X9.84-2010

Biometric Information Management and Security for the Financial Services Industry


 

 

非常抱歉,我们暂时无法提供预览,您可以试试: 免费下载 X9.84-2010 前三页,或者稍后再访问。

如果您需要购买此标准的全文,请联系:

点击下载后,生成下载文件时间比较长,请耐心等待......

 

标准号
X9.84-2010
发布日期
2010年03月31日
实施日期
2018年06月01日
废止日期
中国标准分类号
/
国际标准分类号
/
发布单位
ANSI - American National Standards Institute
引用标准
167
适用范围
This Standard describes the security framework for using biometrics for authentication of individuals in financial services. It introduces the types of biometric technologies and addresses issues concerning their application. This Standard also describes the architectures for implementation@ specifies the minimum security requirements for effective management@ and provides control objectives and recommendations suitable for use by a professional practitioner. Within the scope of this Standard the following topics are addressed: Security for the collection@ distribution@ and processing@ of biometric data@ encompassing data integrity@ authenticity@ and non-repudiation. Management of biometric data across its life cycle comprised of the enrollment@ transmission and storage@ verification@ identification@ and termination processes. Usage of biometric technology@ including one-to-one and one-to-many matching@ for the identification and authentication of banking customers and employees. Application of biometric technology for internal and external@ as well as logical and physical access control. Encapsulation1 and cryptographic protection of biometric information for security@ interoperability@ and data confidentiality.. Secure transmission and storage of biometric information during its life cycle. Security of the physical hardware used throughout the biometric data life cycle. Cryptographic techniques for data integrity@ authenticity@ and data confidentiality of biometric information. Validation of credentials presented at enrollment to support authentication as required by risk management; Surveillance to protect the financial institution and its customers; Items considered out of scope and not addressed in this Standard include the following: The individual??s privacy and ownership of biometric information. Specific techniques for data collection@ signal processing@ and matching of biometric data@ and the biometric matching decision-making process; Usage of biometric technology for non-authentication convenience applications such as speech recognition@ user interaction@ and anonymous access control. Although this Standard does not address specific requirements and limitations of business application employing biometric technology@ other standards may address these topics. 1 Analogous to the ANSI PIN Block@ refer to ANSI X9.8 and ISO 9564 PIN Management and Security standards.




Copyright ©2007-2022 ANTPEDIA, All Rights Reserved
京ICP备07018254号 京公网安备1101085018 电信与信息服务业务经营许可证:京ICP证110310号