Content deleted Content added
m Added NIST reference |
mNo edit summary |
||
Line 9:
<!-- How do I change the title of the entry itself to be ISO 20243:Open Trusted Technology Provider Standard EDIT BELOW THIS LINE -->
The Open Trusted Technology Provider[[Trademark symbol|™]] Standard (O-TTPS) (''Mitigating Maliciously Tainted and Counterfeit Products'') is a standard of [[The Open Group]] that has also been approved for publication as an [[Information technology|Information Technology]] standard by the [[International Organization for Standardization]] and the [[International Electrotechnical Commission]] through [[ISO/IEC JTC 1]] and is now also known as ISO/IEC 20243:2015 <ref>{{cite web|title=ISO/IEC 20243:2015|url=http://www.iso.org/iso/catalogue_detail.htm?csnumber=67394|website=ISO.org|publisher=ISO.org|accessdate=24 September 2015}}</ref>. The standard consists of a set of guidelines, requirements, and recommendations that align with [[best practice]]s for global [[supply chain security]] and the integrity of [[commercial off-the-shelf]] (COTS) [[information and communication technology]] (ICT) products.<ref>{{Cite journal|last=Bartol|first=Nadya|date=23 May 2016|title=Cyber supply chain security practices DNA – Filling in the puzzle using a diverse set of disciplines|url=http://www.sciencedirect.com/science/article/pii/S0166497214000066|journal=Technovation|doi=10.1016/j.technovation.2014.01.005|pmid=|access-date=23 May 2016}}</ref> <ref>{{Cite book|title=Cybersecurity in Our Digital Lives|last=Whitman|first=Dave|publisher=Hudson Whitman Excelsior College Press|year=March 2015|isbn=978-0-9898451-4-4|editor-last=LeClair|editor-first=Jane|___location=|pages=|chapter=Cybersecurity in Supply Chains|editor-last2=Keeley|editor-first2=Gregory}}</ref> It is currently in version 1.1 <ref name=":0">{{cite web|url=https://www2.opengroup.org/ogsys/catalog/C147|title=Open Group's Publication Library|website=opengroup.org|publisher=The Open Group|accessdate=22 June 2015}}</ref> <ref>{{Cite web|url=http://www.iso.org/iso/catalogue_detail.htm?csnumber=67394|title=ISO/IEC 20243:2015 - Information Technology -- Open Trusted Technology ProviderTM Standard (O-TTPS) -- Mitigating maliciously tainted and counterfeit products|website=ISO|access-date=2016-05-23}}</ref>. A Chinese translation has also been published.<ref>{{Cite
== Background ==
Line 21:
== Purpose ==
The standard, developed by industry experts within the Forum, specifies organizational practices that provide assurance against maliciously tainted and counterfeit products throughout the COTS ICT product lifecycle. <ref>{{cite web|url=
== Measurement and Certification ==
Organizations can be certified for their conformance to the standard
== History ==
Line 33:
The first publication of the Forum was a whitepaper describing the overall Trusted Technology Framework in 2010.<ref>{{cite web|url=https://www2.opengroup.org/ogsys/catalog/W157|title=Open Trusted Technology Framework|website=opengroup.org|publisher=The Open Group|accessdate=April 13, 2015}}</ref> The whitepaper was broadly focused on overall best practices that good commercial organizations follow while building and delivering their COTS ICT products. That broad focus was narrowed during late 2010 and early 2011 to address the most prominent threats of counterfeit and maliciously tainted products resulting in the O-TTPS which focuses specifically on those threats.
The first version of O-TTPS was published in April 2013.<ref>{{cite web|title=O-TTPS|url=https://www2.opengroup.org/ogsys/catalog/C139|website=opengroup.org|publisher=The Open Group|accessdate=11 May 2015}}</ref>Version 1.1 of the O-TTPS standard was published in July 2014.<ref
The O-TTPS Accreditation Program began in February 2014. [[IBM]] was the first company to achieve accreditation for conformance to the standard.<ref>{{cite web|title=IBM Secure Engineering|url=http://www-03.ibm.com/security/secure-engineering/ibmottpsaccreditation.html|website=ibm.com|publisher=IBM Corp|accessdate=13 April 2015}}</ref>
|