Overview
ISO/TS 24574:2025 - Document management applications - Specification for a digital safe defines minimum functional requirements for digital safe software to ensure the integrity, confidentiality and availability (ICA) of digital objects. The Technical Specification focuses on software capabilities for managing digital objects (documents, images, scans, audio, etc.), preserving chain of custody, enforcing retention and freeze periods, and enabling transfer between digital safes. It explicitly excludes physical environment and power-supply security measures.
Key topics and technical requirements
The specification organizes functional and operational requirements across core areas. Key topics include:
- Core functions: mandatory operations such as Write, Read, Delete, Verify, Read technical metadata, Read audit trail, List and Count functions, and related parameters and result formats.
- Users and roles: user management model with defined roles (general administrator USR‑G, functional administrator USR‑F, standard user USR‑S) and administration functions for role management.
- Metadata and version control: technical metadata requirements, additional metadata, and versioning rules for digital objects.
- Retention, disposal and freeze: rules to manage retention periods and to prevent deletion during mandatory preservation intervals.
- Integrity, audit trail and chain of custody: requirements for tamper-evident audit trails, verification functions, and preservation of provenance to support legal or regulatory needs.
- Availability and resiliency: secondary hosting, backup, storage technology and migration provisions to maintain long‑term access.
- Security: access control, encryption of stored objects and message exchanges, and date/time formatting to support reliable auditing.
- Documentation and implementation: required technical manuals, installation/operation/user documentation, system versioning, and implementation guidance.
Applications and who should use it
ISO/TS 24574:2025 is intended for stakeholders involved in long‑term digital preservation and secure records management:
- Software vendors building or certifying digital safe or secure archival products
- Records managers and archivists specifying requirements for long‑term storage
- IT procurement teams evaluating vendor solutions against ICA, retention and audit requirements
- Legal, compliance and audit professionals ensuring admissibility and chain of custody
- Cloud storage and hosting providers offering secure, long‑term archival services
Use cases include procurement/specification of digital safe solutions, product interoperability and migration planning, and establishing defensible records retention and disposition policies.
Related standards
This Technical Specification was prepared by ISO/TC 171 (Document management applications) and references the relationship to other archiving and records management standards (see Annex A). Implementers should consider complementary ISO archival standards and organizational legal/regulatory requirements when applying ISO/TS 24574:2025.