ISO/IEC CD 19989-1

Information security — Criteria and methodology for security evaluation of biometric systems — Part 1: Framework ISO/IEC CD 19989-1

General information

30.60   Close of voting/ comment period   Jun 17, 2026

ISO/IEC

ISO/IEC JTC 1/SC 27 Information security, cybersecurity and privacy protection

International Standard

Scope

For security evaluation of biometric recognition performance and presentation attack detection for biometric verification systems and biometric identification systems, this document specifies:
—    extended security functional components to SFR Classes in ISO/IEC 15408-2;
—    evaluation activities to methodology specified in ISO/IEC 18045 for SAR Classes of ISO/IEC 15408-3.
This document introduces the general framework for the security evaluation of biometric systems, including extended security functional components, and evaluation activities to methodology, which is additional activities and guidance/recommendations for an evaluator to handle those activities. The evaluation activities are developed in this document while the detailed recommendations are developed in ISO/IEC 19989-2 (for biometric recognition performance aspects) and in ISO/IEC 19989-3 (for presentation attack detection aspects). This document is applicable only to TOEs for single biometric characteristic type. However, the selection of a characteristic from multiple characteristics in SFRs is allowed.

Life cycle

PREVIOUSLY

PUBLISHED
ISO/IEC 19989-1:2020

NOW

IN_DEVELOPMENT
ISO/IEC CD 19989-1
30.60 Close of voting/ comment period
Jun 17, 2026




Access Genorma App Everywhere

Get fast and easy access to top European and International standards (EN, ISO, IEC) via your mobile phone, tablet or the web.