The ISO 19989 series discusses information security in biometric systems. The ISO 19989 series supplements the ISO 15408 series and ISO 18045 by providing extended security functional requirements together with assurance activities related to these requirements.
For security evaluation of biometric verification systems and biometric identification systems, ISO 19989‑3 provides recommendations and requirements to the developer and the evaluator for the supplementary activities on presentation attack detection specified in ISO 19989‑1. ISO 19989‑3 is dedicated to the security evaluation of presentation attack detection applying the ISO 15408 series.
ISO 19989‑3 is applicable only to TOEs for a single biometric characteristic type but for the selection of a characteristic from multiple characteristics.
ISO 19989‑3 on presentation attack detection in biometric systems is useful for:
Biometric systems can be vulnerable to presentation attacks where attackers attempt to subvert the system security policy by presenting their natural biometric characteristics or artefacts holding copied or faked characteristics. Presentation attacks can occur during enrolment or identification/verification events. Techniques designed to detect presentation artefacts are generally different from those to counter attacks where natural characteristics are used.
ISO 19989‑3 provides you with guidelines and requirements for the supplementary activities on presentation attack detection specified in ISO 19989‑1. ISO 19989‑3 builds on the general considerations described in ISO 19792. ISO 19989‑3 compliments the presentation attack detection testing methodology described in ISO 30107‑3 by providing you with additional guidance. ISO 19989‑3 ensures that your biometric systems detect presentation attacks in a more efficient manner, thereby improving their reliability.
ISO/IEC 19989-3