Overview
SIST ISO 9564-1:1995 is an international standard defining minimum security measures for effective management and protection of Personal Identification Numbers (PINs) in banking. Published by SIST and aligned with ISO/IEC practices, this standard establishes essential principles and techniques for PIN protection throughout their life cycle, supporting secure electronic financial transactions across global networks. It specifically addresses PIN management for bank card originated transactions and does not cover non-PIN transaction data privacy or protection of transactions using integrated circuit cards.
Key Topics
1. PIN Protection Principles
- Emphasizes safeguarding PIN secrecy at all times - including selection, issuance, activation, storage, entry, transmission, validation, deactivation, and destruction.
- Governs procedures so that hardware and software cannot be fraudulently accessed or modified without detection.
- Requires that PINs, when stored, are encrypted unless physically secured.
- Mandates controls to prevent PINs from being displayed, verbally communicated, or entered through insecure devices.
2. PIN Management Techniques
- Stipulates the use of secure procedures for PIN selection (assigned, random, or customer-selected), issuance (via secure PIN mailers), and changes.
- PINs must be 4 to 12 characters in length; customers should be advised on PIN secrecy.
- Special attention to disposal of materials which might reveal PINs (e.g., returned mailers, printing residue).
3. Encipherment and Key Management
- PINs must be encrypted using approved cryptographic algorithms and keys (referenced in ISO 9564-2).
- Specific cryptographic keys for storage and transmission cannot be used elsewhere.
- Proper key management and dual control processes are required to prevent compromise.
4. Physical and Logical Security
- Devices managing PINs must be physically secure - unauthorized penetration must erase sensitive data and render the device unusable.
- All PIN entry devices (PIN pads) should prevent PIN observation and must meet strict design criteria.
- Secure environments are required for handling unencrypted PINs or cryptographic keys.
Applications
- ATM and POS Networks: Banks and transaction processors use the standard to define PIN handling requirements for ATMs and point-of-sale terminals.
- Card Issuance: Institutions follow these PIN management guidelines when issuing cards or enabling PIN changes to ensure customer security.
- Interbank and International Transactions: Provides standardized procedures for PIN encryption and verification, enabling secure cross-institution and international financial services.
- Regulatory Compliance: Financial organizations implement the principles of SIST ISO 9564-1 to meet audit, risk management, and industry compliance requirements.
Related Standards
- ISO 9564-2: Covers approved algorithms for PIN encipherment.
- ISO 7812: Defines identification card numbering systems for issuer and account identification.
- ISO 8583: Specifies financial transaction message content for card-originated exchanges.
- ISO 9807: Details requirements for message authentication in retail banking.
- ISO 8908: Describes vocabulary and data elements in banking and related financial services.
Adherence to SIST ISO 9564-1 supports robust PIN management, reducing fraud risk and fostering consumer trust in electronic banking. Standardized PIN protection techniques are central to the secure operation of ATMs, POS systems, and global interoperable banking infrastructures. For financial institutions, integrating the requirements of this standard is a critical part of building and maintaining resilient payment security systems.