NOBCCS Certification Scheme
162 requirements mapped to controls.
Requirements
| Requirement | Title | Controls | Owner |
|---|---|---|---|
| SOL-01 | Architecture documentation | SID-ARCH-01, SID-OPS-09 | |
| SOL-02 | Security control mapping to architecture | SID-ARCH-01, SID-ARCH-02 | |
| SOL-03 | Risk assessment and risk coverage rationale | SID-ORG-03 | |
| SOL-04 | WSCD tamper resistance (EAL4+ AVA_VAN.5) | SID-CRYPTO-01, SID-KEY-04 | |
| SOL-05 | WSCA high attack potential resistance | SID-KEY-04, SID-KEY-03 | |
| SOL-06 | WSCA authentication-gated signing | SID-KEY-03, SID-KEY-04 | |
| SOL-07 | Multi-factor user authentication at LoA high | SID-AUTH-01, SID-KEY-04, SID-AUTH-05 | |
| SOL-08 | Key generation, erasure, and proof of possession | SID-CRYPTO-01, SID-KEY-04 | |
| SOL-09 | Private key protection (WSCD-resident only) | SID-CRYPTO-01, SID-KEY-04 | |
| SOL-10 | WSCA exclusive authority over critical assets | SID-KEY-03, SID-KEY-04 | |
| SOL-11 | Embedded SE technical specifications | ||
| SOL-12 | Wallet-WSCA communication integrity/authenticity/confidentiality | SID-TRANS-01, SID-KEY-04 | |
| SOL-13 | Two-factor authentication (knowledge + possession) | SID-AUTH-01, SID-AUTH-05, SID-KEY-04 | |
| SOL-14 | Protection against use by others | SID-AUTH-05, SID-AUTH-01 | |
| SOL-15 | Wallet instance uses at least one WSCD | SID-KEY-03, SID-CRYPTO-01 | |
| SOL-16 | Pre-authentication lockout | SID-AUTH-05 | |
| SOL-17 | Wallet unit attestation with WSCD-protected keys | SID-HARD-06 | |
| SOL-18 | Transaction logging | SID-AUDIT-01, SID-AUDIT-02 | |
| SOL-19 | Secure data export and backup | SID-DATA-10 | |
| SOL-20 | Secure software update distribution | SID-HARD-06 | |
| SOL-21 | End user device security assumptions and verification | SID-HARD-06, SID-HARD-09 | |
| WSCA-FDP-01 | FDP_ACC.1 / FDP_ACF.1 — Subset access control | SID-ACCESS-01, SID-KEY-04 | |
| WSCA-FDP-02 | FDP_ITC.2 — Import of user data with security attributes | SID-KEY-04 | |
| WSCA-FDP-03 | FDP_RIP.1 — Subset residual information protection | SID-DATA-09 | |
| WSCA-FIA-01 | FIA_UAU.2 — User authentication before any action | SID-KEY-04, SID-AUTH-05 | |
| WSCA-FIA-02 | FIA_UAU.6 — Re-authentication | SID-KEY-04 | |
| WSCA-FIA-03 | FIA_AFL.1 — Authentication failure handling | SID-ACCESS-02, SID-KEY-04 | |
| WSCA-FCS-01 | FCS_COP.1 — Cryptographic operation (signing) | SID-CRYPTO-01, SID-KEY-04 | |
| WSCA-FCS-02 | FCS_CKM.1 / FCS_CKM.4 — Key generation and destruction | SID-CRYPTO-01, SID-KEY-04 | |
| WSCA-FCS-03 | FCS_CKM.2 — Cryptographic key distribution | SID-KEY-04, SID-TRANS-01 | |
| WSCA-FPT-01 | FPT_TST.1 — TSF self-test (binary integrity) | ||
| WSCA-FPT-02 | FPT_FLS.1 — Failure with preservation of secure state | SID-HARD-03 | |
| WSCA-FPT-03 | FPT_RCV.1 — Manual recovery | ||
| WSCA-FAU-01 | FAU_GEN.1 / FAU_GEN.2 — Audit data generation | SID-AUDIT-01 | |
| WSCA-FAU-02 | FAU_STG_EXT — Tamper-evident audit storage | ||
| WSCA-FTP-01 | FTP_ITC.1 — Inter-TSF trusted channel | SID-TRANS-01, SID-KEY-04 | |
| WSCD-01 | CC EAL4+ AVA_VAN.5 certification | SID-CRYPTO-01 | |
| WSCD-02 | Key storage non-exportability | SID-CRYPTO-01, SID-KEY-04 | |
| WSCD-03 | Approved cryptographic algorithms | SID-CRYPTO-01, SID-CRYPTO-04 | |
| WSCD-04 | Physical tamper resistance | SID-CRYPTO-01 | |
| WSCD-05 | PKCS#11 interface security | SID-CRYPTO-01, SID-KEY-04 | |
| REQ-WI-AR-01 | Unsupported OS version prohibition | SID-HARD-06 | |
| REQ-WI-AR-02 | Outdated OS detection and termination | SID-HARD-06 | |
| REQ-WI-AR-03 | Update integrity validation | SID-HARD-06 | |
| REQ-WI-DS-01 | Platform security function utilisation | SID-CRYPTO-03, SID-CRYPTO-02 | |
| REQ-WI-DS-02 | Sensitive data containment | SID-CRYPTO-03, SID-DATA-08 | |
| REQ-WI-DS-03 | No plaintext credential storage | SID-CRYPTO-03 | |
| REQ-WI-DS-04 | Hardware-backed key storage | SID-CRYPTO-02 | |
| REQ-WI-DS-05 | Sensitive data not in application logs | SID-AUDIT-02 | |
| REQ-WI-LOG-01 | Log all transactions | SID-AUDIT-01 | |
| REQ-WI-NET-01 | Secure network communication | SID-TRANS-01, SID-TRANS-04 | |
| REQ-WI-UI-01 | Keyboard cache and clipboard protection | SID-HARD-08 | |
| REQ-WI-UI-02 | Background/screenshot protection | SID-HARD-08 | |
| REQ-WI-MEM-01 | Memory protection for sensitive data | SID-DATA-09 | |
| REQ-WI-AUTH-01 | Secure authentication implementation | SID-AUTH-01, SID-AUTH-05 | |
| REQ-WI-CRYPTO-01 | Cryptographic best practices | SID-CRYPTO-03, SID-CRYPTO-02, SID-CRYPTO-05 | |
| REQ-WI-HARD-01 | Release mode and debug removal | SID-HARD-05, SID-OPS-08 | |
| REQ-WI-HARD-02 | No external code loading | SID-HARD-05 | |
| REQ-WI-RES-01 | Root/jailbreak detection | SID-HARD-09 | |
| REQ-WI-RES-02 | Debugger detection and response | SID-HARD-09 | |
| REQ-WI-RES-03 | Tamper detection (executables and critical data) | SID-HARD-09 | |
| REQ-WI-RES-04 | Reverse engineering tool detection | SID-HARD-09 | |
| REQ-WI-RES-05 | Obfuscation and payload encryption | SID-HARD-09 | |
| REQ-WI-ENV-01 | Environment integrity reporting | SID-HARD-06 | |
| REQ-WI-ENV-02 | Official distribution only | ||
| REQ-WI-DOC-01 | Component identification and documentation | SID-OPS-09, SID-ARCH-01 | |
| REQ-WI-DOC-02 | Data classification and risk analysis | SID-ORG-08 | |
| REQ-WI-DOC-03 | Function documentation and justification | SID-OPS-09 | |
| REQ-WI-DOC-04 | Threat model | SID-ORG-03 | |
| REQ-WI-DOC-05 | User security guidance | ||
| REQ-WI-DOC-06 | Industry best practices and standards | SID-OPS-08 | |
| SP-01 | ISMS establishment and operation | SID-ORG-01, SID-ORG-03 | |
| SP-02 | Legal entity status | SID-ORG-05 | |
| SP-03 | Legal/regulatory compliance | SID-ORG-05 | |
| SP-04 | Financial capacity and liability | SID-ORG-05 | |
| SP-05 | Termination planning | SID-ORG-05 | |
| SP-06 | Service definition and T&Cs | SID-ORG-07 | |
| SP-07 | Interested party notification | SID-ORG-07 | |
| SP-08 | Data subject rights responses | SID-PRIV-03 | |
| SP-09 | Certification body notification | SID-OPS-05 | |
| SP-10 | Information security policy | SID-ORG-01 | |
| SP-11 | Roles and responsibilities | SID-ORG-02 | |
| SP-12 | Risk management framework | SID-ORG-03 | |
| SP-13 | Risk assessment process | SID-ORG-03 | |
| SP-14 | Risk register complementation with TR 6 | SID-ORG-03 | |
| SP-15 | Risk assessment review and update | SID-ORG-03 | |
| SP-16 | Outsourcing responsibility | SID-ORG-04 | |
| SP-17 | Supplier contractual security | SID-ORG-04 | |
| SP-18 | Supply chain security policy | SID-ORG-04 | |
| SP-19 | Supplier registry | SID-ORG-04 | |
| SP-20 | Supply chain policy review | SID-ORG-04 | |
| SP-21 | Asset inventory | SID-ORG-08 | |
| SP-22 | Information classification scheme | SID-ORG-08 | |
| SP-23 | Asset handling policy | SID-ORG-08 | |
| SP-24 | Access control policies | SID-ACCESS-01 | |
| SP-25 | Access rights lifecycle | SID-ACCESS-01 | |
| SP-26 | Incident management policy | SID-OPS-01 | |
| SP-27 | Incident reporting mechanism | SID-PPL-04 | |
| SP-28 | Incident assessment and classification | SID-OPS-01 | |
| SP-29 | Incident response procedures | SID-OPS-01 | |
| SP-30 | Post-incident review | SID-OPS-01 | |
| SP-31 | Vulnerability management process | SID-OPS-04 | |
| SP-32 | Vulnerability impact analysis | SID-OPS-04 | |
| SP-33 | Vulnerability disclosure | SID-OPS-04 | |
| SP-34 | Business continuity requirements | SID-OPS-02 | |
| SP-35 | Business continuity and DR plan | SID-OPS-02 | |
| SP-36 | Backup copies and resources | SID-OPS-03 | |
| SP-37 | Crisis management | SID-OPS-01 | |
| SP-38 | Compliance review | SID-ORG-05 | |
| SP-39 | Record management | SID-OPS-01 | |
| SP-40 | Record retention (regulatory) | SID-OPS-01 | |
| SP-41 | Five-year record retention | SID-OPS-01 | |
| SP-42 | Personnel background verification | SID-PPL-01 | |
| SP-43 | Personnel security commitments | SID-PPL-03 | |
| SP-44 | Post-employment obligations | SID-PPL-03 | |
| SP-45 | Training and competence | SID-PPL-02 | |
| SP-46 | Cyber hygiene awareness | SID-PPL-02 | |
| SP-47 | Disciplinary process | SID-PPL-04 | |
| SP-48 | Physical access control | SID-ORG-08 | |
| SP-49 | Environmental protection | ||
| SP-50 | Information system operational continuity | SID-OPS-02 | |
| SP-51 | Secure media handling | SID-OPS-10 | |
| SP-52 | Removable storage media policy | SID-OPS-10 | |
| SP-53 | Asset deposit/return/deletion on termination | SID-ACCESS-01 | |
| SP-54 | Privileged account management (dual control) | SID-ACCESS-01, SID-ORG-02 | |
| SP-55 | Identity lifecycle management | SID-ACCESS-01 | |
| SP-56 | Secure authentication procedures | SID-AUTH-01 | |
| SP-57 | Multi-factor authentication | SID-AUTH-01, SID-KEY-04 | |
| SP-58 | Malware protection | SID-OPS-04 | |
| SP-59 | Monitoring and logging | SID-AUDIT-01, SID-OPS-06 | |
| SP-60 | Network security | SID-HARD-03, SID-OPS-11 | |
| SP-61 | Network access control | SID-OPS-11 | |
| SP-62 | Secure development lifecycle | SID-OPS-08 | |
| SP-63 | Change management | SID-OPS-05 | |
| SP-64 | Testing and acceptance | SID-OPS-08 | |
| SP-65 | Cryptographic policy and key management | SID-CRYPTO-01, SID-KEY-04 | |
| SP-66 | Cryptographic module requirements | SID-CRYPTO-01 | |
| SP-67 | Capacity management | SID-OPS-02 | |
| SP-68 | Time synchronisation | SID-OPS-06 | |
| SP-69 | Secure configuration management | SID-OPS-05 | |
| WUP-01 | Installation authenticity and integrity | SID-HARD-06 | |
| WUP-02 | Wallet unit authenticity verification | SID-HARD-06 | |
| WUP-03 | Non-authentic wallet unit handling | SID-AUTH-06 | |
| WUP-04 | User rights and obligations notice | SID-ORG-07 | |
| WUP-05 | User account creation | SID-AUTH-01 | |
| WUP-06 | Logical data separation | SID-ACCESS-01, SID-PRIV-01 | |
| WUP-07 | Passphrase/PIN selection at activation | SID-AUTH-05 | |
| WUP-08 | WUA issuance on activation | SID-HARD-06 | |
| WUP-09 | Continuous automatic updates | SID-HARD-06 | |
| WUP-10 | Certified version enforcement | SID-HARD-06 | |
| WUP-11 | Reactivation after suspension | SID-AUTH-06 | |
| WUP-12 | Transaction log integrity | SID-AUDIT-01 | |
| WUP-13 | Data download procedure | SID-DATA-10 | |
| WUP-14 | Transaction log export | SID-DATA-10 | |
| WUP-15 | Revocation request submission | SID-AUTH-06 | |
| WUP-16 | WUA validity status service | SID-HARD-06 | |
| WUP-17 | Revocation processing | SID-AUTH-06 | |
| WUP-18 | Mandatory revocation triggers | SID-AUTH-06 | |
| WUP-19 | Unauthorised revocation prevention | SID-AUTH-06, SID-ACCESS-01 | |
| WUP-20 | Revocation practices disclosure | SID-ORG-07 | |
| WUP-21 | Revocation user notification | SID-AUTH-06 | |
| WUP-22 | Revocation finality and data erasure | SID-AUTH-06, SID-DATA-10 |