GB/T 20276-2016 in English
VALIDInformation security technology - Security requirements for embedded software in IC card with CPU
- Issued on:2016-08-29
- Implemented on:2017-03-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$485.00
《GB/T 20276-2016信息安全技术 具有中央处理器的IC卡嵌入式软件安全技术要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
1 Scope
This standard specifies the security requirements for the security protection of embedded software in IC card with CPU of EAL4 enhanced level and EAL5 enhanced level, including the security problem definition, security objectives, security requirements, rationale, etc.
This standard is applicable to the testing, evaluation and procurement of embedded software products in IC card with CPU, and may also be used to guide the research and development of such products.
2 Normative references
The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.
GB/T 18336 (All parts) Information technology - Security techniques - Evaluation criteria for IT security
GB/T 25069-2010 Information security technology - Glossary
3 Terms, definitions and abbreviations
3.1 Terms and definitions
For the purposes of this document, the terms and definitions given in GB/T 25069-2010, GB/T 18336.1 and the followings apply.
3.1.1
personalization data
data written in the personalization process of embedded software in IC card, which is used to configure parameters related to specific applications or users
3.2 Abbreviations
For the purposes of this document, the following abbreviations apply.
CM: Configuration Management
EAL: Evaluation Assurance Level
EEPROM: Electrically-Erasable Programmable Read-only Memory
IC: Integrated Circuit
I/O: Input/Output
RAM: Random-Access Memory
ROM: Read-Only Memory
ST: Security Target
TOE: Target of Evaluation
TSF: TOE Security Functionality
Foreword i
Introduction iii
1 Scope
2 Normative references
3 Terms, definitions and abbreviations
3.1 Terms and definitions
3.2 Abbreviations
4 Descriptions of embedded software in IC card
5 Security problem definition
5.1 Assets
5.2 Threats
5.3 Organizational security policies
5.4 Assumptions
6 Security objectives
6.1 Security objectives for the TOE
6.2 Security objective for environment
7 Security requirements
7.1 Security functional requirements
7.2 Security assurance requirements
8 Rationale
8.1 Rationale of security objectives
8.2 Rationale of security requirements
8.3 Component dependencies
Bibliography

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 31495.1-2015 in English
Information security technology―Indicator system of information security assurance and evaluation methods―Part 1:Concepts and model
2015-05-15 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 35101-2017 in English
Information security technology-Smart card reader security technology requirements ( EAL4+)
2017-11-01 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 15843.1-2017 in English
Information technology―Security techniques―Entity authentication―Part 1:General
2017-12-29 -

GB/T 36323-2018 in English
Information security technology--Security management fundamental requirements for industrial control systems
2018-06-07 -

GB/T 37931-2019 in English
Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system
2019-08-30