International Standard: Iso/Iec 20243-1
International Standard: Iso/Iec 20243-1
International Standard: Iso/Iec 20243-1
STANDARD 20243-1
First edition
2018-02
Reference number
ISO/IEC 20243-1:2018(E)
© ISO/IEC 2018
ISO/IEC 20243-1:2018(E)
Contents
1 Introduction ............................................................................................................... 1
1.1 Objectives ....................................................................................................... 1
1.2 Overview......................................................................................................... 1
1.3 Conformance................................................................................................... 3
1.4 Terminology ................................................................................................... 3
1.5 Future Directions ............................................................................................ 4
List of Tables
Table 1: O-TTPS Constituents and their Roles ................................................................... 6
Table 2: Threat Mapping ................................................................................................... 14
List of Figures
Figure 1: Constituents ......................................................................................................... 6
Figure 2: Product Life Cycle – Categories and Activities ................................................. 15
FOREWORD
)SO the )nternational Organization for Standardization and )EC the )nternational Electrotechnical
Commission form the specialized system for worldwide standardization. National bodies that are
members of )SO or )EC participate in the development of )nternational Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. )SO and )EC technical committees collaborate in fields of mutual interest. Other
international organizations, governmental and non‐governmental, in liaison with )SO and )EC, also
take part in the work. )n the field of information technology, )SO and )EC have established a joint
technical committee, )SO/)EC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the )SO/)EC Directives, Part 1. )n particular the different approval criteria needed for
the different types of document should be noted. This document was drafted in accordance with the
editorial rules of the )SO/)EC Directives, Part 2 see www.iso.org/directives .
Attention is drawn to the possibility that some of the elements of this document may be the subject
of patent rights. )SO and )EC shall not be held responsible for identifying any or all such patent
rights. Details of any patent rights identified during the development of the document will be in the
)ntroduction and/or on the )SO list of patent declarations received see www.iso.org/patents .
Any trade name used in this document is information given for the convenience of users and does
not constitute an endorsement.
For an explanation on the voluntary nature of standards, the meaning of )SO specific terms and
expressions related to conformity assessment, as well as information about )SO's adherence to the
World Trade Organization WTO principles in the Technical Barriers to Trade TBT see the
following URL: www.iso.org/iso/foreword.html.
This document was prepared by The Open Group and was adopted, under the PAS procedure, by
Joint Technical Committee )SO/)EC JTC 1, Information technology, in parallel with its approval by
national bodies of )SO and )EC.
This first edition of )SO/)EC 2024 ‐1 cancels and replaces )SO/)EC 2024 :201 of which it
constitutes a minor revision to change the reference number from 2024 to 2024 ‐1..
A list of all parts in the )SO 2024 series can be found on the )SO website.
Preface
The Open Group
The Open Group is a global consortium that enables the achievement of business objectives
through IT standards. With more than 400 member organizations, The Open Group has a diverse
membership that spans all sectors of the IT community – customers, systems and solutions
suppliers, tool vendors, integrators, and consultants, as well as academics and researchers – to:
Capture, understand, and address current and emerging requirements, and establish
policies and share best practices
Facilitate interoperability, develop consensus, and evolve and integrate specifications and
open source technologies
Offer a comprehensive set of services to enhance the operational efficiency of consortia
The Open Group publishes a wide range of technical documentation, most of which is focused on
development of Open Group Standards and Guides, but which also includes white papers,
technical studies, certification and testing documentation, and business titles. Full details and a
catalog are available at www.opengroup.org/bookstore.
Readers should note that updates – in the form of Corrigenda – may apply to any publication. This
information is published at www.opengroup.org/corrigenda.
This Document
The Open Group Trusted Technology Forum (OTTF or Forum) is a global initiative that invites
industry, government, and other interested participants to work together to evolve this Standard
and other OTTF deliverables.
This Standard is the Open Trusted Technology Provider Standard (O-TTPS). The Standard has
been developed by the OTTF and approved by The Open Group, through The Open Group
Company Review process. There are two distinct elements that should be understood with respect
to this Standard: The O-TTPF (Framework) and the O-TTPS (Standard).
The O-TTPS (Standard): The O-TTPS is an open standard containing a set of guidelines that
when properly adhered to have been shown to enhance the security of the global supply chain and
the integrity of COTS ICT products. This part 1 of the Standard provides a set of guidelines,
requirements, and recommendations that help assure against maliciously tainted and counterfeit
products throughout the COTS ICT product life cycle encompassing the following phases: design,
sourcing, build, fulfillment, distribution, sustainment, and disposal.
Part 2 of the O-TTPS Standard, Assessment Procedures for the O-TTPS and ISO/IEC 20243,,
provides assessment procedures that may be used to demonstrate conformance with the
requirements provided in Section 4 of this part of the Standard.
Using the guidelines documented in the Framework as a basis, the OTTF is taking a phased
approach and staging O-TTPS releases over time. This staging will consist of standards that focus
on mitigating specific COTS ICT risks from emerging threats. As threats change or market needs
evolve, the OTTF intends to update the O-TTPS (Standard) by releasing addenda to address
specific threats or market needs.
The Standard is aimed at enhancing the integrity of COTS ICT products and helping customers to
manage sourcing risk. The authors of this Standard recognize the value that it can bring to
governments and commercial customers worldwide, particularly those who adopt procurement
and sourcing strategies that reward those vendors who follow the O-TTPS best practice
requirements and recommendations.
Note: Any reference to “providers” is intended to refer to COTS ICT providers. The use of the
word “component” is intended to refer to either hardware or software components.
Intended Audience
This Standard is intended for organizations interested in helping the industry evolve to meet the
threats in the delivery of trustworthy COTS ICT products. It is intended to provide enough context
and information on business drivers to enable its audience to understand the value in adopting the
guidelines, requirements, and recommendations specified within. It also allows providers,
suppliers, and integrators to begin planning how to implement the Standard in their organizations.
Additionally, acquirers and customers can begin recommending the adoption of the Standard to
their providers and integrators.
Trademarks
ArchiMate®, DirecNet®, Jericho Forum®, Making Standards Work®, OpenPegasus®, The Open
Group®, TOGAF®, and UNIX® are registered trademarks and Boundaryless Information Flow™,
Build with Integrity Buy with Confidence™, Dependability Through Assuredness™, FACE™,
Open Platform 3.0™, Open Trusted Technology Provider™, and The Open Group Certification
Mark™ are trademarks of The Open Group.
All other brands, company, and product names are used for identification purposes only and may
be trademarks that are the sole property of their respective owners.
Acknowledgements
The Open Group acknowledges the contribution of the following people and organizations in the
development of this Standard (presented in alphabetical order).
In particular, we would like to provide a special thank you and acknowledgement to the Chair and
Vice Chair of the OTTF: Andras Szakal, IBM (Chair) and Edna Conway, Cisco Systems (Vice
Chair).
The contributing members of The Open Group Trusted Technology Forum (OTTF):
Contributors Organization
Jon Amis Dell, Inc.
Paul Aschwald Hewlett-Packard Company
Nadya Bartol (formerly of) Booz Allen Hamilton
James Bean Juniper Networks
Kristen Baldwin US DoD AT&L
Terry Blevins MITRE
Joshua Brickman CA Technologies
Stan Brown CA Technologies
Ben Calloni Lockheed Martin
Suresh Cheruserri (formerly of) Tata Consultancy Services
YouHong (Robert) Chu Kingdee Software
Erv Comer Motorola Solutions
Erin Connor Electronic Warfare Associates (EWA) – Canada Ltd.
Tammy Compton (formerly of) SAIC
Edna Conway Cisco Systems Inc.
OTTF Vice-Chair
Don Davidson DOD-CIO
Mary Ann Davidson Oracle Corporation
Charles Dekle (formerly of) US DoD AT&L
Terrie Diaz Cisco Systems Inc.
Robert Dix Juniper Networks
Holly Dunlap Raytheon Company
Bob Ellison SEI
Marcus Fedeli (formerly of) NASA
Luke Forsyth CA Technologies
Susan Fultz Hewlett-Packard Company
Contributors Organization
Steve Goldberg (formerly of) Motorola Solutions
Tim Hahn IBM Corporation
Wes Higaki Apex Assurance Group
Ken Hong Fong (formerly of) US DoD AT&L
Helmut Kurth atsec information security
Mike Lai Microsoft Corporation
David Ling Hewlett-Packard Company
Steve Lipner Microsoft Corporation
O-TTPF Work Stream Co-Chair
Dr. David McQueeney IBM Corporation
Jim Mann Hewlett-Packard Company
Al Marshall NASA
Michele Moss Booz-Allen Hamilton
Shawn Mullen IBM Corporation
Fiona Pattinson atsec information security
Brendan Peter CA Technologies
Glenn Pittaway Microsoft Corporation
Andy Purdy Huawei Technologies
Dan Reddy EMC Corporation
Karen Richter IDA
Jim Robinson Hewlett-Packard Company
Hart Rossman (formerly of) SAIC
Mark Schiller (formerly of) Hewlett-Packard Company
Thomas Stickels MITRE
Andras R. Szakal IBM Corporation
OTTF Chair and O-TTPF Work Stream Co-Chair
Steve Whitlock The Boeing Company
Jim Whitmore IBM Corporation
Robert Williamson SAIC
Eric Winterton Booz Allen Hamilton
Joanne Woytek NASA
Chee Wai Foong Cisco Systems Inc.
Contributor Name
Randy Barr Qualys
Rance DeLong LynuxWorks
Chris Fagan (formerly of) Microsoft Corporation
Rob Hoffman High Assurance Systems, Inc.
Dave McDermitt (formerly of) SAIC
Terry Morgan (formerly of) Cisco Systems Inc.
Paul Nicholas Microsoft Corporation
Kerri Patterson (formerly of) Cisco Systems Inc.
Steve Venema The Boeing Company
Larry Wagoner NSA
Name Role
James Andrews The Open Group Conformance Quality Manager
Joe Bergmann Open Group Government Relations, Director, RT&ES
James de Raeve VP Certification
Cathy Fox Technical Editor
Jim Hietala VP Security
Andrew Josey Director, Standards
Sally Long Director, The Open Group Trusted Technology Forum (OTTF)
Dave Lounsbury Chief Technical Officer
Referenced Documents
The following documents are referenced in this Standard:
2007 Defense Science Board Task Force on Mission Impact of Foreign Influence on DoD
Software, September 2007; findings and recommendations located at:
www.acq.osd.mil/dsb/reports/ADA486949.pdf.
Electronic Industry Citizenship Coalition (EICC) Code of Conduct; refer to:
www.eicc.info.
ISO/IEC 15408: Information Technology – Security Techniques – Evaluation Criteria for
IT Security (Common Criteria).
ISO/IEC 27000:2009: Information Technology – Security Techniques – Information
Security Management Systems – Overview and Vocabulary.
ISO/IEC Directives, Part 2: Rules for the Structure and Drafting of International
Standards.
NIST 800-12: An Introduction to Computer Security: The NIST Handbook.
White Paper: Open Trusted Technology Provider Framework (O-TTPF), W113, published
by The Open Group, February 2011; refer to:
www.opengroup.org/bookstore/catalog/w113.htm.