Information technology — Security techniques — Testing cryptographic modules in their operational en...
1 Scope
This document provides recommendations and checklists which can be used to support the specification and operational testing of cryptographic modules in their operational environment within an organization’s security system.
The cryptographic modules have four security levels which ISO/IEC 19790 defines to provide for a wide spectrum of data sensitivity (e.g. low-value administrative…
Information technology — Data centre facilities and infrastructures — Part 1: General concepts
1 Scope
This document:
a) details the issues to be addressed in a business risk and operating cost analysis enabling application of an appropriate classification of the data centre;
b) defines the common aspects of data centres including terminology, parameters and reference models (functional elements and their accommodation) addressing both the size and complexity of their intended purpose…
Information technology — Data centre facilities and infrastructures — Part 2: Building construction
1 Scope
This document addresses the construction of buildings and other structures which provide accommodation for data centres based upon the criteria and classification for “physical security” within ISO/IEC TS 22237-1 in support of availability.
This document specifies requirements and recommendations for the following:
a) location and site selection;
b) building construction;
c) building…
Information technology — Data centre facilities and infrastructures — Part 3: Power distribution
1 Scope
This document addresses power supplies to, and power distribution within, data centres based upon the criteria and classifications for “availability”, “physical security” and “energy efficiency enablement” within ISO/IEC TS 22237-1.
This document specifies requirements and recommendations for the following:
a) power supplies to data centres;
b) power distribution systems within data…
Information technology — Data centre facilities and infrastructures — Part 4: Environmental control
1 Scope
This document addresses environmental control within data centres based upon the criteria and classifications for “availability”, “security” and “energy efficiency enablement” within ISO/IEC TS 22237-1.
This document specifies requirements and recommendations for the following:
a) temperature control;
b) fluid movement control;
c) relative humidity control;
d) particulate control;…
Information technology — Data centre facilities and infrastructures — Part 5: Telecommunications cab...
1 Scope
This document addresses the wide range of telecommunications cabling infrastructures within data centres based upon the criteria and classifications for “availability” within ISO/IEC TS 22237-1.
This document specifies requirements and recommendations for the following:
a) information technology and network telecommunications cabling (e.g. SAN and LAN);
b) general information…
Information technology — Data centre facilities and infrastructures — Part 6: Security systems
1 Scope
This document addresses the physical security of data centres based upon the criteria and classifications for “availability”, “security” and “energy efficiency enablement” within ISO/IEC TS 22237-1.
This document provides designations for the data centre spaces defined in ISO/IEC TS 22237-1.
This document specifies requirements and recommendations for those data centre spaces, and the…
Information technology — Data centre facilities and infrastructures — Part 7: Management and operati...
1 Scope
This document specifies processes for the management and operation of data centres. The primary focus of this document is the operational processes necessary to deliver the expected level of resilience, availability, risk management, risk mitigation, capacity planning, security and energy efficiency.
The secondary focus is on management processes to align the actual and future demands…
Systems and software engineering — Requirements for acquirers and suppliers of information for users
1 Scope
This document supports the interest of system users in having consistent, complete, accurate, and usable
information. It addresses both available approaches to standardization: a) process standards, which
specify the way that information products are to be acquired and supplied; and b) information product
standards, which specify the characteristics and functional requirements of the…
Information technology — Application security — Part 5-1: Protocols and application security control...
1 Scope
This document defines XML Schemas that implement the minimal set of information requirements and
essential attributes of ASCs and the activities and roles of the Application Security Life Cycle Reference
Model (ASLCRM) from ISO/IEC 27034-5.