Skip to main content

NOBCCS Certification Scheme

162 requirements mapped to controls.

Requirements

RequirementTitleControlsOwner
SOL-01Architecture documentationSID-ARCH-01, SID-OPS-09
SOL-02Security control mapping to architectureSID-ARCH-01, SID-ARCH-02
SOL-03Risk assessment and risk coverage rationaleSID-ORG-03
SOL-04WSCD tamper resistance (EAL4+ AVA_VAN.5)SID-CRYPTO-01, SID-KEY-04
SOL-05WSCA high attack potential resistanceSID-KEY-04, SID-KEY-03
SOL-06WSCA authentication-gated signingSID-KEY-03, SID-KEY-04
SOL-07Multi-factor user authentication at LoA highSID-AUTH-01, SID-KEY-04, SID-AUTH-05
SOL-08Key generation, erasure, and proof of possessionSID-CRYPTO-01, SID-KEY-04
SOL-09Private key protection (WSCD-resident only)SID-CRYPTO-01, SID-KEY-04
SOL-10WSCA exclusive authority over critical assetsSID-KEY-03, SID-KEY-04
SOL-11Embedded SE technical specifications
SOL-12Wallet-WSCA communication integrity/authenticity/confidentialitySID-TRANS-01, SID-KEY-04
SOL-13Two-factor authentication (knowledge + possession)SID-AUTH-01, SID-AUTH-05, SID-KEY-04
SOL-14Protection against use by othersSID-AUTH-05, SID-AUTH-01
SOL-15Wallet instance uses at least one WSCDSID-KEY-03, SID-CRYPTO-01
SOL-16Pre-authentication lockoutSID-AUTH-05
SOL-17Wallet unit attestation with WSCD-protected keysSID-HARD-06
SOL-18Transaction loggingSID-AUDIT-01, SID-AUDIT-02
SOL-19Secure data export and backupSID-DATA-10
SOL-20Secure software update distributionSID-HARD-06
SOL-21End user device security assumptions and verificationSID-HARD-06, SID-HARD-09
WSCA-FDP-01FDP_ACC.1 / FDP_ACF.1 — Subset access controlSID-ACCESS-01, SID-KEY-04
WSCA-FDP-02FDP_ITC.2 — Import of user data with security attributesSID-KEY-04
WSCA-FDP-03FDP_RIP.1 — Subset residual information protectionSID-DATA-09
WSCA-FIA-01FIA_UAU.2 — User authentication before any actionSID-KEY-04, SID-AUTH-05
WSCA-FIA-02FIA_UAU.6 — Re-authenticationSID-KEY-04
WSCA-FIA-03FIA_AFL.1 — Authentication failure handlingSID-ACCESS-02, SID-KEY-04
WSCA-FCS-01FCS_COP.1 — Cryptographic operation (signing)SID-CRYPTO-01, SID-KEY-04
WSCA-FCS-02FCS_CKM.1 / FCS_CKM.4 — Key generation and destructionSID-CRYPTO-01, SID-KEY-04
WSCA-FCS-03FCS_CKM.2 — Cryptographic key distributionSID-KEY-04, SID-TRANS-01
WSCA-FPT-01FPT_TST.1 — TSF self-test (binary integrity)
WSCA-FPT-02FPT_FLS.1 — Failure with preservation of secure stateSID-HARD-03
WSCA-FPT-03FPT_RCV.1 — Manual recovery
WSCA-FAU-01FAU_GEN.1 / FAU_GEN.2 — Audit data generationSID-AUDIT-01
WSCA-FAU-02FAU_STG_EXT — Tamper-evident audit storage
WSCA-FTP-01FTP_ITC.1 — Inter-TSF trusted channelSID-TRANS-01, SID-KEY-04
WSCD-01CC EAL4+ AVA_VAN.5 certificationSID-CRYPTO-01
WSCD-02Key storage non-exportabilitySID-CRYPTO-01, SID-KEY-04
WSCD-03Approved cryptographic algorithmsSID-CRYPTO-01, SID-CRYPTO-04
WSCD-04Physical tamper resistanceSID-CRYPTO-01
WSCD-05PKCS#11 interface securitySID-CRYPTO-01, SID-KEY-04
REQ-WI-AR-01Unsupported OS version prohibitionSID-HARD-06
REQ-WI-AR-02Outdated OS detection and terminationSID-HARD-06
REQ-WI-AR-03Update integrity validationSID-HARD-06
REQ-WI-DS-01Platform security function utilisationSID-CRYPTO-03, SID-CRYPTO-02
REQ-WI-DS-02Sensitive data containmentSID-CRYPTO-03, SID-DATA-08
REQ-WI-DS-03No plaintext credential storageSID-CRYPTO-03
REQ-WI-DS-04Hardware-backed key storageSID-CRYPTO-02
REQ-WI-DS-05Sensitive data not in application logsSID-AUDIT-02
REQ-WI-LOG-01Log all transactionsSID-AUDIT-01
REQ-WI-NET-01Secure network communicationSID-TRANS-01, SID-TRANS-04
REQ-WI-UI-01Keyboard cache and clipboard protectionSID-HARD-08
REQ-WI-UI-02Background/screenshot protectionSID-HARD-08
REQ-WI-MEM-01Memory protection for sensitive dataSID-DATA-09
REQ-WI-AUTH-01Secure authentication implementationSID-AUTH-01, SID-AUTH-05
REQ-WI-CRYPTO-01Cryptographic best practicesSID-CRYPTO-03, SID-CRYPTO-02, SID-CRYPTO-05
REQ-WI-HARD-01Release mode and debug removalSID-HARD-05, SID-OPS-08
REQ-WI-HARD-02No external code loadingSID-HARD-05
REQ-WI-RES-01Root/jailbreak detectionSID-HARD-09
REQ-WI-RES-02Debugger detection and responseSID-HARD-09
REQ-WI-RES-03Tamper detection (executables and critical data)SID-HARD-09
REQ-WI-RES-04Reverse engineering tool detectionSID-HARD-09
REQ-WI-RES-05Obfuscation and payload encryptionSID-HARD-09
REQ-WI-ENV-01Environment integrity reportingSID-HARD-06
REQ-WI-ENV-02Official distribution only
REQ-WI-DOC-01Component identification and documentationSID-OPS-09, SID-ARCH-01
REQ-WI-DOC-02Data classification and risk analysisSID-ORG-08
REQ-WI-DOC-03Function documentation and justificationSID-OPS-09
REQ-WI-DOC-04Threat modelSID-ORG-03
REQ-WI-DOC-05User security guidance
REQ-WI-DOC-06Industry best practices and standardsSID-OPS-08
SP-01ISMS establishment and operationSID-ORG-01, SID-ORG-03
SP-02Legal entity statusSID-ORG-05
SP-03Legal/regulatory complianceSID-ORG-05
SP-04Financial capacity and liabilitySID-ORG-05
SP-05Termination planningSID-ORG-05
SP-06Service definition and T&CsSID-ORG-07
SP-07Interested party notificationSID-ORG-07
SP-08Data subject rights responsesSID-PRIV-03
SP-09Certification body notificationSID-OPS-05
SP-10Information security policySID-ORG-01
SP-11Roles and responsibilitiesSID-ORG-02
SP-12Risk management frameworkSID-ORG-03
SP-13Risk assessment processSID-ORG-03
SP-14Risk register complementation with TR 6SID-ORG-03
SP-15Risk assessment review and updateSID-ORG-03
SP-16Outsourcing responsibilitySID-ORG-04
SP-17Supplier contractual securitySID-ORG-04
SP-18Supply chain security policySID-ORG-04
SP-19Supplier registrySID-ORG-04
SP-20Supply chain policy reviewSID-ORG-04
SP-21Asset inventorySID-ORG-08
SP-22Information classification schemeSID-ORG-08
SP-23Asset handling policySID-ORG-08
SP-24Access control policiesSID-ACCESS-01
SP-25Access rights lifecycleSID-ACCESS-01
SP-26Incident management policySID-OPS-01
SP-27Incident reporting mechanismSID-PPL-04
SP-28Incident assessment and classificationSID-OPS-01
SP-29Incident response proceduresSID-OPS-01
SP-30Post-incident reviewSID-OPS-01
SP-31Vulnerability management processSID-OPS-04
SP-32Vulnerability impact analysisSID-OPS-04
SP-33Vulnerability disclosureSID-OPS-04
SP-34Business continuity requirementsSID-OPS-02
SP-35Business continuity and DR planSID-OPS-02
SP-36Backup copies and resourcesSID-OPS-03
SP-37Crisis managementSID-OPS-01
SP-38Compliance reviewSID-ORG-05
SP-39Record managementSID-OPS-01
SP-40Record retention (regulatory)SID-OPS-01
SP-41Five-year record retentionSID-OPS-01
SP-42Personnel background verificationSID-PPL-01
SP-43Personnel security commitmentsSID-PPL-03
SP-44Post-employment obligationsSID-PPL-03
SP-45Training and competenceSID-PPL-02
SP-46Cyber hygiene awarenessSID-PPL-02
SP-47Disciplinary processSID-PPL-04
SP-48Physical access controlSID-ORG-08
SP-49Environmental protection
SP-50Information system operational continuitySID-OPS-02
SP-51Secure media handlingSID-OPS-10
SP-52Removable storage media policySID-OPS-10
SP-53Asset deposit/return/deletion on terminationSID-ACCESS-01
SP-54Privileged account management (dual control)SID-ACCESS-01, SID-ORG-02
SP-55Identity lifecycle managementSID-ACCESS-01
SP-56Secure authentication proceduresSID-AUTH-01
SP-57Multi-factor authenticationSID-AUTH-01, SID-KEY-04
SP-58Malware protectionSID-OPS-04
SP-59Monitoring and loggingSID-AUDIT-01, SID-OPS-06
SP-60Network securitySID-HARD-03, SID-OPS-11
SP-61Network access controlSID-OPS-11
SP-62Secure development lifecycleSID-OPS-08
SP-63Change managementSID-OPS-05
SP-64Testing and acceptanceSID-OPS-08
SP-65Cryptographic policy and key managementSID-CRYPTO-01, SID-KEY-04
SP-66Cryptographic module requirementsSID-CRYPTO-01
SP-67Capacity managementSID-OPS-02
SP-68Time synchronisationSID-OPS-06
SP-69Secure configuration managementSID-OPS-05
WUP-01Installation authenticity and integritySID-HARD-06
WUP-02Wallet unit authenticity verificationSID-HARD-06
WUP-03Non-authentic wallet unit handlingSID-AUTH-06
WUP-04User rights and obligations noticeSID-ORG-07
WUP-05User account creationSID-AUTH-01
WUP-06Logical data separationSID-ACCESS-01, SID-PRIV-01
WUP-07Passphrase/PIN selection at activationSID-AUTH-05
WUP-08WUA issuance on activationSID-HARD-06
WUP-09Continuous automatic updatesSID-HARD-06
WUP-10Certified version enforcementSID-HARD-06
WUP-11Reactivation after suspensionSID-AUTH-06
WUP-12Transaction log integritySID-AUDIT-01
WUP-13Data download procedureSID-DATA-10
WUP-14Transaction log exportSID-DATA-10
WUP-15Revocation request submissionSID-AUTH-06
WUP-16WUA validity status serviceSID-HARD-06
WUP-17Revocation processingSID-AUTH-06
WUP-18Mandatory revocation triggersSID-AUTH-06
WUP-19Unauthorised revocation preventionSID-AUTH-06, SID-ACCESS-01
WUP-20Revocation practices disclosureSID-ORG-07
WUP-21Revocation user notificationSID-AUTH-06
WUP-22Revocation finality and data erasureSID-AUTH-06, SID-DATA-10