EMVCo Development and Production Site Audit Guidelines
EMV®* Security Guidelines Development and Production Site Audit Guidelines Version 1.1 May 2015 * EMV is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo.
uses of the EMV Specifications (“Materials”) shall be permitted only pursuant to the terms and conditions of the license agreement between the user and EMVCo found at http://www.emvco.com/specifications.aspx.
Development and Production Site Audit Guidelines v1.1 Version v1.0 Date January 2013 Version History Initial release Description v1.1 May 2015 This release removes the references to Payment System specific processes and clarifies that production sites are part of the audit scope. It also introduces teleworking guidelines and periodic renewal audit guidelines.
uses of these Guidelines are subject to the terms and conditions of the EMVCo Terms of Use agreement available at www.emvco.com. These Guidelines are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Guidelines. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE GUIDELINES. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Guidelines. EMVCo undertakes no responsibility to determine whether any implementation of these Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of these Guidelines should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Guidelines may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Guidelines is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with these Guidelines.
Guidelines v1.1
Legal Notice
EMVCo uses test and security evaluation laboratories throughout the worl d in the preparation of Security Evaluation reports to support the EMVCo security evaluation process, as described in the current version of the EMV Security Guidelines Security Evaluation Process document. The security evaluation of a product (e.g., IC, Platform or CPA product) includes an audit of its product provider’s development, production and delivery infrastructure. This document outlines the common requirements and guidelines which a Recognized Security Evaluation Laboratory must use to perform an audit on the development and production site of a product provider. Neither this document nor any other document or communication creates any binding obligations upon EMVCo or any third party regarding testing services or EMVCo approval, which obligations will exist, if at all, pursuant to separate written agreements executed by EMVCo and such third parties. In the absence of a written binding agreement pursuant to which EMVCo has agreed to perform evaluation services for a product provider or to permit a third party to act as a test laboratory, no product provider, test laboratory or any other third party should rely on this document, nor shall EMVCo be liable for any such reliance. No product provider, test laboratory nor other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter or certificate issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo IC, Platform and ICC security evaluations, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received security evaluations and to the Card Type Approval process general ly, including, without limitation, any implied warranties of merchantability, fitness for purpose or noninfringement. All warranties, rights and remedies relating to products and services that have received EMVCo Card Type Approval are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo accepts no liability whatsoever in connection with such products and services. Unless otherwise agreed in writing by EMVCo, this document and matter contained herein, including all products and services contemplated by this document are provided on an “as -is” basis, “with all faults” and with no warranties whatsoever, and EMVCo specifically disclaims any implied warranties of merchantability, fitness for purpose, or non-infringement.
Guidelines v1. 1. 1. 1. 1. 1. 1. 2. 2. 2. 2. 2. 3. 3. 4. 4. 5. 5. 5.2.1 5.2.2 5.2.
Guidelines v1.1 1 Overview 1.1
Introduction
The security evaluation of a product (e.g., IC, Platform, or CPA product) includes an audit of its product provider’s development, production, and delivery infrastructure. The EMVCo development and production site audit process establishes common requirements and guidelines which a Recognized Security Evaluation Laboratory (“Evaluation Laboratory”) must use to perform an audit on the development or production site of a product provider. This includes the facility at which the product will be programmed (e.g., in case of a flash memory product). These requirements and guidelines:
- Allow product providers to reuse existing audit results and reports to avoid duplication of effort and cost
- Reduce inter-payment system redundancies and inconsistencies in the audit process Since each development environment is different and each country has different laws and requirements, the Evaluation Laboratory must take these differences into consideration in its preparation and execution of the site audit.
1.2 Objective The objective of this document is to provide Evaluation Laboratories with guidance and requirements regarding how to perform an EMVCo site audit on the development and production sites of a product provider, including any facility at which the products will be programmed, if applicable.
1.3 Audience This document is primarily intended for:
- Evaluation Laboratories – To enable them to perform an EMVCo site audit on development or production sites of product providers.
- Product Providers – To enable them to prepare for an onsite audit. Guidelines v1.1 1.4 Related Information Throughout this document, the following references have been used. These references include the most current versions at the time of this document’s writing. For future use, the most current versions should be referenced. Reference [PROC] Document Title EMVCo Security Evaluation Process [BL7] EMVCo SEWG – Development & Production Site Audit Version 5.0 – Mar 2015 1 – Apr 2015 1.5 Support and Contact Information Contact the EMVCo Security Evaluation Secretariat at securityevaluation@emvco.com with any questions about site audits on development and production sites of product providers.
1.6 Organization of Document This document includes the following information: Chapter 1 – Overview provides a general outline of the document, describes its objective and intended audience, identifies related documents, and provides support and contact information. Chapter 2 – Development and Production Site Audit Process describes the tasks the Evaluation Laboratory must consider to perform a site audit. Chapter 3 – Configuration Management focuses on establishing and maintaining consistency and traceability of the Target of Evaluation (TOE) throughout its life cycle. Chapter 4 – Delivery Management focuses on all handling and delivery processes related to the TOE and TOE product components. Chapter 5 – Site Protection Around TOE focuses on physical, logical, and organizational controls for all sensitive information and assets related to the TOE and TOE product components in the development or production site. Annex A – SAR Template provides the EMVCo Shared Audit Report template. Annex B – Glossary
Guidelines v1.1 2 Development and Production Site Audit Process 2.1 Introduction As part of the security evaluation process for each product, an Evaluation Laboratory must conduct an audit of the site at which the product is developed or produced, including any facility at which the product provider programs the product. An Evaluation Laboratory must provide assurance that product assets are properly tracked in a configuration management system and are appropriately protected against disclosure, theft, and corruption. 2.2
Scope
An Evaluation Laboratory must examine and understand the complete product development and production processes (from software design to final product delivery) and verify that the product provider implements and enforces appropriate security at each step in the process. An Evaluation Laboratory must:
- Obtain and review the product developer's written site security policies and procedures.
- Interview appropriate product provider personnel.
- Observe and record each step of the product developer's process.
- Examine the premises, facilities, and networks upon which product development occurs.
- Where appropriate, request sample elements of evidence. An audit might not be required for sites that are only involved in operations that could also be performed in the field (such as OTA personalization or application loading) using the same evaluated product security mechanisms. In order to allow reuse of site audit results, the audits shall focus on all onsite processes applicable to EMVCo products (whenever possible with actual product evidence). At minimum, the development and production site audit covers the following aspects:
- Configuration management – The product provider must identify, manage, and track all product elements during the product development and production processes.
- Delivery management – The product provider must adequately protect against disclosure or corruption (of product components such as source code or of the final product) during the delivery process.
- Site protection around the TOE – The product provider must promulgate and implement policies regarding physical, logical, and organizational security, including the security of the human resources, physical facilities, and networks involved in product development and production. Guidelines v1.1 In preparing and conducting each site audit, the Evaluation Laboratory should take into account that each development and production environment is different and each country has different laws and requirements. When considered appropriate, an Evaluation Laboratory should test for vulnerabilities associated with social engineering, bribery, extortion, or threats. The Evaluation Laboratory must document the results of each completed audit in an EMVCo development or production site audit report. Guidelines v1.1 2.3 Policy The Evaluation Laboratory must determine whether the product developer's development or production site and the products developed or produced therein are properly protected [PROC]. EMVCo requires that at least one EMVCo audit, covering the audit scope described herein, be performed per site. The Evaluation Laboratory may reuse previous site audit reports as well as a Common Criteria (CC) audit that covers the scope of the audit described herein. If a site audit has previously been conducted under a different evaluation scheme, the Evaluation Laboratory shall assess the previous audit evidence against EMVCo requirements to establish the level of reuse that can be applied. The Evaluation Laboratory shall also consider any changes to the site since the original audit date and present their findings to EMVCo. Because the full site audit report contains an Evaluation Laboratory’s intellectual property, only a summary of the site audit report is shared with other laboratories via an EMVCo Shared Audit Report (SAR). EMVCo requires that the SAR contains some minimum information (see section 2.5) that can be shared amongst the different EMVCo Evaluation Laboratories. For all new and previously audited sites, an EMVCo SAR is required. As part of each new product security evaluation, the product provider must attest to any changes from the original site audit. The Evaluation Laboratory must assess the impact of each change and document the conclusions in an updated SAR. Based on the product provider’s attestation about changes made since the last audit, the Evaluation Laboratory must submit an updated EMVCo SAR with each product submission. EMVCo considers a site audit to be valid for a period of five years from the audit completion date, assuming any small changes to the facility post audit have been reviewed by a trusted party and incorporated into the site audit report. After the five-year period has elapsed, a renewal site audit is required. EMVCo and each payment scheme reserve the right to request an additional site audit at any time. Guidelines v1.1 2.4 Site Audit Report The development or production site audit report must include a summary of the audit scope and security measures (physical, logical, and organizational). The report must provide an assessment of whether the security measures properly protect the assets related to the products developed or produced. The report must cover the following aspects:
- Summary of the audit scope
- Organizational structure
- Site(s), assets, and threats evaluated
- Services provided by the site(s)
- Delivery process
- Configuration management control
- Relevant policies and procedures, including their implementation and enforcement
- Organizational, logical, and site security 2.5 Shared Audit Report In addition to the full site audit report, the Evaluation Laboratory must create an EMVCo Shared Audit Report (SAR), which summarizes the site audit report. EMVCo requires that the SAR must contain the following information:
- Date
- Name and contact information of Evaluation Laboratory for SAR
- Name and contact information of Evaluation Laboratory that performed the full development or production site audit
- Site(s)
- Summary of audit scope
- Open findings and agreed action steps Please refer to Annex A for the EMVCo SAR template. Guidelines v1.1 3 Configuration Management Configuration management establishes and maintains consistency and traceability of the TOE throughout its life cycle. It provides security assurances through change control applied to changes made to hardware, software, firmware, tests, test tools, and documentation.
3.1 Scope The Evaluation Laboratory must assess the documented configuration management policies and procedures for the identification and management of the TOE and the TOE product components (including TOE product-related sensitive assets and tools). The Evaluation Laboratory must assess the appropriateness and correct implementation of the configuration management system. The system must provide good traceability and a unique identifier for all items constituting the TOE product. Note Configuration management requirements also apply to development tools and compilation variables.
3.2 Audit Activities At minimum, the Evaluation Laboratory must observe and perform the following activities:
- Review the documented configuration management policies and procedures in use for the TOE, its product components, and tools used.
- Review the configuration management system on site to establish that the policies and procedures are effectively implemented.
- Verify that:
- Each part of the TOE is uniquely identified.
- Changes are performed by authorized personnel only.
- Each change is traceable. Guidelines v1.1 4 Delivery Management Delivery management focuses on all handling and delivery of the TOE and its product components to ensure adequate security. This assessment must include examination of the encryption system, cryptographic keys, and the key management system used to protect the delivery process.
4.1 Scope The Evaluation Laboratory must examine all handling and delivery processes for the TOE and its product components (e.g., wafers, source code, and transport key) and assess whether they provide appropriate protection against masquerade, disclosure, and corruption. Prior to transferring materials between development and production sites, the sending party must notify the receiving party of the transfer and document the fact that the receiving party has been notified. The delivery notification must inform the recipient what is being shipped, the quantity (if relevant), and how to inform the sending party in the event of an anomaly. Upon receipt of the shipment, the receiving party must acknowledge receipt. The sending party must maintain the acknowledgement together with the original delivery notification.
4.2 Audit Activities At minimum, the Evaluation Laboratory must observe and perform the following activities:
- Review the documented internal handling, delivery, and receiving policies and procedures for the TOE and its product components.
- Review evidence to assess the effective implementation of policies and procedures.
- Verify that the TOE product and associated sensitive assets (e.g., wafers, source code), data, and information are protected by adequate integrity and access controls against masquerade, disclosure, and corruption.
- Verify that the TOE source code integrity is controlled at each stage. Guidelines v1.1 5 Site Protection Around TOE Site protection policies and procedures provide physical, logical, and organizational controls for all sensitive information and assets related to the TOE and its product components in the development or production site.
5.1 Scope The Evaluation Laboratory must assess the physical, logical, and organizational protections provided in all development or production sites that issue or handle sensitive information. This includes the secure management of sensitive items provided by subcontractors. The Evaluation Laboratory must determine whether the product developer's security policies and procedures are implemented in such a manner as to ensure adequate protection of the TOE and its product components.
5.2 Audit Activities At minimum, the Evaluation Laboratory must observe and perform the following activities:
- Review the documented security policies and procedures enforcing the protection of the TOE, sensitive information, systems, and devices.
- Review the management of subcontractors, including the subcontractor security procedures.
- Review the development or production site(s) physical, logical, and organizational controls, including security systems; toward that end:
- Obtain samples of evidence related to site security controls such as personnel security management, site and building access controls, and security monitoring (e.g., video, alarms, and recording of security events).
- Inspect the software development environment, and obtain samples of evidence related to physical and logical access controls for networks and software databases, and for the delivery of source code files to external partners. Guidelines v1.1 5.2.1 Physical
- The development area must be a solid structure and should prevent external observation of development or production work through, for example, windows or skylights.
- Where the development or production area is part of a shared building or complex, there must be sufficient security measures in place to prevent unauthorized people from entering the area.
- The development or production area must be secured with an intrusion alarm system. All entrances and windows must be secured and alarmed. This alarm system must be linked directly to the police or a security firm.
- The cabling of the physical network must be adequately protected to prevent monitoring or tampering with data. If the cabling cannot be protected then all data being transferred on an unprotected LAN must be encrypted.
- There must also be sufficient security measures in place to prevent eavesdropping or similar monitoring of work performed.
5.2.2 Organizational
- In order to avoid conflict of interest and duty, there must be organizational separation between development, production, testing, and quality assurance.
- There must be a Security Manager, approved by management, responsible for ensuring compliance with documented security policies and procedures, continued application of security measures, and the detection of security breaches.
- If someone leaves the development team for any reason, their access rights to both physical and network development facilities must immediately be revoked and the product developer's Security Manager must be made aware of the person’s removal or departure. The Security Manager should interview and out-process all departing personnel, confirming that they are not taking any products, product components, or product development data, and that they understand their continuing duty to hold such products, components, and data confidential.
- If someone leaves the production team for any reason their access rights to both physical and network production facilities must immediately be revoked and the production Security Manager must be made aware of the person’s removal or departure. The Security Manager should interview and out-process all departing personnel, confirming that they are not taking any products or product components, and that they understand their continuing duty to hold such products and components confidential.
- There must be a documented contingency plan concerning access control to the TOE and its product components in the event of an emergency. The plan must detail what procedures are to be followed. Guidelines v1.1
- The development documentation must identify the locations at which development occurs, and describe the aspects of development performed, along with the security measures applied at each location and for transport between different locations.
- The production documentation must identify the locations at which production occurs, and describe the aspects of production performed, along with the security measures applied at each location and for transport between different locations.
- All visitors to the development and production environments must have proper identification and verification, must be logged, and must be escorted at all times once in the environment.
- To the extent legally permissible in the applicable jurisdiction, the product provider must perform background checks on all staff including:
- A summary description of current personnel background check policies and procedures, to confirm that the procedures include at least:
- Gathering current photographs
- Verifying identity and existence of aliases (if any)
- Annually reviewing records of any criminal activity, arrests, or convictions
- All applicant and employee background information is to be retained on file for at least 18 months after the termination of the contract of employment. This information must be available for the inspector during site security reviews.
- Subcontractors must be required by contract to implement commensurate security measures so that all items transiting their companies are provided with an equivalent level of protection in terms of integrity and confidentiality. Note It is not mandatory to visit the subcontractor site: The need for such a visit will depend on the security control and management of the subcontracted activities achieved by the product developer, and the elements of evidence provided during the visit to the product developer.
5.2.3 Logical
- Only the Security Manager (or delegated authority) should have authority to grant access privileges to the development or production network. Access rights shall only be granted to employees as part of an approved management procedure, and based on access privileges that are necessary to perform each employee's job functions.
- Access to development machines shall be restricted to approved development team members and system administrators.
- Access to production machines shall be restricted to approved production team members and system administrators. Guidelines v1.1
- Weak and shared passwords are not allowed. The product provider shall have specific polices as to how long passwords must be, how many different character types must be included in a password, and how frequently passwords must be changed, and it must have a practical means for enforcing those policies.
- Development and production machines must be configured to prevent employees, contractors, and other personnel from installing unauthorized software or hardware tools.
- The Security Manager (or delegated authority) must approve in writing any request to install additional software or hardware tools, and must do so only when necessary to an employee's performance of job functions.
- The product provider should have and implement policies and procedures for creating, storing, protecting, and securely destroying backups. The policy should prohibit making unauthorized backups.
- For data transmission between physically separate sites, sensitive data must be encrypted based on industry accepted cryptography and standards. On closed systems within the same secure physical site no encryption is required.
- Where a non-dedicated network is used, suitable controls must be in place to protect the integrity of the data within the development and production sites. Access to the networks must be limited to those people who require access as part of their work, and the network must be capable of preventing all unauthorized access by the use of security controls. These controls include the use of firewalls and routers that offer sufficient security levels for the data being handled.
- If remote working is allowed, then:
- The product provider must have a documented policy and procedure stating this and specifying in detail the activities allowed. The Evaluation Laboratory must verify that this policy adequately defines permitted activities and associated controls to prevent unauthorized disclosure or modification of information. This includes adequate logging to support traceability and audit trails.
- Remote working (teleworking) solutions must be adequately protected to prevent data from being monitored or tampered with. The solutions used must encrypt the data based on industry accepted cryptography and standards.
- An independent network security auditor should document and assess all network security measures at least once a year.
- If wireless networks are used, they must be securely configured and must be monitored.
- The product provider must have a policy for control of personal devices within development or production areas. It must be verified that this policy adequately protects the development or production site from threats. Guidelines v1.1
- The product provider must have a removable media policy (e.g., use of thumb drives). It must be verified that this policy adequately protects the development or production site from threats.
- The product provider must have an employee monitoring policy indicating that all use of the development or production network may be lawfully monitored. Guidelines v1.1 Annex A SAR Template The classification of the SAR is Confidential. EMVCo Development and Production Site Shared Audit Report (SAR) Shared Audit Report (SAR) Evaluation Laboratory: Date: Sites: Full Site Audit Evaluation Laboratory: Date: Sites: Summary of Audit Scope Open Findings and Agreed Action Steps EMVCo-SEWG-15-G02 - May 2015 uses of the EMV Specif ications (“Materials”) shall be permitted only pursuant to the terms and conditions of the license agreement between the user and EMVCo f ound at http://www.emvco.co m/sp ecificatio ns.asp x. Annex B Glossary Development and Production Site Audit Guidelines v1.1 CC CPA IC SAR TOE Term Common Criteria Definition Common Payment Application Integrated Circuit Shared Audit Report Target of Evaluation EMVCo-SEWG-15-G02 - May 2015 uses of the EMV Specif ications (“Materials”) shall be permitted only pursuant to the terms and conditions of the license agreement between the user and EMVCo f ound at http://www.emvco.co m/sp ecificatio ns.asp x.