Is your biometric data safe online? ISO/IEC standard ensures security and privacy

Biometrics, like fingerprints and iris scans, is being used more and more as a reliable form of authentication for online transactions. But how can we be sure that this data won’t be compromised? To ensure security and privacy when managing and processing biometric information, ISO and the International Electrotechnical Commission (IEC) have jointly published a new International Standard, ISO/IEC 24745:2011, Information technology – Security techniques – Biometric information protection.

Biometrics refers to the automated identification of individuals based on their behavioural and physiological characteristics. It includes recognition technologies based on face, iris or palms image, voice patterns and the like e.g. fingerprint scans used to access a computer, or iris scans to cross border control.

Mr. Myung Geun Chun, Project Editor of ISO/IEC 24745 explains “As the Internet is increasingly used to access services with highly sensitive information, such as eBanking and remote healthcare, the reliability and strength of authentication mechanisms is critical. Biometrics is regarded as a powerful solution because of its unique link to an individual that is nearly or absolutely impossible to fake.

“And the technology has come of age. The cost of biometric techniques has been decreasing, while their reliability and popularity have been growing. But biometric identification raises unique privacy concerns.

“While the unchanging and distinct association with an individual on the one hand, provides strong assurance of authentication, this binding which links biometrics with personally identifiable information on the other hand, carries some risks, including the unlawful processing and use of data. ISO/IEC 24745 is an invaluable tool for addressing those risks.”

With biometrics, if the authentication information is compromised, usual solutions such as issuing a new password or token are not available because biometric characteristics are difficult or impossible to change. Moreover, as more and more personal identifiable information is linked with biometric references, and this data is shared across international borders, it is crucial to safeguard the security of a biometric system and the privacy of data subjects with solid countermeasures as outlined in ISO/IEC 24745.

The standard specifies:

■Analysis of threats and countermeasures inherent in a biometric and biometric system application models
■Security requirements for binding between a biometric reference and an identity reference
■Biometric system application models with different scenarios for the storage and comparison of biometric references
■Guidance on the protection of an individual’s privacy during the processing of biometric information.

iso.org
 
 
Add To Facebook     Add To Twitter              Print | Send | 23 Eylül 2011 Cuma
Last 10 News
23.09.2011 | Are you ready? New ISO standard for ensuring resilience throughout the supply chain
23.09.2011 | ISO publishes Six Sigma performance-improvement methodology
05.07.2010 | Measuring customer satisfaction with new ISO technical specification
05.07.2010 | ISO standards expected to improve quality of marine fuels
09.11.2009 | Launching of The ISO Concept Database (ISO/CDB) will benefit standards users and developers
09.11.2009 | ISO, ILAC and IAF streamline quality management requirements for medical laboratories
09.11.2009 | ISO standard to increase confidence in ship recycling certification
09.11.2009 | ISO standard for cruise control systems promises safer and more enjoyable driving
09.11.2009 | WARC – new ISO file format to store billions of online data
09.11.2009 | New ISO report will contribute to making escape from buildings easier when fire breaks out
Click Here All News

We are looking forward
to working with you.
Phone: +90 0212 211 16 16
Fax: +90 0212 356 20 02
kalite@acarkalite.com
Quality and productivity improvement through our trainings

Quality management system training serves to provide a framework that enables a company to use industry standard vocabulary when describing quality management procedures and processes. Employees who do not deal with customers directly often lack the motivation to improve processes without understanding the direct impact their work has on customer satisfaction and company profit. Click here to see our training programs.
OUR CLIENTS More >>
         
 
Copyright © 2004 | ACAR Quality Consulting Ltd  
ISO 9001       ISO 14001       ISO 22000       HACCP       ISO 18001       ISO13485