ISO/IEC 17825:2024 Information Technology
Table of Contents
ISO/IEC 17825:2024 is an international cybersecurity standard that defines testing methods for evaluating the resistance of cryptographic modules against non-invasive attacks. Published in January 2024 by ISO and IEC, this second edition replaces ISO/IEC 17825:2016 and introduces updated testing methodologies aligned with current security research and industry practices.
The standard plays a critical role in ensuring that cryptographic devices—such as hardware security modules (HSMs), smart cards, payment terminals, IoT devices, and secure processors—can withstand side-channel attacks without requiring physical damage to the device. It is primarily used alongside ISO/IEC 19790 (Security Requirements for Cryptographic Modules) and ISO/IEC 24759 (Cryptographic Module Test Requirements) to validate security Levels 3 and 4.
Purpose and Scope
The primary objective of ISO/IEC 17825:2024 is to establish repeatable, technically sound, and cost-effective test metrics for assessing non-invasive attack mitigation. Unlike invasive attacks that involve physically altering a device, non-invasive attacks exploit observable characteristics such as power consumption, electromagnetic emissions, timing behavior, and fault injection opportunities.
The standard evaluates cryptographic modules at their defined operational boundary, focusing on accessible inputs and outputs. This approach enables accredited laboratories to perform consistent security assessments while ensuring reliable comparison across different products and vendors.
Key Improvements in the 2024 Edition
The 2024 revision introduces several significant enhancements over the 2016 version:
- Updated test methods reflecting modern side-channel attack research.
- Improved traceability through numbered requirements.
- A new introductory framework explaining security level expectations.
- Better alignment with ISO/IEC 19790 and ISO/IEC 24759 evaluation processes.
IECLIST+1
These updates strengthen the standard’s relevance for contemporary cryptographic implementations used in cloud infrastructure, financial services, government systems, and embedded security solutions.
Why ISO/IEC 17825:2024 Matters
Organizations handling sensitive information increasingly depend on hardware-based cryptography to protect digital assets. Compliance with ISO/IEC 17825:2024 demonstrates that cryptographic modules have been independently tested against sophisticated side-channel threats, improving trust, regulatory readiness, and product assurance. It is particularly valuable for manufacturers seeking international certification and organizations deploying high-security cryptographic devices.
Relevant External Resources
- ISO Official Standard: ISO/IEC 17825:2024
- IEC Webstore: ISO/IEC 17825:2024 Publication
- ISO/IEC JTC 1/SC 27: Information Security, Cybersecurity and Privacy Protection Committee
ISO/IEC 17825:2024 represents an essential benchmark for modern cryptographic security testing, providing standardized methods to verify resilience against non-invasive attack techniques and supporting the development of trustworthy cybersecurity products worldwide.
#InformationSecurity
What is ISO/IEC 17825:2024 and Why Is It Important for Information Technology Security?
Introduction
ISO/IEC 17825:2024 is an internationally recognized cybersecurity standard that specifies testing methods for evaluating the resistance of cryptographic modules against non-invasive attack classes. Developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), the standard provides a structured framework for assessing whether hardware and embedded cryptographic devices can withstand sophisticated side-channel attacks without requiring physical modification of the device. It serves as a critical companion standard to ISO/IEC 19790 and ISO/IEC 24759, supporting the security validation of cryptographic modules used in high-assurance environments.
Understanding ISO/IEC 17825:2024
The standard focuses on non-invasive attacks, where attackers attempt to extract sensitive information by observing characteristics such as power consumption, electromagnetic emissions, timing behavior, or fault responses. Unlike invasive attacks that involve physically opening or damaging hardware, non-invasive techniques exploit information leaked during normal device operation. ISO/IEC 17825:2024 establishes repeatable laboratory test methods that measure how effectively cryptographic modules mitigate these threats under controlled conditions.
The 2024 edition replaces the earlier 2016 version and incorporates updated testing methodologies based on recent cybersecurity research. It also improves requirement traceability and better aligns with modern cryptographic security evaluation practices.
Why Is It Important for Information Technology Security?
As organizations increasingly rely on encryption to protect financial transactions, personal information, government communications, and cloud infrastructure, the security of cryptographic hardware has become essential. ISO/IEC 17825:2024 helps manufacturers and security laboratories verify that cryptographic modules remain resilient against practical side-channel attacks before products reach the market.
Key benefits include:
- Enhanced data protection: Validates resistance to attacks targeting encryption keys and confidential data.
- International standardization: Provides consistent testing procedures recognized across global cybersecurity industries.
- Regulatory compliance: Supports certification processes for products requiring ISO/IEC 19790 security validation.
- Improved product trust: Demonstrates that cryptographic devices have undergone independent, technically sound security testing.
- Reduced cybersecurity risk: Identifies hardware vulnerabilities early in the product development lifecycle.
Applications Across Industries
ISO/IEC 17825:2024 is widely applicable in sectors where cryptographic security is mission-critical. Typical implementations include hardware security modules (HSMs), smart cards, payment terminals, secure microcontrollers, Internet of Things (IoT) devices, telecommunications equipment, and government security systems. Organizations developing secure hardware use the standard to strengthen product assurance and meet international security expectations.
Conclusion
ISO/IEC 17825:2024 represents a significant advancement in information technology security by providing standardized methods for testing cryptographic modules against non-invasive attack techniques. Its emphasis on repeatable, evidence-based evaluation enables manufacturers, certification laboratories, and security professionals to improve the resilience of hardware-based encryption systems. As cyber threats continue to evolve, adopting this standard helps organizations build trustworthy products, protect sensitive information, and achieve globally recognized security assurance.
Relevant External Links
- ISO Official Standard: ISO/IEC 17825:2024
- IEC Publication: ISO/IEC 17825:2024 | IEC
- ISO/IEC JTC 1/SC 27 Committee: Information Security, Cybersecurity and Privacy Protection
#DataSecurity

How Does ISO/IEC 17825:2024 Help Evaluate Electromagnetic Information Leakage in IT Equipment?
Introduction
Electromagnetic (EM) information leakage is one of the most significant side-channel security risks affecting modern information technology equipment. Devices that perform cryptographic operations—such as hardware security modules (HSMs), smart cards, payment terminals, servers, and IoT devices—can unintentionally emit electromagnetic signals during normal operation. These emissions may reveal sensitive information, including encryption keys and confidential data, to attackers using specialized monitoring equipment. ISO/IEC 17825:2024 provides standardized testing methods for evaluating and measuring this type of non-invasive information leakage, helping manufacturers and security laboratories verify the resilience of cryptographic modules against electromagnetic side-channel attacks.
Understanding Electromagnetic Information Leakage
Whenever electronic circuits process data, they generate small electromagnetic emissions as a natural byproduct of electrical activity. Although these signals are typically weak, advanced attackers can capture and analyze them to infer secret values without physically opening or damaging the device. This attack method is known as electromagnetic analysis (EMA) and is widely recognized in cybersecurity as a practical side-channel attack technique.
ISO/IEC 17825:2024 establishes a repeatable framework for identifying whether these emissions leak enough information to compromise cryptographic security.
How the Standard Evaluates EM Leakage
The standard defines laboratory procedures that simulate realistic attack conditions while maintaining consistent testing environments. Rather than focusing on electromagnetic compatibility (EMC), ISO/IEC 17825 evaluates security-related electromagnetic leakage by examining emissions produced during cryptographic operations.
Key evaluation activities include:
- Measuring electromagnetic emissions while cryptographic algorithms are executing.
- Collecting multiple signal traces under controlled environmental conditions.
- Applying statistical analysis to determine whether sensitive information correlates with observed emissions.
- Assessing the effectiveness of hardware and software countermeasures designed to reduce information leakage.
- Documenting results using standardized methodologies that enable reproducible security evaluations
This structured approach ensures that different testing laboratories can produce consistent and comparable evaluation results.
Benefits for Information Technology Security
ISO/IEC 17825:2024 strengthens IT security by helping organizations detect vulnerabilities before products are deployed. Manufacturers can identify weaknesses in processor design, cryptographic implementations, shielding techniques, and power management systems that may contribute to electromagnetic leakage. The standard also supports certification programs based on ISO/IEC 19790 by providing technical evidence that cryptographic modules meet required resistance levels against non-invasive attacks.
Industries benefiting from these evaluations include banking, telecommunications, defense, cloud computing, healthcare, and government infrastructure, where protecting cryptographic keys is essential.
Conclusion
ISO/IEC 17825:2024 plays a vital role in evaluating electromagnetic information leakage by providing internationally standardized methods for testing cryptographic modules against EM side-channel attacks. Through controlled measurements, statistical analysis, and repeatable laboratory procedures, the standard helps ensure that IT equipment maintains the confidentiality of sensitive information even when subjected to sophisticated electromagnetic monitoring techniques. As cyber threats continue to evolve, compliance with ISO/IEC 17825:2024 significantly improves the security and trustworthiness of hardware-based encryption systems.
Relevant External Links
- ISO Official Standard: ISO/IEC 17825:2024 – Information technology — Security techniques — Testing methods for the mitigation of non-invasive attack classes against cryptographic modules
- IEC Webstore Publication: ISO/IEC 17825:2024 | IEC
- ISO/IEC JTC 1/SC 27 Committee: ISO/IEC 17825:2024 – Information technology – Security techniques – Testing methods for the mitigation of non-invasive attack classes against cryptographic modules
Yes. ISO/IEC 17825:2024 can be applied to a broad range of cryptographic modules implemented in hardware or IT equipment, provided the module falls within the scope of the security requirements and evaluation framework it supports. The standard is specifically concerned with testing resistance to non-invasive attacks, rather than assessing the general cybersecurity of every component in an IT environment.
Types of Hardware and IT Systems That Can Be Assessed
Examples include:
- Hardware security modules (HSMs): Dedicated devices used to generate, store, and protect cryptographic keys.
- Smart cards and secure elements: Commonly used in payment cards, identity systems, SIMs, and secure authentication devices.
- Cryptographic processors and secure microcontrollers: Chips that perform encryption, decryption, authentication, or key-management operations.
- Payment terminals: Devices handling sensitive financial and cryptographic transactions can be evaluated for information leakage through power, timing, electromagnetic, and other observable characteristics.
- Embedded and IoT devices: Connected devices containing cryptographic functionality may require protection against side-channel attacks, particularly when deployed in physically accessible environments.
- Network and communications equipment: Certain routers, gateways, telecommunications equipment, and other systems incorporating cryptographic modules may be evaluated when their cryptographic functionality falls within the applicable requirements.
- Other dedicated cryptographic devices: Specialized equipment used by government, financial, enterprise, and security-critical applications can also be relevant.
The important distinction is that ISO/IEC 17825:2024 does not function as a general-purpose IT equipment security standard. Its testing methods are designed specifically to evaluate the mitigation of non-invasive attack classes against cryptographic modules. The results can support assessments conducted under ISO/IEC 19790, which specifies security requirements for cryptographic modules, and ISO/IEC 24759, which addresses testing requirements for those modules.
Why This Broad Applicability Matters
Modern IT systems increasingly depend on cryptographic modules to protect authentication credentials, encryption keys, financial information, communications, and sensitive data. A cryptographic algorithm can be mathematically secure while its implementation still leaks information through physical characteristics such as electromagnetic emissions or power consumption.
ISO/IEC 17825:2024 therefore helps organizations evaluate the implementation-level security of cryptographic technology. Manufacturers can use testing to identify weaknesses during product development, while independent laboratories can use standardized methods when performing security evaluations.
This is particularly important for devices deployed outside controlled data centers, where an attacker may have physical proximity to equipment and sophisticated measurement capabilities.
Conclusion
In practical terms, ISO/IEC 17825:2024 is most relevant to hardware and embedded systems that contain cryptographic modules, rather than ordinary IT equipment without cryptographic functionality. Its standardized testing approach helps determine whether these modules adequately mitigate non-invasive side-channel threats and provides valuable evidence for broader cryptographic security certification.
For authoritative information, see ISO/IEC 17825:2024 at ISO and the IEC Webstore publication.
#HardwareSecurity
How Can Testing and Evaluation Improve Hardware Security and Reduce Information Leakage Risks?
Testing and evaluation play a critical role in improving hardware security because they can reveal weaknesses that may not be apparent from source code, functional testing, or cryptographic algorithm analysis alone. For cryptographic hardware, ISO/IEC 17825:2024 provides standardized testing methods for evaluating the mitigation of non-invasive attack classes. This helps manufacturers and security laboratories determine whether a cryptographic module unintentionally exposes sensitive information through observable physical characteristics.
Identifying Side-Channel Vulnerabilities
One of the main benefits of hardware security testing is the ability to identify side-channel leakage. During cryptographic operations, electronic devices can produce measurable signals related to their internal processing. Examples include power consumption, electromagnetic emissions, timing behavior, and other physical characteristics. If these characteristics correlate with secret information, an attacker may potentially use statistical analysis to recover sensitive cryptographic data.
Testing allows security professionals to collect and analyze these signals under controlled conditions. This provides evidence about whether an implementation adequately protects sensitive information against non-invasive attacks.
Improving Hardware and Software Countermeasures
Evaluation results can also guide manufacturers in strengthening their products. If testing identifies excessive leakage, engineers can introduce appropriate countermeasures at the hardware, firmware, or cryptographic implementation level. Depending on the vulnerability, improvements may include better circuit design, masking techniques, balanced implementations, improved randomness, electromagnetic shielding, or other protections.
Testing can then be repeated to determine whether the implemented countermeasures actually reduce the observed leakage. This creates an important test-and-improve cycle throughout product development.
Supporting Security Certification
Testing is also important for demonstrating compliance with established security requirements. ISO/IEC 17825:2024 is used in conjunction with standards such as ISO/IEC 19790, which defines security requirements for cryptographic modules, and ISO/IEC 24759, which specifies testing requirements for those modules. Together, these standards provide a structured foundation for evaluating cryptographic security.
Reducing Long-Term Security Risks
Regular and independent evaluation can help organizations discover weaknesses before hardware is widely deployed. This is particularly valuable for payment systems, identity technologies, telecommunications equipment, IoT devices, and other environments where attackers may have physical access to equipment.
Ultimately, testing does not simply establish whether hardware works correctly; it helps determine how securely it operates under attack conditions. By identifying information leakage, validating countermeasures, and supporting consistent security assessments, ISO/IEC 17825:2024 helps manufacturers develop more resilient cryptographic hardware and reduces the risk that sensitive information can be extracted through non-invasive techniques.
Relevant external resources: ISO/IEC 17825:2024 — ISO · IEC Webstore
#CryptographicSecurity

What Are the Benefits of Implementing ISO/IEC 17825:2024 for Cybersecurity, Regulatory Compliance, and Critical Infrastructure Protection?
ISO/IEC 17825:2024 provides standardized testing methods for evaluating how effectively cryptographic modules mitigate non-invasive attacks. Its value extends beyond technical testing because secure cryptographic hardware is an important component of cybersecurity, regulatory assurance, and protection of critical information systems. The standard is designed to work alongside standards such as ISO/IEC 19790 and ISO/IEC 24759, creating a structured approach to cryptographic module security evaluation.
Strengthening Cybersecurity
One of the primary benefits of ISO/IEC 17825:2024 is improved protection against side-channel attacks. Attackers may attempt to obtain cryptographic secrets by analyzing information unintentionally exposed during device operation, including electromagnetic emissions, power consumption, timing characteristics, or other observable behavior.
Standardized testing helps manufacturers identify these weaknesses and assess whether implemented countermeasures are effective. Organizations can consequently make better-informed decisions about the security of cryptographic hardware used to protect encryption keys, authentication credentials, communications, and sensitive data.
Supporting Regulatory and Certification Requirements
ISO/IEC 17825:2024 can also contribute to regulatory and certification efforts by providing consistent testing methodologies and objective evidence of security performance. It is particularly relevant when organizations are evaluating cryptographic modules against the requirements of ISO/IEC 19790.
Although implementing ISO/IEC 17825:2024 does not automatically mean that an organization is compliant with every cybersecurity regulation, testing against the standard can strengthen an organization’s overall compliance and assurance program. It provides documented evidence that security controls have been evaluated using internationally recognized methods.
Protecting Critical Infrastructure
Critical infrastructure—including financial services, telecommunications, energy, transportation, government, and industrial systems—depends heavily on cryptography to protect sensitive communications and operational information. A compromise of cryptographic keys could potentially undermine multiple layers of security.
Applying standardized non-invasive attack testing helps organizations identify vulnerabilities in cryptographic hardware before attackers can exploit them. This is particularly important for equipment deployed in locations where physical access cannot be completely controlled.
Improving Product Assurance and Trust
For manufacturers, ISO/IEC 17825:2024 provides a systematic way to evaluate security countermeasures during product development. Testing can reveal implementation weaknesses, allowing engineers to improve hardware and software before deployment. Independent laboratory evaluation can also increase confidence among customers, regulators, and other stakeholders.
Conclusion
The implementation of ISO/IEC 17825:2024 can deliver three major advantages: stronger cybersecurity, better evidence for security assurance and certification, and improved resilience of critical infrastructure. By systematically evaluating non-invasive attack resistance, organizations can reduce information-leakage risks and make cryptographic products more trustworthy. However, the standard should be viewed as one component of a broader cybersecurity program rather than a complete security solution.
Relevant external resources: ISO/IEC 17825:2024 — ISO · IEC Webstore
#Cybersecurity
Case Study of ISO/IEC 17825:2024 in Information Technology Security
Introduction
Modern information technology systems increasingly depend on cryptographic modules to protect sensitive information, authentication credentials, encryption keys, and digital communications. However, strong cryptographic algorithms alone do not guarantee complete security. Physical characteristics produced during cryptographic operations can potentially expose information to attackers through non-invasive techniques. ISO/IEC 17825:2024 addresses this challenge by establishing testing metrics for evaluating the mitigation of non-invasive attack classes against cryptographic modules. The standard was published in January 2024 as the second edition and replaced ISO/IEC 17825:2016.
Case Study: Evaluating a Cryptographic Security Module
Consider a hypothetical financial technology company developing a hardware security module (HSM) for protecting encryption keys used in banking transactions. The company has implemented several security mechanisms, but before deploying the device, it needs to determine whether its cryptographic module is sufficiently resistant to non-invasive attacks.
The company begins by defining the cryptographic module’s security boundary and identifying the inputs and outputs available at that boundary. This is important because ISO/IEC 17825:2024 specifies that testing is conducted at the defined boundary of the cryptographic module and considers the available inputs and outputs.
Security testers then apply the relevant non-invasive attack testing metrics. Depending on the characteristics of the module and its security functions, the evaluation can investigate whether observable behavior generated during operation could provide useful information to an attacker. The objective is not simply to determine whether the device functions correctly, but whether its security mechanisms adequately mitigate relevant information leakage.
Identifying and Addressing Security Weaknesses
Suppose testing identifies evidence that certain operating conditions produce measurable leakage associated with cryptographic processing. The development team can investigate the implementation and introduce appropriate countermeasures. These could include changes to hardware design, cryptographic implementation, randomization, or other mechanisms intended to reduce exploitable leakage.
The module can then undergo further testing to determine whether the changes provide the expected improvement. This creates a practical development cycle: test, identify weaknesses, implement countermeasures, and retest.
Supporting Conformance and Certification
The value of ISO/IEC 17825:2024 extends beyond product development. Its test metrics are intended to support determination of conformance with the requirements specified in ISO/IEC 19790:2012 for Security Levels 3 and 4. ISO/IEC 17825:2024 is also intended to be used together with ISO/IEC 24759:2017, which provides the testing methods used by laboratories to assess cryptographic modules against the applicable requirements and metrics.
The standard describes its testing approach as technically sound, repeatable, and designed to have moderate costs. This makes standardized evaluation valuable for manufacturers and testing laboratories that need consistent security evidence.
Results and Business Benefits
For the hypothetical financial technology company, successful evaluation provides several benefits. First, it can identify implementation weaknesses before the HSM is deployed in production. Second, it gives engineers measurable evidence for improving security countermeasures. Third, standardized testing can support the broader certification process and increase confidence among customers and other stakeholders.
The same approach can be relevant to cryptographic modules used in payment systems, telecommunications, government technology, secure computing, and other environments where protection of cryptographic information is essential.
Conclusion
This case study demonstrates how ISO/IEC 17825:2024 can be incorporated into the development and evaluation lifecycle of a cryptographic module. Rather than treating hardware security as a purely theoretical property, the standard provides structured metrics for assessing resistance to non-invasive attacks. When combined with ISO/IEC 19790 and ISO/IEC 24759, it contributes to a systematic framework for testing, improving, and demonstrating the security of cryptographic implementations.
For organizations developing or evaluating cryptographic hardware, ISO/IEC 17825:2024 therefore represents an important tool for reducing information-leakage risks and strengthening overall hardware security assurance.
Relevant External Resources
- ISO/IEC 17825:2024 — Official ISO Standard
- ISO/IEC 17825:2024 — IEC Webstore
- ISO/IEC JTC 1/SC 27 — Information Security, Cybersecurity and Privacy Protection
#InformationTechnology
White Paper: ISO/IEC 17825:2024 Information Technology
Executive Summary
Cryptography is a fundamental component of modern information technology security. Organizations rely on cryptographic modules to protect encryption keys, authentication information, communications, financial transactions, and sensitive data. However, the security of a cryptographic system depends not only on the strength of its algorithms but also on the way those algorithms are implemented in hardware and software.
ISO/IEC 17825:2024 addresses an important aspect of this challenge. Formally titled Information technology — Security techniques — Testing methods for the mitigation of non-invasive attack classes against cryptographic modules, the standard specifies test metrics for evaluating mitigation against non-invasive attacks. The second edition was published in January 2024 and replaced ISO/IEC 17825:2016.
The standard is specifically intended to help determine conformance with the requirements of ISO/IEC 19790:2012 for Security Levels 3 and 4. It is designed to be used together with ISO/IEC 24759:2017, which provides testing methods for laboratories assessing cryptographic modules.
This white paper examines the purpose, scope, testing approach, security significance, implementation considerations, and benefits of ISO/IEC 17825:2024.
1. Introduction
The rapid expansion of cloud computing, digital payments, telecommunications, connected devices, and critical digital infrastructure has increased dependence on cryptographic technologies. Encryption and authentication mechanisms are now embedded in a wide variety of information technology products.
While cryptographic algorithms are mathematically designed to resist attacks, implementations can unintentionally reveal information through their physical or operational behavior. These vulnerabilities are commonly associated with non-invasive attacks, in which an attacker attempts to obtain useful information without physically modifying or destroying the cryptographic module.
ISO/IEC 17825:2024 provides a standardized approach for evaluating whether cryptographic modules adequately mitigate these types of attacks. The standard focuses on test metrics associated with the security functions addressed by ISO/IEC 19790:2012.
2. Understanding Non-Invasive Attacks
A cryptographic module processes sensitive information such as secret keys and authentication data. During operation, the device may produce observable characteristics that can potentially provide information about internal processing.
Examples of information that may be examined during security evaluation include physical or operational behavior associated with cryptographic processing. Attackers with appropriate equipment and expertise may attempt to analyze such observations to identify relationships between measurable behavior and secret information.
The significance of these attacks is that an adversary may not need to open, modify, or destroy the target device. Consequently, conventional functional testing alone may not identify these vulnerabilities.
ISO/IEC 17825:2024 addresses this problem by defining standardized non-invasive attack mitigation test metrics.
3. Scope of ISO/IEC 17825:2024
The standard is focused specifically on cryptographic modules and their resistance to non-invasive attack classes. According to ISO, testing is conducted at the defined boundary of the cryptographic module and the inputs and outputs available at that boundary.
This defined boundary is important because it establishes what is being evaluated and provides a consistent basis for testing. Rather than attempting to assess every component of a larger IT environment, the methodology concentrates on the security-relevant cryptographic module.
ISO/IEC 17825:2024 specifies metrics associated with the security functions addressed by ISO/IEC 19790:2012 and is intended to support conformance evaluation for Security Levels 3 and 4.
4. Relationship With Other Security Standards
ISO/IEC 17825:2024 should not be viewed as an isolated security standard. It forms part of a broader framework for cryptographic module evaluation.
ISO/IEC 19790:2012 establishes security requirements for cryptographic modules. ISO/IEC 17825:2024 provides non-invasive attack mitigation test metrics associated with those requirements.
Meanwhile, ISO/IEC 24759:2017 specifies the test methods used by testing laboratories to assess whether cryptographic modules conform to the applicable ISO/IEC 19790 requirements and the associated metrics in ISO/IEC 17825.
This relationship can be summarized as:
ISO/IEC 19790 → Security requirements
ISO/IEC 17825 → Non-invasive attack mitigation test metrics
ISO/IEC 24759 → Laboratory testing methods
Together, these standards provide a structured approach to cryptographic module security evaluation.
5. Testing and Evaluation Approach
One of the notable characteristics of ISO/IEC 17825:2024 is its emphasis on testing that is technically sound, repeatable, and relatively efficient. ISO describes the approach as an efficient “push-button” approach, with moderate testing costs.
A typical evaluation process can involve establishing the scope of the cryptographic module, identifying the applicable security functions, performing the prescribed testing, analyzing the resulting evidence, and determining whether the applicable mitigation metrics have been satisfied.
This repeatability is important for security laboratories because consistent methodologies allow evaluations to be performed using standardized criteria rather than relying exclusively on subjective judgment.
6. Importance for Hardware Security
Hardware security is increasingly important because cryptographic functions are frequently implemented in physical devices. Examples include dedicated cryptographic hardware, secure processors, embedded systems, payment technologies, and other security-sensitive platforms.
A cryptographic implementation may be vulnerable even when it uses a well-established algorithm. Weaknesses can arise from implementation details, physical characteristics, or insufficient countermeasures.
Testing against non-invasive attack classes can therefore help manufacturers identify potential information leakage and evaluate whether security mechanisms are functioning as intended.
This supports a security-development lifecycle in which testing is performed not merely after a product has been completed but as part of continuous design validation and security assurance.
7. Benefits for Cybersecurity
Implementation and evaluation against ISO/IEC 17825:2024 can provide several cybersecurity benefits.
Improved Detection of Information Leakage
Testing can reveal weaknesses that conventional software or functional testing may overlook. This is particularly valuable when cryptographic secrets could potentially be inferred from observable behavior.
Stronger Cryptographic Module Assurance
The standard provides objective testing metrics that contribute to a structured assessment of cryptographic module security.
Support for Certification
Because ISO/IEC 17825:2024 is intended to be used with ISO/IEC 19790:2012 and ISO/IEC 24759:2017, it can contribute to a broader conformity and certification process.
Improved Product Development
Security testing can identify weaknesses early enough for manufacturers to introduce appropriate countermeasures before deployment.
Greater Stakeholder Confidence
Independent, standardized testing can provide customers and other stakeholders with greater confidence that a cryptographic module has undergone a structured security evaluation.
8. Applications in Information Technology
ISO/IEC 17825:2024 is relevant to organizations and laboratories involved in designing and evaluating cryptographic modules. Potential application areas include financial technology, telecommunications, secure computing, government systems, payment infrastructure, and embedded security technologies.
The standard is particularly relevant where cryptographic modules must provide stronger assurance against sophisticated non-invasive attacks.
However, it is important to recognize that ISO/IEC 17825:2024 is not a general-purpose cybersecurity standard for an entire organization or IT network. Its primary focus is the testing of cryptographic modules against defined classes of non-invasive attacks.
9. Implementation Considerations
Organizations considering ISO/IEC 17825:2024 should begin by determining whether their technology contains a cryptographic module that falls within the applicable evaluation framework.
The organization should then establish the module boundary, identify relevant security functions, understand the applicable ISO/IEC 19790 requirements, and determine the appropriate testing methodology under ISO/IEC 24759.
Testing should be performed by appropriately qualified personnel or laboratories with suitable expertise in cryptographic module evaluation. Organizations should also maintain appropriate documentation of the module configuration, testing conditions, results, corrective actions, and subsequent evaluations.
Importantly, successful testing should be treated as one element of a comprehensive cybersecurity strategy rather than as a substitute for secure development, vulnerability management, access control, physical security, incident response, and other security measures.
10. Strategic Value for Critical Infrastructure
Critical infrastructure organizations increasingly rely on cryptographic mechanisms to protect operational technology, communications, authentication systems, and sensitive information.
A weakness in a cryptographic module could have consequences extending beyond a single device, particularly when the module is responsible for protecting keys used across interconnected systems.
By introducing repeatable testing for non-invasive attack mitigation, ISO/IEC 17825:2024 can contribute to stronger cryptographic assurance within security-sensitive environments.
Its value is particularly significant when organizations need demonstrable evidence that security controls have been evaluated against defined technical criteria.
11. Conclusion
ISO/IEC 17825:2024 provides an important technical framework for evaluating the resistance of cryptographic modules to non-invasive attack classes. Published as the second edition in January 2024, it updates the previous 2016 edition and provides test metrics intended to support conformance with ISO/IEC 19790:2012 Security Levels 3 and 4.
The standard’s greatest value lies in its structured and repeatable approach to evaluating cryptographic implementations. By examining security at the defined cryptographic-module boundary and working alongside ISO/IEC 19790 and ISO/IEC 24759, it contributes to a broader ecosystem for cryptographic security assurance.
For technology manufacturers, security laboratories, financial organizations, government agencies, and operators of security-sensitive infrastructure, ISO/IEC 17825:2024 can help identify information-leakage risks, strengthen cryptographic implementations, support conformity assessments, and improve confidence in hardware-based security.
As dependence on cryptography continues to grow, rigorous testing of how cryptographic modules behave in the real world will remain an important component of trustworthy information technology security.
Official and Relevant External Resources
- ISO/IEC 17825:2024 — Official ISO Standard
- ISO/IEC 17825:2024 — IEC Webstore
- ISO/IEC 17825:2024 Preview — ISO Online Browsing Platform
- ANSI — ISO/IEC 17825:2024
#ISOIEC178252024
Industry Application of ISO/IEC 17825:2024 Information Technology
Introduction
ISO/IEC 17825:2024 is an important standard for organizations that design, manufacture, test, or deploy cryptographic modules. Officially titled Information technology — Security techniques — Testing methods for the mitigation of non-invasive attack classes against cryptographic modules, the standard specifies test metrics for evaluating protection against non-invasive attacks. It is particularly relevant to cryptographic modules being assessed for ISO/IEC 19790 Security Levels 3 and 4 and is intended to be used together with ISO/IEC 24759:2017. (ISO)
Financial Services and Payment Technology
The financial industry is one of the major areas where cryptographic security is essential. Banks, payment processors, and financial technology providers use cryptographic modules to protect encryption keys, authentication information, and transaction data. Applying ISO/IEC 17825:2024 testing can help organizations evaluate whether cryptographic implementations adequately mitigate non-invasive attack techniques and identify potential information leakage before systems are deployed.
This is particularly important for hardware security modules and other security-sensitive payment technologies where compromise of cryptographic keys could have serious financial and operational consequences.
Telecommunications and Network Security
Telecommunications infrastructure relies extensively on cryptography to protect communications and authenticate devices and users. Cryptographic modules may be incorporated into network and communications equipment. ISO/IEC 17825:2024 provides a structured approach for evaluating the non-invasive attack resistance of such cryptographic implementations.
Testing at the defined cryptographic-module boundary also creates a consistent basis for laboratory assessment and comparison. (ISO)
IoT and Embedded Systems
Connected and embedded devices increasingly perform cryptographic operations while operating in environments where physical access may be difficult to control. Testing against non-invasive attack classes can help manufacturers identify weaknesses in cryptographic implementations and improve security countermeasures.
The standard is therefore relevant to organizations developing security-sensitive embedded products, although it should not be interpreted as a general cybersecurity certification for an entire IoT product or network.
Government and Critical Infrastructure
Government systems and critical infrastructure depend on cryptography to protect sensitive communications, identities, authentication mechanisms, and other critical information. Evaluating cryptographic modules using standardized testing methodologies can provide additional security assurance and support broader conformity assessments.
Hardware and Security Testing Laboratories
ISO/IEC 17825:2024 is particularly significant for testing laboratories because it establishes defined metrics for non-invasive attack mitigation. ISO states that its testing approach is designed to be technically sound, repeatable, and relatively efficient. (ISO)
Conclusion
ISO/IEC 17825:2024 has applications across financial services, telecommunications, embedded technology, government systems, critical infrastructure, and security testing laboratories. Its primary industry value is providing a consistent methodology for evaluating cryptographic modules against non-invasive attacks. By identifying potential leakage and supporting the evaluation of security countermeasures, the standard can strengthen cryptographic assurance and contribute to more resilient information technology systems.
Organizations should remember that ISO/IEC 17825:2024 addresses a specific aspect of cryptographic security rather than providing comprehensive protection for an entire IT environment. Its greatest value comes when it is incorporated into a broader security and conformity-assessment program.
Relevant External Resources
- ISO/IEC 17825:2024 — Official ISO Standard
- ISO/IEC 17825:2024 — IEC Webstore
- ISO/IEC 20085-1:2019 — Test Tools for Non-Invasive Attack Testing
- ISO/IEC JTC 1/SC 27 — Information Security, Cybersecurity and Privacy Protection
#ISOIEC17825
Ask FAQs
What is ISO/IEC 17825:2024?
ISO/IEC 17825:2024 is an international standard that specifies testing methods and metrics for evaluating the mitigation of non-invasive attack classes against cryptographic modules.
What types of attacks does ISO/IEC 17825:2024 address?
The standard focuses on non-invasive attacks that attempt to obtain sensitive information from cryptographic modules without physically modifying or damaging them. This includes attacks involving observable characteristics of a device during operation.
Which industries can benefit from ISO/IEC 17825:2024?
It is relevant to industries that rely on secure cryptographic modules, including banking and financial services, telecommunications, government, payment technology, embedded systems, IoT, and critical infrastructure.
How does ISO/IEC 17825:2024 improve hardware security?
It provides standardized testing metrics that can help identify information leakage and evaluate whether security countermeasures effectively reduce the risks associated with non-invasive attacks.
Is ISO/IEC 17825:2024 a complete cybersecurity standard?
No. It specifically addresses testing for non-invasive attack mitigation in cryptographic modules. It is intended to work alongside standards such as ISO/IEC 19790 and ISO/IEC 24759 as part of a broader cryptographic security evaluation and certification framework.
Disclaimer: This content is for general informational purposes only and should not be considered professional, legal, or certification advice. Always refer to the latest official ISO/IEC standards and qualified professionals for specific requirements.