ISO/TC 68/SC 2/WG 16 - Security aspects related to third party payment service providers (TPP’s)
Aspects relatifs à la sécurité concernant les prestataires de services de paiement tiers
General Information
Frequently Asked Questions
ISO/TC 68/SC 2/WG 16 is a Subcommittee within the International Organization for Standardization (ISO). It is named "Security aspects related to third party payment service providers (TPP’s)". This committee has published 1 standards.
ISO/TC 68/SC 2/WG 16 develops ISO standards in the area of Information technology. Currently, there are 1 published standards from this subcommittee.
The International Organization for Standardization (ISO) is an independent, non-governmental international organization that develops and publishes international standards. Founded in 1947 and headquartered in Geneva, Switzerland, ISO brings together experts from 170+ member countries to share knowledge and develop voluntary, consensus-based standards that support innovation and provide solutions to global challenges.
A Subcommittee (SC) in ISO operates under a Technical Committee and focuses on a specific subset of the TC's scope. Subcommittees develop standards and technical specifications in their specialized area, reporting to their parent Technical Committee. They may also have working groups for detailed technical work.
This document defines a common terminology to be used in the context of third-party payment (TPP). Next, it establishes two logical structural models in which the assets to be protected are clarified. Finally, it specifies security objectives based on the analysis of the logical structural models and the interaction of the assets affected by threats, organizational security policies and assumptions. These security objectives are set out in order to counter the threats resulting from the intermediary nature of TPPSPs offering payment services compared with simpler payment models where the payer and the payee directly interact with their respective account servicing payment service provider (ASPSP). This document assumes that TPP-centric payments rely on the use of TPPSP credentials and the corresponding certified processes for issuance, distribution and renewal purposes. However, security objectives for such processes are out of the scope of this document. NOTE This document is based on the methodology specified in the ISO/IEC 15408 series. Therefore, the security matters that do not belong to the TOE are dealt with as assumptions, such as the security required by an information system that provides TPP services and the security of communication channels between the entities participating in a TPP business.
- Standard40 pagesEnglish languagesale 15% off