IS 18595 : 2024 Electronic Signatures and Infrastructures (ESI) - Policy and Security Requirements for Applications for Signature Creation and Signature Validation

ICS 35.020

SSD 10


This standard provides general security and policy requirements for applications for signature creation, validation and augmentation.

The present standard is primarily relevant to the following stakeholders:

 a) Implementers and providers of applications for signature creation, signature validation and/or signature augmentation, who need to ensure that relevant requirements are covered; and

 b) Stakeholders that integrate applications for signature creation, signature validation and/or signature augmentation components with business process software (or use standalone software), who want to ensure proper functioning of the overall signature creation/validation/augmentation process and that the signature creation/validation is done in a sufficiently secure environment.

The present standard is applicable to these stakeholders, and their evaluators (for a selfevaluation or an evaluation by a third party) to have a list of criteria against which to check the implementation.

The requirements cover applications for signature creation, signature validation and/or signature augmentation, such as the implementation and provision of the Signature Creation Application/Signature Validation Application/Signature Augmentation Application (SCA/SVA/SAA) modules, the Driving Application (DA), the communication between the SCA and the signature creation device (SCDev) and the environment in which the SCA/SVA/SAA is used.

It also specifies user interface requirements, while the user interface can be part of the SCA/SVA/SAA or of the DA which calls the SCA/SVA/SAA. Any entity using SCA/SVA/SAA components in its business process acts as driving application.

The standard covers:

 a) Legal driven policy requirements;

 b) Information security (management system) requirements;

 c) Signature creation, signature validation and signature augmentation processes requirements;

 d) Development and coding policy requirements; and

 e) General requirements.

Protection Profiles (PP) for signature creation applications and signature validation applications are out of scope and are defined in the CEN standard 'Protection Profiles for Signature Creation and Validation Applications' CEN EN 419 111.


