For Public Comment DRAFT MALAYSIAN STANDARD

Size: px
Start display at page:

Download "For Public Comment DRAFT MALAYSIAN STANDARD"

Transcription

1 DRAFT MALAYSIAN STANDARD 14G007R1 STAGE: PUBLIC COMMENT (40.20) DATE: 01/08/ /09/2015 Code of practice for deploying secure applications through the Third Party Gateway for Government Multipurpose Card - Part 1: Secure connectivity (First revision) OFFICER/SUPPORT STAFF: (SD / rozi) ICS: Descriptors: code of practice, secure, application, third party gateway, government multipurpose card, connectivity Copyright DEPARTMENT OF STANDARDS MALAYSIA

2 Contents Page Committee representation...ii Foreword... iii Introduction...iv 1 Scope Terms and definitions Abbreviations Card Lifecycle Management System Third Party Gateway infrastructure Authentication and security access... 9 Bibliography STANDARDS MALAYSIA All rights reserved i

3 Committee representation The Industry Standards Committee on Information Technology, Communications and Multimedia (ISC G) under whose authority this Malaysian Standard was developed, comprises representatives from the following organisations: Association of Consulting Engineers Malaysia Chief Government Security Office Cybersecurity Malaysia Department of Standards Malaysia Federation of Malaysian Manufacturers Institut Tadbiran Awam Negara, Malaysia Majlis Keselamatan Negara Malaysian Administrative, Modernisation and Management Planning Unit Malaysian International Chamber of Commerce and Industry Malaysian National Computer Confederation Malaysian Technical Standards Forum Bhd MIMOS Berhad Ministry of Communication and Multimedia Ministry of Domestic Trade, Co-operatives and Consumerism Ministry of Energy, Green Technology and Water Ministry of International Trade and Industry Ministry of Science, Technology and Innovation Multimedia Development Corporation Sdn Bhd Multimedia University Persatuan Industri Komputer dan Multimedia Malaysia Science and Technology Research Institute for Defence SIRIM Berhad (Secretariat) Suruhanjaya Komunikasi dan Multimedia Malaysia Telekom Malaysia Berhad The Institution of Engineers, Malaysia Universiti Teknologi Malaysia The Technical Committee on Identification Cards and Related Devices which developed this Malaysian Standard consists of representatives from the following organisations: CALMS Technologies Sdn Bhd CyberSecurity Malaysia Datasonic Group Berhad IRIS Corporation Berhad Jabatan Imigresen Malaysia Jabatan Pendaftaran Negara Malaysia Malaysian Administrative, Modernisation and Management Planning Unit Malaysian Electronic Payment System Sdn Bhd Malaysian National Computer Confederation MIMOS Berhad Ministry of Home Affairs Multimedia Development Corporation Sdn Bhd Multimedia University Silterra Malaysia Sdn Bhd SIRIM Berhad (Secretariat) Tricubes Berhad Universiti Utara Malaysia ii STANDARDS MALAYSIA All rights reserved

4 Foreword This Malaysian Standard was developed by the Technical Committee on Identification Cards and Related Devices under the authority of the Industry Standards Committee on Information Technology, Communications and Multimedia. MS 2482 consists of the following parts, under the general title Code of practice for deploying secure applications through the Third Party Gateway for Government Multipurpose Card: Part 1 : Secure connectivity Part 2 : Applet configuration Major modifications in this revision are as follows: a) the title has been changed to Code of practice for deploying secure applications through the Third Party Gateway for Government Multipurpose Card - Part 1: Secure connectivity ; b) definitions of generic applet, generic applet module, chip and TPG Agency SAM Bank have been introduced in 2.3, 2.4, 2.5 and 2.13, respectively; c) definition of Secure Access Module (SAM) has been amended in 2.9; d) new Figure 2 regarding Agency s TPG system and network architecture for MyKad Category B has been added; e) new subclauses 6.3.4, and have been added; f) new Figures 4, 5, 6 and 7 have been added; and g) new Tables 4, 5, 6 and 7 have been added. This Malaysian Standard cancels and replaces MS :2012, Code of practice for deploying secure applications through the Third Party Gateway for Malaysia Multipurpose Smart Card - Part 1: Secure connectivity. Compliance with a Malaysian Standard does not of itself confer immunity from legal obligations. STANDARDS MALAYSIA All rights reserved iii

5 Introduction Overview In view of the current situation where many new companies, organisations and agencies are interested to utilise the Government Multipurpose Card (MyKad), to store their business related information, National Registration Department of Malaysia () has established an infrastructure to enable the addition of new applets to be stored in the MyKad chip from external sites/agencies. This connectivity termed as Third Party Gateway (TPG) is the access point to the s Card Lifecycle Management System (CLMS).The external agency requiring the services will need to develop their TPG system interface to connect to the CLMS at. Objective The objective of this standard is to facilitate application development on MyKad through the TPG of the agency. Furthermore, it ensures that these applications are to be deployed in a secure manner through a standard guidance. iv STANDARDS MALAYSIA All rights reserved

6 Code of practice for deploying secure applications through the Third Party Gateway for Government Multipurpose Card - Part 1: Secure connectivity 1 Scope This Malaysian Standard provides guidance for deploying secure applications through the Third Party Gateway (TPG) for the Government Multipurpose Card (GMPC) such as MyKad issued by National Registration Department of Malaysia (). This standard details the remote access framework for delivering secure communication between the authorised agencies TPG systems and the Card Lifecycle Management System (CLMS) at. 2 Terms and definitions For the purposes of this standard, the following terms and definitions apply. 2.1 Application Program Interface Application Programming Interface (API) is an interface implemented by a software program which enables it to interact with other software. In this standard, API refers to the programs interfacing CLMS to the TPG systems. 2.2 Card Lifecycle Management System Card Lifecycle Management System (CLMS) manages the card and its applets lifecycle. 2.3 Generic Applet A pre-determined applet provided by which can be customised and used by other organisations/agencies to store their business related data in MyKad. 2.4 Generic Applet Module A TPG module manages signed applet and TPG Client Secure Access Certificate. 2.5 Chip It is a small electronic device made out of a semiconductor material and commonly referred as integrated circuit. 2.6 MyKad MyKad is a multi-application Integrated Circuit(s) Card (ICC) issued by the National Registration Department of Malaysia to citizens of Malaysia. The artwork for MyKad is blue. There are two categories of MyKad in circulation i.e. Category A and Category B NOTE. For information on the categories of MyKad, refer to. STANDARDS MALAYSIA All rights reserved 1

7 2.7 MyKad applet A set of instructions that enables the creation/deletion of data items in the MyKad chip. 2.8 MyKad reader Software Development Kit (SDK) A set of development tools that is obtained from the respective reader distributor or developer to read open data from MyKad. 2.9 Secure Access Module (SAM) An integrated circuit(s) card used to enhance the security and cryptography performance in secure electronic transactions. The SAM size can be in the form of normal card size of mm wide by mm height by 0.76 mm thick or the nominal size of 25 mm wide by 15 mm height by 0.76 mm thick Simple Object Access Protocol Simple Object Access Protocol (SOAP) is a protocol specification for exchanging structured information in the implementation of web services in computer networks Secure Sockets Layer Secure Sockets Layer (SSL) is a cryptographic protocol that provides security for communications over a network Third Party Gateway Third Party Gateway (TPG) is the access point to the s Card Lifecycle Management System (CLMS). The connectivity between s CLMS web server and the agency s TPG server is secured through the SSL Authentication System TPG Agency SAM Bank (applicable to MyKad Category B) A collection of SAMs housed in a secured hardware provided by to secure the process of initialisation, personalisation and data read write. 3 Abbreviations For the purposes of this standard, the following abbreviations apply. AMM APDU API CLMS CMM Application Management Module Application Protocol Data Unit Application Programming Interface Card Lifecycle Management System Card Management Module 2 STANDARDS MALAYSIA All rights reserved

8 CTM GA GAM GMPC ICC KMM Card Tracking Module Generic Applet Generic Applet Module Government Multipurpose Card Integrated Circuit(s) Card Key Management Module National Registration Department SAM SMM SOAP SSL TLS TPG XML Secure Access Module SAM Management Module Simple Object Access Protocol Secure Sockets Layer Transport Layer Security Third Party Gateway Extensible Markup Language 4 Card Lifecycle Management System 4.1 Overview of CLMS CLMS manages the card and its applets lifecycle. The system records the card historical data from creation until disposal/deactivation. 4.2 CLMS modules and functionalities The CLMS architecture consists of the following modules: a) Card Management Module; b) Card Tracking Module; c) Key Management Module; d) Application Management Module; and e) SAM Management Module. STANDARDS MALAYSIA All rights reserved 3

9 4.2.1 Card Management Module (CMM) The CMM is the core of CLMS which manages and keeps track of the entire lifecycle of MyKad. It contains all components necessary to provide comprehensive card management services, communications, interfacing and security. The card status tracking is managed by CMM which includes but not limited to pre-personalised, personalised, issuance, unblocking, termination, loss or damage. In addition, the card management services also manage the data store, which contains lifecycle tracking information for all the issued cards in the system. The data store also provides centralised tracking, logging, reporting and control for all the functionalities in the CLMS Card Tracking Module (CTM) CTM provides the capability to track and monitor the movement and status of MyKad throughout the card production process. Upon receiving the card serial number from the manufacturer, a new card profile is generated and its status is continuously monitored before leaving the card production centre Key Management Module (KMM) The KMM is a security system that manages the keys used to control MyKad applets. The key management system involves the process of injecting keys and generating SAM cards. The two main roles of the KMM in the CLMS are to: a) generate load/delete certificates for dynamic application loading/deletion purposes; and b) generate master keys, controller and supervisor cards for new MyKad applets. To generate load/delete certificates, KMM will need to work in synchronous with AMM to obtain the necessary applet information required to create the unique load and delete certificates. All communications between these two modules are managed by the CMM. For generating new MyKad scheme master keys, controller and supervisor cards, a generic key generation system shall be implemented Application Management Module (AMM) The AMM in CLMS is primarily responsible for managing the assembly of applets by merging the applets with the unique load/delete certificates for dynamic application loading and deletion purposes. These certificates are obtained from the KMM. All external communications to and from the AMM are managed by the CMM. To successfully assemble a MyKad applet, the AMM also requires the load/delete certificates from KMM. Therefore both AMM and KMM modules have to work in synchronous to produce a complete MyKad applet to be dynamically loaded into a MyKad. Communication between the AMM and KMM is also handled by the CMM. 4 STANDARDS MALAYSIA All rights reserved

10 4.2.5 SAM Management Module (SMM) The SMM is an independent module having its own card management module, application management module, key management module and SAM tracking module which functions in almost the same way as for the CLMS CMM, AMM, KMM and CTM. The SAM card is used to enable a secure read and write to MyKad applet and can reside at any authorised agency. 5 Third Party Gateway infrastructure 5.1 TPG network and architecture TPG infrastructure comprises the agency s TPG centralised server with a number of TPG client workstations interacting with CLMS web server via SSL connection. The infrastructure allows TPG client workstation to perform the downloading/removal of MyKad applets into/from MyKad (see Figures 1 and 2). Prior to the addition/deletion of MyKad applet into or from MyKad, an authentication has to be conducted between agency's TPG and CLMS. The communication between CLMS and TPG agencies shall conform to the following requirements: a) registered TPG client in CLMS; b) secure internet connection; c) security token/soft certificate (provided by ); and d) TPG application which communicates with CLMS Web API through SOAP Messaging. 5.2 TPG system requirements Table 1 indicates the requirements for the agency s TPG system: Table 1. Agency s TPG system requirements No Component Requirement 1. TPG system software a) The TPG system to be developed in web-based environment. b) The software used shall be able to communicate with the provided CLMS Web APIs through SOAP messaging. c) The system software shall be able to communicate with the MyKad reader SDKs. STANDARDS MALAYSIA All rights reserved 5

11 Table 1. Agency s TPG system requirements (continued) No Component Requirement 2. Internet connection through The minimum bandwidth of 156 kbps. SSL 3. Internet browser Cross-browser, with minimum TLS Security token/soft certificate The security token loaded with a valid certificate. 5. TPG system hardware The hardware such as workstation and MyKad reader. 6 STANDARDS MALAYSIA All rights reserved

12 STANDARDS MALAYSIA All rights reserved 7 Figure 1. Agency s TPG system and network architecture for MyKad Category A

13 8 STANDARDS MALAYSIA All rights reserved Figure 2. Agency s TPG system and network architecture for MyKad Category B

14 6 Authentication and security access 6.1 SSL certificate Prior to establishing the connection, shall provide SSL security certificate to the requesting agency. 6.2 SSL authentication module The agency s TPG will first authenticate the SSL authentication module server and establish a secure connection automatically. When the TPG first connects to SSL authentication module, it responds by sending the TPG its security credentials. The TPG then verifies the validity of the security credentials and establish connection with SSL authentication module. 6.3 Web API Uniform Resource Locator (URL) for CLMS Web API The CLMS Web API page will be displayed once successful connection to this website is established CLMS Web API and transaction codes The CLMS transaction codes are given in Table 2. Transaction Codes Table 2. CLMS transaction Transaction Type Output SL007 Dynamic Application Loading Applet Data and Load Certificates SL008 Dynamic Application Deletion Delete Certificates SL009 SL010 Dynamic Application Loading Completion Update Dynamic Application Deletion Completion Update Confirmation that the status has been updated Confirmation that the status has been updated SL011* Card Info Query MyKad Information SL013* Check Card Blacklist Card Blacklist Status SL014* JPN Quick Check Current Card Status * Not applicable to MyKad Category B STANDARDS MALAYSIA All rights reserved 9

15 6.3.3 XML Schema for MyKad Category A To utilise the TPG functionalities, XML messages are sent to according to the XML schema as shown in the Figure 3. Detailed descriptions of each XML tags are described in Table 3. <CLMSAPIWEBREQUEST> <TRANSACTIONCODE> </TRANSACTIONCODE> <TRANSACTIONTYPE> </TRANSACTIONTYPE> <TRANSDATETIME> </TRANSDATETIME> <TRANSACTIONDATA> <KPTNO></KPTNO> <KPTVERNO></KPTVERNO> <CHIPSN></CHIPSN> <NAME> </NAME> <BRANCHCODE> </BRANCHCODE> <USERID> </USERID> <WSID> </WSID> <AID> </AID> <APPVERNO> </APPVERNO> <SEQCTR> </SEQCTR> <TRANSDATE> </TRANSDATE> </TRANSACTIONDATA> </CLMSAPIWEBREQUEST> Figure 3. XML schema for MyKad Category A 10 STANDARDS MALAYSIA All rights reserved

16 STANDARDS MALAYSIA All rights reserved 11 Table 3. XML description for MyKad Category A XML Tag Description Load Remove Completion update for load Completion update for remove Card info query Check card blacklist TransactionCode Transaction code SL007 SL008 SL009 SL010 SL011 SL013 SL014 TransactionType TransDateTime KPTNO KPTVERNO The full description of the transaction The current date and time of transaction Format = YYYYMMDDHHMMSS The cardholder IC number The cardholder IC version number Dynamic Application Loading Current date and time Dynamic Application Deletion Current date and time Dynamic Application Loading Completion Update Current date and time Dynamic Application Deletion Completion Update Current date and time Card info Query Current date and time Check Card Blacklist Current date and time quick check JPN Quick Check Current date and time 0

17 12 STANDARDS MALAYSIA All rights reserved Table 3. XML description for MyKad Category A (continued) XML Tag Description Load Remove Completion update for load Chip SN Name BranchCode UserID WSID The chip serial number Full name of the cardholder The branch code where the transaction is performed The user ID of the person that perform the transaction The workstation ID where the transaction is performed Branch code UserID Workstation ID AID The applet identifier The applet ID to be loaded Branch code UserID Workstation ID Branch code UserID Workstation ID Completion update for remove Branch code UserID Workstation ID Card info query Branch code UserID Workstation ID The applet ID to be removed The applet ID that has been loaded The applet ID that has been removed Check card blacklist Branch code UserID Workstation ID quick check Branch code UserID Workstation ID

18 STANDARDS MALAYSIA All rights reserved 13 Table 3. XML description for MyKad Category A (concluded) XML Tag Description Load Remove Completion update for load AppVerNo Applet version number The applet version number to be loaded SeqCtr Sequence counter The applet version number to be loaded The applet version number that has been loaded The applet version number that has been loaded Completion update for remove The applet version number that has been loaded The applet version number that has been loaded Card info query Check card blacklist quick check TransDate Transaction date Current date Current date Current date Current date Current date Current date Current date

19 6.3.4 XML Schema for MyKad Category B To utilise the TPG functionalities, XML messages are sent to according to the XML schema. The message can be constructed in either SOAP 1.1 format or SOAP 1.2 format SOAP 1.1 format Figure 4 is a sample SOAP 1.1 request. The placeholders shown need to be replaced with actual values (see Table 4). POST /TPGCLMS.asmx HTTP/1.1 Host: [CLMS HOST NAME] Content-Type: text/xml; charset=utf-8 Content-Length: SOAPAction: [CLMS HOST SOAP ACTION] <?xml version="1.0" encoding="utf-8"?> <soap:envelope xmlns:xsi=" xmlns:xsd=" xmlns:soap=" <soap:body> <samrelay xmlns=[clms HOST SAM RELAY URL]> <action>[transaction NAME]</action> <cryptogram> [CRYPTOGRAM PARAMETER] </cryptogram> </samrelay> </soap:body> </soap:envelope> Figure 4. XML schema for SOAP request Table 4. Placeholders description for SOAP request Placeholders CLMS HOST NAME CLMS HOST SOAP ACTION CLMS HOST SAM RELAY URL TRANSACTION NAME CRYPTOGRAM PARAMETER Host name of JPN CLMS Description Action name defined by JPN CLMS URL for SAM Relay defined by JPN CLMS Transaction name defined by JPN CLMS Encrypted parameter constructed by JPN CLMS 14 STANDARDS MALAYSIA All rights reserved

20 Figure 5 is a sample SOAP 1.1 response. The placeholders shown results returned by CLMS (see Table 5). HTTP/ OK Content-Type: text/xml; charset=utf-8 Content-Length: <?xml version="1.0" encoding="utf-8"?> <soap:envelope xmlns:xsi=" xmlns:xsd=" xmlns:soap=" <soap:body> <samrelayresponse xmlns=" <samrelayresult>[result TYPE]</samRelayResult> <result>[cryptogram RESULT]</result> <status>[status CODE]</status> </samrelayresponse> </soap:body> </soap:envelope> Placeholders RESULT TYPE CRYPTOGRAM RESULT STATUS CODE Figure 5. XML schema for SOAP response Table 5. Results description for SOAP response Description Type of results returned by JPN CLMS Encrypted results constructed by JPN CLMS Status code returned by JPN CLMS STANDARDS MALAYSIA All rights reserved 15

21 SOAP 1.2 format Figures 6 is a sample SOAP 1.2 request. The placeholders shown need to be replaced with actual values (see Table 6). POST /TPGCLMS.asmx HTTP/1.1 Host: [CLMS HOST NAME] Content-Type: application/soap+xml; charset=utf-8 Content-Length: 39 <?xml version="1.0" encoding="utf-8"?> <soap12:envelope xmlns:xsi=" xmlns:xsd=" xmlns:soap12=" <soap12:body> <samrelay xmlns=[clms HOST SAM RELAY URL] > <action>[transaction NAME]</action> <cryptogram>[cryptogram PARAMETER]</cryptogram> </samrelay> </soap12:body> </soap12:envelope> Figure 6. XML schema for SOAP request Table 6. Placeholders description for SOAP request Placeholders Description CLMS HOST NAME Host name of JPN CLMS CLMS HOST SOAP ACTION CLMS HOST SAM RELAY URL TRANSACTION NAME CRYPTOGRAM PARAMETER Action name defined by JPN CLMS URL for SAM Relay defined by JPN CLMS Transaction name defined by JPN CLMS Encrypted parameter constructed by JPN CLMS 16 STANDARDS MALAYSIA All rights reserved

22 Figures 7 is a sample SOAP 1.2 response. The placeholders shown results returned by CLMS (see Table 7). HTTP/ OK Content-Type: application/soap+xml; charset=utf-8 Content-Length: <?xml version="1.0" encoding="utf-8"?> <soap12:envelope xmlns:xsi=" xmlns:xsd=" xmlns:soap12=" <soap12:body> <samrelayresponse xmlns=" <samrelayresult>[result TYPE]</samRelayResult> <result>[cryptogram RESULT]</result> <status>[status CODE]</status> </samrelayresponse> </soap12:body> </soap12:envelope> Figure 7. XML schema for SOAP response Table 7. Results description for SOAP response Placeholders Description RESULT TYPE Type of results returned by JPN CLMS CRYPTOGRAM RESULT Encrypted results constructed by JPN CLMS STATUS CODE Status code returned by JPN CLMS STANDARDS MALAYSIA All rights reserved 17

23 Bibliography [1] MS :YYYY, Government Multipurpose Card - Part 1: General characteristics - Code of practice [2] MS :YYYY, Government Multipurpose Card - Part 2: Data format for National ID application - Code of practice [3] ISO/IEC 7816 (all parts), Identification cards - Integrated circuit cards 18 STANDARDS MALAYSIA All rights reserved

24 Acknowledgements Members of Technical Committee on Identification Cards and Related Devices Prof Dr Zulkhairi Mohd Dahalin (Chairman) Ms Syuibah Abirah Tarmizi (Deputy Chairman) Ms Salwa Denan (Secretary) Ms Koh Lee Ching Ms Norahana Salimin/ Mr Ahmad Dahari Jarno Mr Wong Chee Wai/ Mr Ramzani Abd Raub Ms Connie Yee/ Mr Tan Jia Giin/ Ms Anis Azalina Mohamed Ms Nurul Ashikin Subli/ Ms Rohana Ismail Ms Rajeswari Subaramaniam/ Ms Nur Diyana Fazlollah Suhaimi Ms Rohaila Abdul Latif Mr R Kunaseelan Mr Ahmad Nizar Harun/ Ms Siti Sarah Ramli Mr Tahiruddin Hamdan Mr Shamsul Azhar Mohd Akhbar Universiti Utara Malaysia Multimedia Development Corporation Sdn Bhd SIRIM Berhad CALMS Tecnologies Sdn Bhd CyberSecurity Malaysia Datasonic Group Berhad IRIS Corporation Berhad Jabatan Imigresen Malaysia Jabatan Pendaftaran Negara Malaysia Malaysian Electronic Payment System Sdn Bhd Malaysian National Computer Confederation MIMOS Berhad Silterra Malaysia Sdn Bhd Tricubes Berhad STANDARDS MALAYSIA All rights reserved

For Public Comment DRAFT MALAYSIAN STANDARD

For Public Comment DRAFT MALAYSIAN STANDARD DRAFT MALAYSIAN STANDARD 14G008R1 STAGE: PUBLIC COMMENT (40.20) DATE: 01/08/2015-30/09/2015 Code of practice for deploying secure applications through the Third Party Gateway for Government Multipurpose

More information

DRAFT MALAYSIAN STANDARD. Government Multipurpose Card - Part 1: General characteristics - Code of practice (First revision)

DRAFT MALAYSIAN STANDARD. Government Multipurpose Card - Part 1: General characteristics - Code of practice (First revision) DRAFT MALAYSIAN STANDARD 14G005R1 STAGE: PUBLIC COMMENT (40.20) DATE: 01/08/2015-30/09/2015 Government Multipurpose Card - Part 1: General characteristics - Code of practice (First revision) OFFICER/SUPPORT

More information

MALAYSIAN STANDARD INFORMATION AND DOCUMENTATION - RECORDS MANAGEMENT - PART 1: GENERAL (ISO :2001, IDT)

MALAYSIAN STANDARD INFORMATION AND DOCUMENTATION - RECORDS MANAGEMENT - PART 1: GENERAL (ISO :2001, IDT) MALAYSIAN STANDARD MS 2223-1:2009 INFORMATION AND DOCUMENTATION - RECORDS MANAGEMENT - PART 1: GENERAL (ISO 15489-1:2001, IDT) ICS: 01.140.20 Descriptors: information, documentation, record management,

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Software asset management Part 2: Software identification tag

ISO/IEC INTERNATIONAL STANDARD. Information technology Software asset management Part 2: Software identification tag INTERNATIONAL STANDARD ISO/IEC 19770-2 First edition 2009-11-15 Information technology Software asset management Part 2: Software identification tag Technologies de l'information Gestion de biens de logiciel

More information

SYSTEMS PLANNING AND MANAGEMENT TOWARDS SMART GRID APPLICATION

SYSTEMS PLANNING AND MANAGEMENT TOWARDS SMART GRID APPLICATION Terms SEMINAR and ON Conditions MALAYSIAN STANDARDS FOR POWER 14-May-15 (Thursday),, Auditorium Dato Yahaya Ahmad, SIRIM Berhad, Shah Alam Introduction Tentative Programme The Malaysian Grid Code (Grid

More information

LEGISLATIVE SITUATION IN MALAYSIA

LEGISLATIVE SITUATION IN MALAYSIA ATTACHMENT 13 LEGISLATIVE SITUATION IN MALAYSIA Pirunthavany Muthuvelu Ministry of Health Malaysia (MOH) Engineering Services Division BACKGROUND There were public concerns over the health effects of base

More information

Glossary of Exchange Network Related Groups

Glossary of Exchange Network Related Groups Glossary of Exchange Network Related Groups CDX Central Data Exchange EPA's Central Data Exchange (CDX) is the point of entry on the National Environmental Information Exchange Network (Exchange Network)

More information

Factsheet of Public Services Infrastructure (PSi) Updated on: 1st Sep 03

Factsheet of Public Services Infrastructure (PSi) Updated on: 1st Sep 03 Factsheet of Public Services Infrastructure (PSi) Updated on: 1st Sep 03 1 Objective of Paper 1.1 This document provides an overview of the Public Services Infrastructure (PSi). 2 Overview of PSi 2.1 PSi

More information

Information technology IT asset management Overview and vocabulary

Information technology IT asset management Overview and vocabulary INTERNATIONAL STANDARD ISO/IEC 19770-5 Second edition 2015-08-01 Information technology IT asset management Overview and vocabulary Technologies de l information Gestion de biens de logiciel Vue d ensemble

More information

SPARROW Gateway. Custom Payment Redirect. Version (Build 7373)

SPARROW Gateway. Custom Payment Redirect. Version (Build 7373) SPARROW Gateway Custom Payment Redirect Version 3.2.0 (Build 7373) Released September 2016 Revision History Date Revision Comments Author 2015 06 09 1.0 Initial document created Blinova Alexandra 2 Table

More information

ISO/TR TECHNICAL REPORT. Financial services Information security guidelines

ISO/TR TECHNICAL REPORT. Financial services Information security guidelines TECHNICAL REPORT ISO/TR 13569 Third edition 2005-11-15 Financial services Information security guidelines Services financiers Lignes directrices pour la sécurité de l'information Reference number ISO/TR

More information

Data Transport. Publisher's Note

Data Transport. Publisher's Note Data Transport Publisher's Note This document should be considered a draft until the message formats have been tested using the latest release of the Apache Foundation's SOAP code. When those tests are

More information

ISO INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO 8583-1 First edition 2003-06-15 Financial transaction card originated messages Interchange message specifications Part 1: Messages, data elements and code values Messages initiés

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Multimedia content description interface Part 5: Multimedia description schemes

ISO/IEC INTERNATIONAL STANDARD. Information technology Multimedia content description interface Part 5: Multimedia description schemes INTERNATIONAL STANDARD ISO/IEC 15938-5 First edition 2003-05-15 Information technology Multimedia content description interface Part 5: Multimedia description schemes Technologies de l'information Interface

More information

TRAINING PROVIDER S CIRCULAR NO. 1/2014 THE NEW TERMS AND CONDITIONS FOR REGISTRATION OF TRAINING PROVIDERS, TRAINING PROGRAMMES AND COURSES

TRAINING PROVIDER S CIRCULAR NO. 1/2014 THE NEW TERMS AND CONDITIONS FOR REGISTRATION OF TRAINING PROVIDERS, TRAINING PROGRAMMES AND COURSES Our Ref.: (36)PSMB/1/14/13 Kulit 2 Date : 16 January 2014 TRAINING PROVIDER S CIRCULAR NO. 1/2014 THE NEW TERMS AND CONDITIONS FOR REGISTRATION OF TRAINING PROVIDERS, TRAINING PROGRAMMES AND COURSES 1.0

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 18013-2 First edition 2008-05-15 Information technology Personal identification ISO-compliant driving licence Part 2: Machine-readable technologies Technologies de l'information

More information

Australian/New Zealand Standard

Australian/New Zealand Standard AS/NZS ISO/IEC 18028.4:2006 ISO/IEC 18028-4:2005 AS/NZS ISO/IEC 18028.4:2006 Australian/New Zealand Standard Information technology Security techniques IT network security Part 4: Securing remote access

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO 17090-1 Second edition 2013-05-01 Health informatics Public key infrastructure Part 1: Overview of digital certificate services Informatique de santé Infrastructure de clé publique

More information

ISO INTERNATIONAL STANDARD. Road vehicles Extended data link security. Véhicules routiers Sécurité étendue de liaison de données

ISO INTERNATIONAL STANDARD. Road vehicles Extended data link security. Véhicules routiers Sécurité étendue de liaison de données INTERNATIONAL STANDARD ISO 15764 First edition 2004-08-15 Road vehicles Extended data link security Véhicules routiers Sécurité étendue de liaison de données Reference number ISO 15764:2004(E) ISO 2004

More information

IHS Haystack Web Services Quick Start Guide April 2014

IHS Haystack Web Services Quick Start Guide April 2014 IHS Haystack Web Services Quick Start Guide April 2014 Table of Contents: Overview Methods GetFLISBriefResultsByCAGECodeAndPartNumber GetFLISBriefResultsByPartNumber GetFLISSummaryResultsByMultipleNIINs

More information

Fax Broadcast Web Services

Fax Broadcast Web Services Fax Broadcast Web Services Table of Contents WEB SERVICES PRIMER... 1 WEB SERVICES... 1 WEB METHODS... 1 SOAP ENCAPSULATION... 1 DOCUMENT/LITERAL FORMAT... 1 URL ENCODING... 1 SECURE POSTING... 1 FAX BROADCAST

More information

SOLUTION ARCHITECTURE AND TECHNICAL OVERVIEW. Decentralized platform for coordination and administration of healthcare and benefits

SOLUTION ARCHITECTURE AND TECHNICAL OVERVIEW. Decentralized platform for coordination and administration of healthcare and benefits SOLUTION ARCHITECTURE AND TECHNICAL OVERVIEW Decentralized platform for coordination and administration of healthcare and benefits ENABLING TECHNOLOGIES Blockchain Distributed ledgers Smart Contracts Relationship

More information

SELF SERVICE INTERFACE CODE OF CONNECTION

SELF SERVICE INTERFACE CODE OF CONNECTION SELF SERVICE INTERFACE CODE OF CONNECTION Definitions SSI Administration User Identity Management System Identity Provider Service Policy Enforcement Point (or PEP) SAML Security Patch Smart Card Token

More information

ISO 7200 INTERNATIONAL STANDARD. Technical product documentation Data fields in title blocks and document headers

ISO 7200 INTERNATIONAL STANDARD. Technical product documentation Data fields in title blocks and document headers INTERNATIONAL STANDARD ISO 7200 Second edition 2004-02-15 Technical product documentation Data fields in title blocks and document headers Documentation technique de produits Champs de données dans les

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 7816-2 Second edition 2007-10-15 Identification cards Integrated circuit cards Part 2: Cards with contacts Dimensions and location of the contacts Cartes d'identification

More information

ETSI TR V1.1.1 ( )

ETSI TR V1.1.1 ( ) TR 119 400 V1.1.1 (2016-03) TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); Guidance on the use of standards for trust service providers supporting digital signatures and related services

More information

INSURER BATCH UPLOAD GUIDE NORTH CAROLINA SURPLUS LINES ASSOCIATION

INSURER BATCH UPLOAD GUIDE NORTH CAROLINA SURPLUS LINES ASSOCIATION INSURER BATCH UPLOAD GUIDE NORTH CAROLINA SURPLUS LINES ASSOCIATION TABLE OF CONTENTS 1 Document Metadata... 4 1.1 Authors... 4 1.2 Intended Audience... 4 1.3 Glossary of Terms and Acronyms... 4 1.4 Document

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO/IEC 19770-5 Second edition 2015-08-01 Information technology IT asset management Overview and vocabulary Technologies de l information Gestion de biens de logiciel Vue d ensemble

More information

ISO INTERNATIONAL STANDARD. Health informatics Harmonized data types for information interchange

ISO INTERNATIONAL STANDARD. Health informatics Harmonized data types for information interchange INTERNATIONAL STANDARD ISO 21090 First edition 2011-02-15 Health informatics Harmonized data types for information interchange Informatique de santé Types de données harmonisées pour une interchangeabilité

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 9594-8 Sixth edition 2008-12-15 Information technology Open Systems Interconnection The Directory: Publickey and attribute certificate frameworks Technologies de l'information

More information

Table of Contents. Page 1 of 6 (Last updated 27 April 2017)

Table of Contents. Page 1 of 6 (Last updated 27 April 2017) Table of Contents What is Connect?... 2 Physical Access Controls... 2 User Access Controls... 3 Systems Architecture... 4 Application Development... 5 Business Continuity Management... 5 Other Operational

More information

Batch Submission Manual for Insurers March 1, 2013

Batch Submission Manual for Insurers March 1, 2013 New Jersey Department of Banking and Insurance SLAS Implementation Batch Submission Manual for Insurers March 1, 2013 PO Box 325 Trenton, NJ 08625 Phone: 609.292.7272 Fax: 609.777.0508 http://www.state.nj.us/dobi

More information

OIML-CS PD-05 Edition 2

OIML-CS PD-05 Edition 2 PROCEDURAL DOCUMENT OIML-CS PD-05 Edition 2 Processing an application for an OIML Type Evaluation Report and OIML Certificate OIML-CS PD-05 Edition 2 ORGANISATION INTERNATIONALE DE MÉTROLOGIE LÉGALE INTERNATIONAL

More information

Summary of Updates CPS Revision 7 (Amendment from CPS Revision 6) 15 June 2018

Summary of Updates CPS Revision 7 (Amendment from CPS Revision 6) 15 June 2018 Summary of Updates CPS Revision 7 (Amendment from CPS Revision 6) 15 June 2018 Section CPS Revision 6 CPS Revision 7 Reasoning / Notes 1.4.2 Prohibited certificate uses: 1.4.2 Prohibited certificate uses:

More information

ISO/IEC Information technology Software asset management. Part 2: Software identification tag

ISO/IEC Information technology Software asset management. Part 2: Software identification tag INTERNATIONAL STANDARD ISO/IEC 19770-2 Second edition 2015-10-01 Corrected version 2017-02 Information technology Software asset management Part 2: Software identification tag Technologies de l information

More information

ISO/IEC INTERNATIONAL STANDARD. Identification cards Integrated circuit cards Part 4: Organization, security and commands for interchange

ISO/IEC INTERNATIONAL STANDARD. Identification cards Integrated circuit cards Part 4: Organization, security and commands for interchange INTERNATIONAL STANDARD ISO/IEC 7816-4 Third edition 2013-04-15 Identification cards Integrated circuit cards Part 4: Organization, security and commands for interchange Cartes d'identification Cartes à

More information

GS1Trade Sync Data Pool - FTPS Service

GS1Trade Sync Data Pool - FTPS Service GS1Trade Sync Data Pool - FTPS Service Connectivity Guide Version 1.0, Draft/Approved, 2018.08.05 GS1 Hungary Document Summary Document Item Document Name Current Value (Connectivity Guide) Document Date

More information

Is your organization ready for ISMS certification?

Is your organization ready for ISMS certification? Is your organization ready for ISMS certification? By: HALIZA IBRAHIM What are management systems? An organization s structure for the identification, establishment, control, monitoring and improvement

More information

PKCS #15: Conformance Profile Specification

PKCS #15: Conformance Profile Specification Table of Contents PKCS #15: Conformance Profile Specification RSA Laboratories August 1, 2000 1 INTRODUCTION... 2 1 REFERENCES AND RELATED DOCUMENTS... 2 2 DEFINITIONS... 2 3 SYMBOLS AND ABBREVIATIONS...

More information

AN UPDATE ON MALAYSIAN STANDARDS ON HALAL

AN UPDATE ON MALAYSIAN STANDARDS ON HALAL AN UPDATE ON MALAYSIAN STANDARDS ON HALAL RIDZWAN KASIM Senior Director (Standardisation) Department of Standards Malaysia Ministry of Science, Technology and Innovation ridzwan@jsm.gov.my +603-83182225

More information

APA Web Services Access Request

APA Web Services Access Request APA Web Services Access Request For Gas Transmission Customers Version: v0.6 Date: 21 st April 2015 All rights reserved. No part of this document may be reproduced, stored in a retrieval system or transmitted

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO 14906 Second edition 2011-10-15 Electronic fee collection Application interface definition for dedicated shortrange communication Perception du télépéage Définition de l'interface

More information

SC27 WG4 Mission. Security controls and services

SC27 WG4 Mission. Security controls and services copyright ISO/IEC JTC 1/SC 27, 2012. This is an SC27 public document and is distributed as is for the sole purpose of awareness and promotion of SC 27 standards and so the text is not to be used for commercial

More information

TECHNICAL SPECIFICATION

TECHNICAL SPECIFICATION TECHNICAL SPECIFICATION IEC/TS 62351-5 Edition 2.0 2013-04 Power systems management and associated information exchange Data and communications security Part 5: Security for IEC 60870-5 and derivatives

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 9594-8 Fifth edition 2005-12-15 Information technology Open Systems Interconnection The Directory: Publickey and attribute certificate frameworks Technologies de l'information

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO 14817-1 First edition 2015-10-15 Intelligent transport systems ITS central data dictionaries Part 1: Requirements for ITS data definitions Systèmes intelligents de transport

More information

Mobile Communications Client Server System for Stock Exchange e-services Access

Mobile Communications Client Server System for Stock Exchange e-services Access Mobile Communications Client Server System for Stock Exchange e-services Access E. Pop, and M. Barbos Abstract Using mobile Internet access technologies and e- services, various economic agents can efficiently

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 7816-3 Third edition 2006-11-01 Identification cards Integrated circuit cards Part 3: Cards with contacts Electrical interface and transmission protocols Cartes d'identification

More information

ISO Intelligent transport systems Reference model architecture(s) for the ITS sector Data presentation in ASN.1

ISO Intelligent transport systems Reference model architecture(s) for the ITS sector Data presentation in ASN.1 INTERNATIONAL STANDARD ISO 14813-6 First edition 2009-09-15 Intelligent transport systems Reference model architecture(s) for the ITS sector Part 6: Data presentation in ASN.1 Systèmes intelligents de

More information

Security Policy for Schlumberger Cyberflex Access 32K Smart Card with ActivCard Applets

Security Policy for Schlumberger Cyberflex Access 32K Smart Card with ActivCard Applets Security Policy for Schlumberger Cyberflex Access 32K Smart Card with ActivCard Applets TABLE OF CONTENTS 1 SCOPE OF DOCUMENT... 1 2 INTRODUCTION... 1 3 SECURITY LEVELS... 1 3.1 CRYPTOGRAPHIC MODULE SPECIFICATION...

More information

SPARROW Gateway. Developer API. Version (Build 7373)

SPARROW Gateway. Developer API. Version (Build 7373) SPARROW Gateway Developer API Version 3.2.0 (Build 7373) Released September 2016 Revision History Date Revision Comments Author 2016 02 26 2.0 Initial document created Alexandra Blinova 2 Table of Contents

More information

Australian/New Zealand Standard

Australian/New Zealand Standard AS/NZS ISO/IEC 27005:2012 Australian/New Zealand Standard Information technology Security techniques Information security risk management (ISO/IEC 27005:2011, MOD) This Joint Australian/New Zealand Standard

More information

NATIONAL STUDENT INDEX

NATIONAL STUDENT INDEX NATIONAL STUDENT INDEX The Guide To Integrating With the National Student Index Specifications document for ECE Student Management System and the ELI Service Portal integrating with the National Student

More information

ISO/IEC INTERNATIONAL STANDARD. Identification cards Integrated circuit card programming interfaces Part 2: Generic card interface

ISO/IEC INTERNATIONAL STANDARD. Identification cards Integrated circuit card programming interfaces Part 2: Generic card interface INTERNATIONAL STANDARD ISO/IEC 24727-2 First edition 2008-10-01 Identification cards Integrated circuit card programming interfaces Part 2: Generic card interface Cartes d'identification Interfaces programmables

More information

Identification and Authentication

Identification and Authentication Identification and Authentication Example Policy Author: A Heathcote Date: 24/05/2017 Version: 1.0 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information Centre

More information

ITU-T Y Next generation network evolution phase 1 Overview

ITU-T Y Next generation network evolution phase 1 Overview I n t e r n a t i o n a l T e l e c o m m u n i c a t i o n U n i o n ITU-T Y.2340 TELECOMMUNICATION STANDARDIZATION SECTOR OF ITU (09/2016) SERIES Y: GLOBAL INFORMATION INFRASTRUCTURE, INTERNET PROTOCOL

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Multimedia content description interface Part 1: Systems

ISO/IEC INTERNATIONAL STANDARD. Information technology Multimedia content description interface Part 1: Systems INTERNATIONAL STANDARD ISO/IEC 15938-1 First edition 2002-07-01 Information technology Multimedia content description interface Part 1: Systems Technologies de l'information Interface de description du

More information

Information technology Security techniques Telebiometric authentication framework using biometric hardware security module

Information technology Security techniques Telebiometric authentication framework using biometric hardware security module INTERNATIONAL STANDARD ISO/IEC 17922 First edition 2017-09 Information technology Security techniques Telebiometric authentication framework using biometric hardware security module Technologies de l information

More information

GS1 Finland Synkka Data Pool Connectivity guide - FTPS Service

GS1 Finland Synkka Data Pool Connectivity guide - FTPS Service Synkka Data Pool Connectivity guide - FTPS Service Connectivity Guide Version 1.0, Draft/Approved, 2017.06.16. Document Summary Document Item Document Name Current Value Synkka Data Pool - FTPS Connection

More information

Berner Fachhochschule. Technik und Informatik. Web Services. An Introduction. Prof. Dr. Eric Dubuis Berner Fachhochschule Biel

Berner Fachhochschule. Technik und Informatik. Web Services. An Introduction. Prof. Dr. Eric Dubuis Berner Fachhochschule Biel Berner Fachhochschule Technik und Informatik Web Services An Introduction Prof. Dr. Eric Dubuis Berner Fachhochschule Biel Overview Web Service versus Web Application A Definition for the Term Web Service

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 7816-2 Second edition 2007-10-15 Identification cards Integrated circuit cards Part 2: Cards with contacts Dimensions and location of the contacts Cartes d'identification

More information

ISO/IEC/ IEEE INTERNATIONAL STANDARD

ISO/IEC/ IEEE INTERNATIONAL STANDARD This is a preview - click here to buy the full publication INTERNATIONAL STANDARD ISO/IEC/ IEEE 26531 First edition 2015-05-15 Systems and software engineering Content management for product lifecycle,

More information

DCCKI Interface Design Specification. and. DCCKI Repository Interface Design Specification

DCCKI Interface Design Specification. and. DCCKI Repository Interface Design Specification DCCKI Interface Design Specification and DCCKI Repository Interface Design Specification 1 INTRODUCTION Document Purpose 1.1 Pursuant to Section L13.13 of the Code (DCCKI Interface Design Specification),

More information

Main title goes here EDT Hub API Specification v2.9

Main title goes here EDT Hub API Specification v2.9 Main title goes here EDT Hub API Specification v2.9 Prepared by: Philip Young, PCTI IS2 Folder: Internal\Technical\Products\EDT Date: Monday, 24 September 2007 Revision No: 2.9 (EDT Hub version 800800

More information

Inland Revenue. Build Pack. Identity and Access Services. Date: 04/09/2017 Version: 1.5 IN CONFIDENCE

Inland Revenue. Build Pack. Identity and Access Services. Date: 04/09/2017 Version: 1.5 IN CONFIDENCE Inland Revenue Build Pack Identity and Access Services Date: 04/09/2017 Version: 1.5 IN CONFIDENCE About this Document This document is intended to provide Service Providers with the technical detail required

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 9594-8 Fourth edition 2001-08-01 Information technology Open Systems Interconnection The Directory: Public-key and attribute certificate frameworks Technologies de l'information

More information

APA Automatic Nomination System. FTPS Access Request. For Gas Transmission Customers

APA Automatic Nomination System. FTPS Access Request. For Gas Transmission Customers APA Automatic Nomination System FTPS Access Request For Gas Transmission Customers Version: v0.7 Date: 29 th November 2012 All rights reserved. No part of this document may be reproduced, stored in a retrieval

More information

Oracle Access Manager 10g - Oracle Enterprise Gateway Integration Guide

Oracle Access Manager 10g - Oracle Enterprise Gateway Integration Guide An Oracle White Paper June 2011 Oracle Access Manager 10g - Oracle Enterprise Gateway Integration Guide 1/26 Disclaimer The following is intended to outline our general product direction. It is intended

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 23009-1 First edition 2012-04-01 Information technology Dynamic adaptive streaming over HTTP (DASH) Part 1: Media presentation description and segment formats Technologies

More information

Smart Cards and Authentication. Jose Diaz Director, Technical and Strategic Business Development Thales Information Systems Security

Smart Cards and Authentication. Jose Diaz Director, Technical and Strategic Business Development Thales Information Systems Security Smart Cards and Authentication Jose Diaz Director, Technical and Strategic Business Development Thales Information Systems Security Payment Landscape Contactless payment technology being deployed Speeds

More information

ISO/IEC Information technology Multimedia framework (MPEG-21) Part 3: Digital Item Identification

ISO/IEC Information technology Multimedia framework (MPEG-21) Part 3: Digital Item Identification INTERNATIONAL STANDARD ISO/IEC 21000-3 First edition 2003-04-01 Information technology Multimedia framework (MPEG-21) Part 3: Digital Item Identification Technologies de l'information Cadre multimédia

More information

PKI Knowledge Dissemination Program. PKI Standards. Dr. Balaji Rajendran Centre for Development of Advanced Computing (C-DAC) Bangalore

PKI Knowledge Dissemination Program. PKI Standards. Dr. Balaji Rajendran Centre for Development of Advanced Computing (C-DAC) Bangalore PKI Standards Dr. Balaji Rajendran Centre for Development of Advanced Computing (C-DAC) Bangalore Under the Aegis of Controller of Certifying Authorities (CCA) Government of India 1 PKCS Why PKCS? Even

More information

ISO/IEC Identification cards Integrated circuit cards Part 12: Cards with contacts USB electrical interface and operating procedures

ISO/IEC Identification cards Integrated circuit cards Part 12: Cards with contacts USB electrical interface and operating procedures INTERNATIONAL STANDARD ISO/IEC 7816-12 First edition 2005-10-01 Identification cards Integrated circuit cards Part 12: Cards with contacts USB electrical interface and operating procedures Cartes d'identification

More information

XenApp 5 Security Standards and Deployment Scenarios

XenApp 5 Security Standards and Deployment Scenarios XenApp 5 Security Standards and Deployment Scenarios 2015-03-04 20:22:07 UTC 2015 Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement Contents XenApp 5 Security Standards

More information

ISO 2146 INTERNATIONAL STANDARD. Information and documentation Registry services for libraries and related organizations

ISO 2146 INTERNATIONAL STANDARD. Information and documentation Registry services for libraries and related organizations INTERNATIONAL STANDARD ISO 2146 Third edition 2010-04-15 Information and documentation Registry services for libraries and related organizations Information et documentation Services de registre pour les

More information

Symmetric Key Services Markup Language Use Cases

Symmetric Key Services Markup Language Use Cases Symmetric Key Services Markup Language Use Cases Document Version 1.1 - February 28, 2007 The OASIS Symmetric Key Services Markup Language (SKSML) is the proposed language/protocol that defines how a client

More information

e-authentication guidelines for esign- Online Electronic Signature Service

e-authentication guidelines for esign- Online Electronic Signature Service e-authentication guidelines for esign- Online Electronic Signature Service (Issued under Electronic Signature or Electronic Authentication Technique and Procedure Rules, 2015) Version 1.3 April 2017 Controller

More information

Overview of cryptovision's eid Product Offering. Presentation & Demo

Overview of cryptovision's eid Product Offering. Presentation & Demo Presentation & Demo Benjamin Drisch, Adam Ross cv cryptovision GmbH T: +49 (0) 209.167-24 50 F: +49 (0) 209.167-24 61 info(at)cryptovision.com 1 General Requirements Government of Utopia Utopia Electronic

More information

SMKI Code of Connection

SMKI Code of Connection SMKI Code of Connection DCC Public Page 1 of 12 Contents 1 Connection Mechanism... 4 1.1 Browser Policy... 4 2 SMKI Services interfaces... 5 2.1 SMKI Services interfaces via DCC Gateway Connection... 5

More information

CMDP-STATE DATABASE INTERFACE CONTROL DOCUMENT

CMDP-STATE DATABASE INTERFACE CONTROL DOCUMENT CMDP-STATE DATABASE INTERFACE CONTROL DOCUMENT Prepared for: WILL BOWMAN PRODUCT OWNER U.S. EPA OFFICE OF WATER KRISTEN GASTNER PROJECT MANAGER U.S. EPA OFFICE OF WATER Prepared by: ATTAIN 1600 TYSONS

More information

OIML-CS PD-08 Edition 1

OIML-CS PD-08 Edition 1 PROCEDURAL DOCUMENT OIML-CS PD-08 Edition 1 Signing the OIML-CS Declaration OIML-CS PD-08 Edition 1 ORGANISATION INTERNATIONALE DE METROLOGIE LEGALE INTERNATIONAL ORGANIZATION OF LEGAL METROLOGY Contents

More information

INTERNATIONAL STANDARD

INTERNATIONAL STANDARD INTERNATIONAL STANDARD This is a preview - click here to buy the full publication ISO/IEC 9594-8 Eighth edition 2017-05 Information technology Open Systems Interconnection The Directory Part 8: frameworks

More information

Hub API Specification

Hub API Specification Hub API Specification Version: 2.13 Published: 18.06.15 Docman is the trading name of PCTI Solutions Ltd. Pioneer Court, Pioneer Way Whitwood, Castleford WF10 5QU 2013 PCTI Solutions Ltd. Docman is the

More information

simply secure IncaMail Information security Version: V01.10 Date: 16. March 2018 Post CH Ltd 1 / 12

simply secure IncaMail Information security Version: V01.10 Date: 16. March 2018 Post CH Ltd 1 / 12 simply secure IncaMail Information security Version: V01.10 Date: 16. March 2018 Post CH Ltd 1 / 12 Contents 1 Introduction... 3 2 Basic principles... 3 3 Connection types... 4 3.1 Mail Gateway Integration

More information

ETSI TS V1.2.1 ( )

ETSI TS V1.2.1 ( ) TS 101 871-2 V1.2.1 (2003-04) Technical Specification Digital Enhanced Cordless Telecommunications (DECT); Application Specific Access Profile (ASAP); DECT Multimedia Access Profile (DMAP); Profile requirement

More information

ISO INTERNATIONAL STANDARD. Information and documentation Records management processes Metadata for records Part 1: Principles

ISO INTERNATIONAL STANDARD. Information and documentation Records management processes Metadata for records Part 1: Principles INTERNATIONAL STANDARD ISO 23081-1 First edition 2006-01-15 Information and documentation Records management processes Metadata for records Part 1: Principles Information et documentation Processus de

More information

Technical Guideline TR eid-client Part 2: Conformance Test Specification. Version 1.3

Technical Guideline TR eid-client Part 2: Conformance Test Specification. Version 1.3 Technical Guideline TR-03124-2 e-client Part 2: Conformance Test Specification Version 1.3 12. June 2017 Federal Office for Information Security Post Box 20 03 63 D-53133 Bonn Phone: +49 22899 9582-0 E-Mail:

More information

ISO INTERNATIONAL STANDARD. Information and documentation Records management Part 1: General

ISO INTERNATIONAL STANDARD. Information and documentation Records management Part 1: General Provläsningsexemplar / Preview INTERNATIONAL STANDARD ISO 15489-1 First edition 2001-09-15 Information and documentation Records management Part 1: General Information et documentation «Records management»

More information

Personalization and Card Issuance. Bob Beer Vice President - Business Development Datacard Group June 4, 2002

Personalization and Card Issuance. Bob Beer Vice President - Business Development Datacard Group June 4, 2002 Personalization and Card Issuance Bob Beer Vice President - Business Development Datacard Group June 4, 2002 The complexity of multi-application cards and the need for process intense solutions 2 Multi-

More information

Ministry of Health and Long-Term Care EBS HCV SOAP Specification Version 4.2

Ministry of Health and Long-Term Care EBS HCV SOAP Specification Version 4.2 Technical Specification for Health Card Validation (HCV) Service via Electronic Business Services (EBS) Ministry of Health and Long-Term Care EBS HCV SOAP Specification Version 4.2 Table of Contents Chapter

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO 9564-4 First edition 2016-03-01 Financial services Personal Identification Number (PIN) management and security Part 4: Requirements for PIN handling in ecommerce for Payment

More information

e-sign and TimeStamping

e-sign and TimeStamping e-sign and TimeStamping Dr. Balaji Rajendran Centre for Development of Advanced Computing (C-DAC) Bangalore Under the Aegis of Controller of Certifying Authorities (CCA) Government of India 1 Recent Developments:

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO/IEC 29151 First edition 2017-08 Information technology Security techniques Code of practice for personally identifiable information protection Technologies de l'information Techniques

More information

Development of smart authentication and identification in Asia

Development of smart authentication and identification in Asia Development of smart authentication and identification in Asia Asia PKI Consortium Dr. Wei-Chung Hwang weichung.hwang@gmail.com Nov 16, 2017 Agenda About APKIC Background Current Development New trends

More information

ISO INTERNATIONAL STANDARD. Quality management Customer satisfaction Guidelines for codes of conduct for organizations

ISO INTERNATIONAL STANDARD. Quality management Customer satisfaction Guidelines for codes of conduct for organizations INTERNATIONAL STANDARD ISO 10001 First edition 2007-12-01 Quality management Customer satisfaction Guidelines for codes of conduct for organizations Management de la qualité Satisfaction du client Lignes

More information

ISO INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO 15745-1 First edition 2003-03-01 Industrial automation systems and integration Open systems application integration framework Part 1: Generic reference description Systèmes d'automatisation

More information

Learn how to explain the purpose and business benefits of an ISMS, of ISMS standards, of management system audit and of third-party certification

Learn how to explain the purpose and business benefits of an ISMS, of ISMS standards, of management system audit and of third-party certification LAST UPDATED 03-01-2018 ISMS (ISO/IEC 27001:2013) AUDITOR / LEAD AUDITOR TRAINING COURSE (A17533) COURSE DURATION: 5 DAYS LEARNING OBJECTIVES Learn how to explain the purpose and business benefits of an

More information

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Supplier's declaration of conformity Part 1: General requirements

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Supplier's declaration of conformity Part 1: General requirements INTERNATIONAL STANDARD ISO/IEC 17050-1 First edition 2004-10-01 Conformity assessment Supplier's declaration of conformity Part 1: General requirements Évaluation de la conformité Déclaration de conformité

More information

Information Technology Security Guideline. Network Security Zoning

Information Technology Security Guideline. Network Security Zoning Information Technology Security Guideline Network Security Zoning Design Considerations for Placement of s within Zones ITSG-38 This page intentionally left blank. Foreword The Network Security Zoning

More information