ISO IEC 20243-2015 Information Technology - Open Trusted Technology ProviderTM Standard (O-TTPS) - Mitigating maliciously tainted and counterfeit products《信息技术 .pdf
《ISO IEC 20243-2015 Information Technology - Open Trusted Technology ProviderTM Standard (O-TTPS) - Mitigating maliciously tainted and counterfeit products《信息技术 .pdf》由会员分享,可在线阅读,更多相关《ISO IEC 20243-2015 Information Technology - Open Trusted Technology ProviderTM Standard (O-TTPS) - Mitigating maliciously tainted and counterfeit products《信息技术 .pdf(46页珍藏版)》请在麦多课文档分享上搜索。
1、Information Technology Open Trusted Technology ProviderTM Standard (O-TTPS) Mitigating maliciously tainted and counterfeit products Technologies de linformation Norme de fournisseur de technologie de confiance ouverte (O-TTPS) Attnuation des produits contrefaits et malicieusement contamins INTERNATI
2、ONAL STANDARD ISO/IEC 20243 Reference number ISO/IEC 20243:2015(E) First edition 2015-09- 15 ISO/IEC 2015 ii ISO/IEC 2015 All rights reserved COPYRIGHT PROTECTED DOCUMENT ISO/IEC 2015, Published in Switzerland All rights reserved. Unless otherwise specified, no part of this publication may be reprod
3、uced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or ISOs member body in the country of the requester.
4、 ISO copyright office Ch. de Blandonnet 8 CP 401 CH-1214 Vernier, Geneva, Switzerland Tel. +41 22 749 01 11 Fax +41 22 749 09 47 copyrightiso.org www.iso.org ISO/IEC 20243:2015(E)Open Trusted Technology Provider Standard (O-TTPS), Version 1.1 iii Contents 1 Introduction.1 1.1 Objectives . 1 1.2 Ov e
5、rv iew . 1 1.3 Conform ance . 3 1.4 Terminology . 3 1.5 Future Directions 4 2 Business Context and Overview .5 2.1 Business Environment Summary 5 2.1.1 Operational Scenario . 5 2.2 Business Rationale 7 2.2.1 Business Drivers 7 2.2.2 Objectives and Benefits . 8 2.3 Recognizing the COTS ICT Context 9
6、2.4 Ov erv iew . 11 2.4.1 O-TTPF Framework Overview . 11 2.4.2 Standard Overview 11 2.4.3 Relationship with Other Standards 12 3 O-TTPS Tainted and Counterfeit Risks .13 4 O-TTPS Requirements for Addressing the Risks of Tainted and Counterfeit Products.15 4.1 Technology Development . 16 4.1.1 PD: Pr
7、oduct Development/Engineering Method . 16 4.1.1.1 PD_DES: Software/Firmware/Hardware Design Process . 16 4.1.1.2 PD_CFM: Configuration Management 17 4.1.1.3 PD_MPP: Well-defined Development/Engineering Method Process and Practices 17 4.1.1.4 PD_QAT: Quality and Test Management 17 4.1.1.5 PD_PSM: Pro
8、duct Sustainment Management . 18 4.1.2 SE: Secure Development/Engineering Method . 18 4.1.2.1 SE_TAM: Threat Analysis and Mitigation 18 4.1.2.2 SE_RTP: Run-time Protection Techniques 19 4.1.2.3 SE_VAR: Vulnerability Analysis and Response 19 4.1.2.4 SE_PPR: Product Patching and Remediation 20 4.1.2.5
9、 SE_SEP: Secure Engineering Practices . 20 ISO/IEC 20243:2015(E) ISO/IEC 2015 All rights reservediv Open Group Standard (2014) 4.1.2.6 SE_MTL: Monitor and Assess the Impact of Changes in the Threat Landscape 20 4.2 Supply Chain Security 21 4.2.1 SC: Supply Chain Security 21 4.2.1.1 SC_RSM: Risk Mana
10、gement . 21 4.2.1.2 SC_PHS: Physical Security . 22 4.2.1.3 SC_ACC: Access Controls 22 4.2.1.4 SC_ESS: Employee and Supplier Security and Integrity . 23 4.2.1.5 SC_BPS: Business Partner Security 23 4.2.1.6 SC_STR: Supply Chain Security Training 24 4.2.1.7 SC_ISS: Information Systems Security . 24 4.2
11、.1.8 SC_TTC: Trusted Technology Components 24 4.2.1.9 SC_STH: Secure Transmission and Handling . 25 4.2.1.10 SC_OSH: Open Source Handling 25 4.2.1.11 SC_CTM: Counterfeit Mitigation 26 4.2.1.12 SC_MAL: Malware Detection . 26 List of Tables Table 1: O-TTPS Constituents and their Roles . 6 Table 2: Thr
12、eat Mapping . 14 List of Figures Figure 1: Constituents . 6 Figure 2: Product Life Cycle Categories and Activities . 15 ISO/IEC 20243:2015(E) ISO/IEC 2015 All rights reservedOpen Trusted Technology Provider Standard (O-TTPS), Version 1.1 v Preface The Open Group The Open Group is a global consortium
13、 that enables the achievement of business objectives through IT standards. With more than 400 member organizations, The Open Group has a diverse membership that spans all sectors of the IT community customers, systems and solutions suppliers, tool vendors, integrators, and consultants, as well as ac
14、ademics and researchers to: Capture, understand, and address current and emerging requirements, and establish policies and share best practices Facilitate interoperability, develop consensus, and evolve and integrate specifications and open source technologies Offer a comprehensive set of services t
15、o enhance the operational efficiency of consortia Operate the industrys premier certification service Further information on The Open Group is available at www.opengroup.org. The Open Group publishes a wide range of technical documentation, most of which is focused on development of Open Group Stand
16、ards and Guides, but which also includes white papers, technical studies, certification and testing documentation, and business titles. Full details and a catalog are available at www.opengroup.org/bookstore. Readers should note that updates in the form of Corrigenda may apply to any publication. Th
17、is information is published at www.opengroup.org/corrigenda. This Document The Open Group Trusted Technology Forum (OTTF or Forum) is a global initiative that invites industry, government, and other interested participants to work together to evolve this Standard and other OTTF deliverables. This St
18、andard is the Open Trusted Technology Provider Standard (O-TTPS). The Standard has been developed by the OTTF and approved by The Open Group, through The Open Group Company Review process. There are two distinct elements that should be understood with respect to this Standard: the O-TTPF (Framework)
19、 and the O-TTPS (Standard). The O-TTPF (Framework): The Framework is an evolving compendium of organizational guidelines and best practices relating to the integrity of Commercial Off-the-Shelf (COTS) Information and Communication Technology (ICT) products and the security of the supply chain throug
20、hout the entire product life cycle. An early version of the Framework was published as a White Paper in February 2011 (see Referenced Documents). The Framework serves as the basis for this Standard, future updates, and additional standards. The content of the Framework is the result of industry coll
21、aboration and research as to those commonly used commercially ISO/IEC 20243:2015(E) ISO/IEC 2015 All rights reservedvi Open Group Standard (2014) reasonable practices that increase product integrity and supply chain security. The members of the OTTF will continue to collaborate with industry and gov
22、ernments and update the Framework as the threat landscape changes and industry practices evolve. The O-TTPS (Standard): The O-TTPS is an open standard containing a set of guidelines that when properly adhered to have been shown to enhance the security of the global supply chain and the integrity of
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ISOIEC202432015INFORMATIONTECHNOLOGYOPENTRUSTEDTECHNOLOGYPROVIDERTMSTANDARDOTTPSMITIGATINGMALICIOUSLYTAINTEDANDCOUNTERFEITPRODUCTS

链接地址:http://www.mydoc123.com/p-1257016.html