ISO/IEC 23837:2023
Part 1 Clause 7: Security problem definition – ISO/IEC 23837:2023

ISO/IEC 23837:2023 1-7.2: Part 1, 7.2 Security assumptions

The operational environment is assumed to give: physical protection of the module, so no threat agent can get near it (an assumption that does not remove threats arriving through its external interfaces); trusted operators, meaning administrators, auditors and other legitimate roles act in the organization's security interest; and a pre-shared key that is random and kept confidential before it is loaded. Assumptions are made only where a matter cannot be handled technically by an SFR, and they reduce but do not remove side-channel considerations (6.1).

Maintained by Gerard BlokdykControl text last updated

Other controls in Part 1 Clause 7: Security problem definition – ISO/IEC 23837:2023

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.