ISO/IEC TR 6114:2023

Cybersecurity — Security considerations throughout the product life cycle ISO/IEC TR 6114:2023

Publication date:   Oct 10, 2023

General information

60.60 Standard published   Oct 10, 2023

ISO/IEC

ISO/IEC JTC 1/SC 27 Information security, cybersecurity and privacy protection

Technical Report

35.030   IT Security

Buying

Published

Language in which you want to receive the document.

Scope

This document describes security considerations throughout the product life cycle (SCLC), which is a framework that spans the entire information and communications technology (ICT) product life cycle. The aim of the framework is to align the industry and bring greater transparency to customers at every point on the ICT product life cycle.
This document describes the following items for suppliers, end users (consumers), intermediaries of the ICT supply chain, service providers, and regulators:
—     definition of phases in the ICT product life cycle from concept to retirement;
—     threat vectors possible in each phase of the life cycle;
—     potential controls against those threat vectors.
The target audiences of this document are suppliers and consumers of ICT products, including all participants throughout the supply chain such as silicon chip designers, fabricators, product assemblers, logistics providers, service providers, and information security organizations. Clauses 5 to 11 target an organization’s strategic and risk management teams. This document provides an end-to-end view of the threats in each phase to help the organization shape their plans, procedures and policies.

Life cycle

NOW

PUBLISHED
ISO/IEC TR 6114:2023
60.60 Standard published
Oct 10, 2023