ISO/IEC 19790 evalaution

ISO/IEC 19790 Evaluation

STQC IT – ERTL(N) provides independent evaluation and testing services for cryptographic modules in accordance with the requirements of ISO/IEC 19790 for Security Levels 1 to 4. The evaluation activities are performed in conjunction with ISO/IEC 24759, which specifies the associated testing requirements, evaluation procedures, and validation methodology for cryptographic modules. The services are intended to support vendors, developers, integrators, and solution providers seeking independent assessment of cryptographic modules against internationally recognized security requirements.

Evaluation Scope

The evaluation services cover cryptographic functionalities implemented within security products and systems that may be categorized, as identified in ISO/IEC 19790, as:

  • Hardware cryptographic modules
  • Software cryptographic modules
  • Firmware cryptographic modules
  • Hybrid cryptographic modules

The evaluation may be applicable to products such as (but is not limited to) IoT and Embedded Security Devices, Security Appliances and Gateways, Cryptographic Libraries and Security Software, Network Security Products etc.

Evaluation Activities

The evaluation process includes, but is not limited to, the following activities:

  • Review of security documentation, module specification, and architecture
  • Verification of cryptographic services, approved algorithms, and security functions
  • Validation and/or verification of the cryptographic mechanisms implemented by the TOE
  • Assessment of roles, services, access control, and authentication mechanisms
  • Evaluation of key management processes and protection mechanisms
  • Verification of software/firmware integrity and trusted initialization controls
  • Assessment of physical security and operational environment requirements
  • Verification of self-tests, integrity tests, and error handling mechanisms
  • Review of life-cycle assurance, configuration management, and secure delivery procedures
  • Vulnerability analysis and verification of mitigation mechanisms against applicable attack vectors

Evaluation Outcome

A cryptographic module may be considered compliant when all applicable requirements of ISO/IEC 19790 are satisfactorily met, the implemented security functions operate as claimed, Sensitive Security Parameters (SSPs) are adequately protected, and identified vulnerabilities have been appropriately addressed within the claimed operational environment.

Deliverables

The evaluation process may include the following deliverables, as applicable:

  • Evaluation Test Plan
  • Observation and Non-Conformity Reports
  • Evaluation Technical Report (ETR)