The modern cybersecurity systems are based on cryptographic modules. They safeguard monetary dealings, individual information, state communications, industrial control systems, and secure networks. Cryptographic modules may weaken or fail to provide appropriate protection to the whole security system. IEC 19790 gives standard security requirements that include physical security, logical security, key management, roles and services, and operational environments. The standard allows for a standardized assessment and certification of cryptographic modules in order to be able to withstand specified security levels and avoid unauthorized access or manipulation.
Get Certified IEC 19790 for Trusted Cryptographic Security
Both certification to IEC 19790 and certification to IEC 9554 prove that a cryptographic module satisfies internationally recognized security requirements. Certified modules offer the regulators, customers, and integrators of the system an assurance that cryptographic controls are working in a secure and reliable manner. Compliance promotes government approvals, validation of the financial system, and safe product deployment in international markets.
IEC 19790 Security Requirement Areas
| Module Specification | Definition of cryptographic module boundaries and components |
| Roles and Services | Identification of authorized roles and permitted services |
| Operational Environment | Secure configuration and execution environment |
| Cryptographic Key Management | Generation, storage, distribution, and destruction of keys |
| Self-Tests | Power-up and conditional integrity tests |
| Design Assurance | Documentation, configuration management, and testing controls |
| Mitigation of Attacks | Protection against side-channel and other advanced attacks |
