保卫管理信息代码 第6部分:储蓄所(营业网点)编码规则
The codes for finance security manage information-Part 6:The codes for financial business address
2007-03-08
现行
GA/T 738.1-2007
保安服务管理信息规范 第1部分:保安服务公司编码
The information code on security service management-Part 1:Code number for security services company
2007-11-26
现行
BS ISO 9564-2-2014
Financial services. Personal Identification Number (PIN) management and security-Approved algorithms for PIN encipherment
金融服务 个人识别码(PIN)管理和安全
2014-08-31
现行
YD/T 3214-2017
互联网资源协作服务信息安全管理系统接口规范
Interfacespecification for information security management of Internet resource collaboration service
2017-01-09
现行
X9 TR-39-2009
TG-3 Retail Financial Services Compliance Guideline - Part 1: PIN Security and Key Management
TG-3零售金融服务合规指南-第1部分:PIN安全和密钥管理
2009-05-10