ISO 23195 defines a common terminology to be used in the context of third-party payment (TPP).
ISO 23195 establishes two logical structural models in which the assets to be protected are clarified.
ISO 23195 specifies security objectives based on the analysis of the logical structural models and the interaction of the assets affected by threats, organizational security policies, and assumptions. ISO 23195 assumes that TPP-centric payments rely on the use of TPPSP credentials and the corresponding certified processes for issuance, distribution, and renewal purposes.
NOTE-
ISO 23195 is based on the methodology specified in the ISO/IEC 15408 series. Therefore, the security matters that do not belong to the TOE are dealt with as assumptions, such as the security required by an information system that provides TPP services and the security of communication channels between the entities participating in a TPP business.
ISO 23195 on information systems of third-party payment services is useful for:
The global third-party payment (TPP) service is booming and has a profound impact on payment methods. The third-party payment service providers (TPPSPs) act as an intermediary entity between the payment service user (PSU) and the account servicing payment service provider (ASPSP), usually a financial institution. TPPSPs provide payment and other financial services (referred to in this document as TPP services). From the security point of view, the intermediary nature of TPPSPs raises the specific threat of customer impersonation in payment processing. Payment service providers increasingly seek to mitigate the risks of payment fraud in order to protect PSUs and enhance their own business.
Security objectives specified in ISO 23195 lets you counter the threats resulting from the intermediary nature of TPPSPs offering payment services compared with simpler payment models where the payer and the payee directly interact with their respective account servicing payment service provider (ASPSP).
Security objectives in ISO 23195 focus on the mitigation of identified threats against the integrity, non-repudiation and confidentiality of TPP payment data.
ISO 23195 provides guidelines for logical structural models, assets, threats, and security objectives that are based on real-world practices and are described in a way that is independent of the specific payment instrument used for the TPP payment.
Conformity with the security objectives set out in ISO 23195 can help stakeholders gain trust when establishing a business relationship with TPPSPs.
ISO 23195