BS ISO IEC 19678-2015 Information Technology BIOS Protection Guidelines《信息技术 BIOS保护指南》.pdf
《BS ISO IEC 19678-2015 Information Technology BIOS Protection Guidelines《信息技术 BIOS保护指南》.pdf》由会员分享,可在线阅读,更多相关《BS ISO IEC 19678-2015 Information Technology BIOS Protection Guidelines《信息技术 BIOS保护指南》.pdf(26页珍藏版)》请在麦多课文档分享上搜索。
1、BSI Standards Publication BS ISO/IEC 19678:2015 Information Technology BIOS Protection GuidelinesBS ISO/IEC 19678:2015 BRITISH STANDARD National foreword This British Standard is the UK implementation of ISO/IEC 19678:2015. The UK participation in its preparation was entrusted to Technical Committee
2、 ICT/-/1, Information systems co-ordination. A list of organizations represented on this committee can be obtained on request to its secretary. This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application. The British Stan
3、dards Institution 2015. Published by BSI Standards Limited 2015 ISBN 978 0 580 85780 5 ICS 35.080 Compliance with a British Standard cannot confer immunity from legal obligations. This British Standard was published under the authority of the Standards Policy and Strategy Committee on 30 April 2015.
4、 Amendments/corrigenda issued since publication Date T e x t a f f e c t e dInformation Technology BIOS Protection Guidelines Technologies de linformation Lignes directrices de protection BIOS INTERNATIONAL STANDARD ISO/IEC 19678 Reference number ISO/IEC 19678:2015(E) First edition 2015-05-01 ISO/IE
5、C 2015 BS ISO/IEC 19678:2015ii ISO/IEC 2015 All rights reserved COPYRIGHT PROTECTED DOCUMENT ISO/IEC 2015, Published in Switzerland All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanic
6、al, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or ISOs member body in the country of the requester. ISO copyright office Ch. de Blandonnet 8 CP 401 CH-1214 Vernier, Geneva, Swit
7、zerland Tel. +41 22 749 01 11 Fax +41 22 749 09 47 copyrightiso.org www.iso.org ISO/IEC 19678:2015(E)Contents Page Foreword v Introduction . vi 1 Scope 1 2 Conformance . 1 3 Normative references. . 2 4 Terms and definitions . 2 5 Symbols (and abbreviated terms) . 3 6 Background . 4 6.1 System BIOS .
8、 4 6.2 Role of System BIOS in the Boot Process . . 5 6.3 Updating the System BIOS . . 8 6.4 Importance of BIOS Integrity . . 8 6.5 Threats to the System BIOS . . 9 7 Threat Mitigation . 10 Bibliography . 14 ISO/IEC 2015 All rights reserved BS ISO/IEC 19678:2015 ISO/IEC 19678:2015(E)Foreword ISO (the
9、 International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees es
10、tablished by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In
11、the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2. The main task of the joint technical committee is to prepare International Standards
12、. Draft International Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as an International Standard requires approval by at least 75 % of the national bodies casting a vote. Attention is drawn to the possibility that some of the elements of
13、 this document may be the subject of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights. Note: ITTF will provide the document number needed below ISO/IEC 19678 was prepared by the U.S. National Institute of Standards and Technology from NIST SP 800
14、- 147, BIOS Protection Guidelines. NIST SP 800-147 was reformatted in accordance with ISO/IEC Directives, Part 2, while maintaining the technical content of the NIST publication (available at http:/csrc.nist.gov/publications/nistpubs/800-147/NIST-SP800-147-April2011.pdf). The resulting standard was
15、adopted under a special “fast-track procedure”, by Joint Technical Committee ISO/IEC JTC 1, Information technology, in parallel with its approval by the national bodies of ISO and IEC. ISO/IEC 2015 All rights reserved BS ISO/IEC 19678:2015 ISO/IEC 19678:2015(E)Introduction Modern computers rely on f
16、undamental system firmware, commonly known as the system Basic Input/Output System (BIOS), to facilitate the hardware initialization process and transition control to the operating system. The BIOS is typically developed by both original equipment manufacturers (OEMs) and independent BIOS vendors, a
17、nd is distributed to end-users by motherboard or computer manufacturers. Manufacturers frequently update system firmware to fix bugs, patch vulnerabilities, and support new hardware. This International Standard provides security requirements and guidance for preventing the unauthorized modification
18、of BIOS firmware on PC client systems. Unauthorized modification of BIOS firmware by malicious software constitutes a significant threat because of the BIOSs unique and privileged position within the PC architecture. A malicious BIOS modification could be part of a sophisticated, targeted attack on
19、an organizationeither a permanent denial of service (if the BIOS is corrupted) or a persistent malware presence (if the BIOS is implanted with malware). The move from conventional BIOS implementations to implementations based on the Unified Extensible Firmware Interface (UEFI) may make it easier for
20、 malware to target the BIOS in a widespread fashion, as these BIOS implementations are based on a common specification. This International Standard focuses on current and future x86 and x64 desktop and laptop systems, although the controls and procedures could potentially apply to any system design.
21、 Likewise, although the guide is oriented toward enterprise-class platforms, the necessary technologies are expected to migrate to consumer- grade systems over time. The security requirements do not attempt to prevent installation of unauthentic BIOSs through the supply chain, by physical replacemen
22、t of the BIOS chip, or through secure local update procedures. The intended audience for this International Standard includes BIOS and platform vendors, and information system security professionals who are responsible for managing the endpoint platforms security, secure boot processes, and hardware
23、 security modules. The material may also be of use when developing enterprise- wide procurement strategies and deployment. The material in this International Standard is technically oriented, and it is assumed that readers have at least a basic understanding of system and network security. The Inter
24、national Standard provides background information to help such readers understand the topics that are discussed. Readers are encouraged to take advantage of other resources (including those listed in this International Standard) for more detailed information. ISO/IEC 2015 All rights reserved BS ISO/
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSISOIEC196782015INFORMATIONTECHNOLOGYBIOSPROTECTIONGUIDELINES 信息技术 BIOS 保护 指南 PDF

链接地址:http://www.mydoc123.com/p-396489.html