ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Assurance
Specify assurance requirements covering development, guidance, life-cycle support, tests, and vulnerability assessment for this distribution method.
- Assurance plan
- Life-cycle records
- Vulnerability assessment reports
- Vulnerability assessment shallow
- Life-cycle records incomplete
Channel
Authenticate the classical channel used for sifting and reconciliation so an attacker cannot impersonate either endpoint.
- Pre-shared key procedure
- Authentication algorithm specification
- Key refresh logs
- Initial trust bootstrap undocumented
- Authentication keys not refreshed
Clause 1-3: Introductory Provisions
Defines the scope of security evaluation of QKD under the ISO/IEC 15408 series framework
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
References to ISO/IEC 15408 series, ISO/IEC 19790, and related cryptographic module standards
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Terminology specific to quantum key distribution security evaluation
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Defines scope of guidelines for organizational privacy risk management extended from ISO 31000:2018
- Privacy risk assessment
- Scope statement
- Definitions glossary
- Reference catalog
- Scope ambiguous
- Reference list incomplete
- Definitions inconsistent
- No baseline assessment
References to ISO 31000:2018, ISO/IEC 27005, and ISO/IEC 29100
- Privacy risk assessment
- Scope statement
- Definitions glossary
- Reference catalog
- Scope ambiguous
- Reference list incomplete
- Definitions inconsistent
- No baseline assessment
Privacy risk management terminology including PII, privacy event, and organizational privacy risk
- Privacy risk assessment
- Scope statement
- Definitions glossary
- Reference catalog
- Scope ambiguous
- Reference list incomplete
- Definitions inconsistent
- No baseline assessment
Clause 4: QKD Module Security Overview
Structural analysis of the security functionality of QKD modules
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Classification framework for QKD protocols to facilitate analysis of security functional requirements
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Analysis of security problems that QKD modules can face in their operational environment
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Clause 5: Security Functional Requirements for Conventional Network Components
Baseline security functional requirements for conventional network components of QKD modules
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
SFRs characterized under the framework of ISO/IEC 15408 and referring to ISO/IEC 19790 methodology
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Requirements aligned with standards on testing of cryptographic modules and network devices
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Clause 6: Security Functional Requirements for Quantum Optical Components
Security functional requirements specific to quantum optical components in QKD modules
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Requirements for security of single-photon and entangled-photon sources
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Requirements for protecting the quantum channel against side-channel attacks and eavesdropping
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Clause 7: Security Functional Requirements for QKD Protocol Implementation
Security functional requirements for the entire implementation of QKD protocols
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Requirements for error correction, privacy amplification, and key verification processes
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Security requirements for classical communication channels used in QKD post-processing
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Guidance
Provide preparative and operational guidance enabling secure installation, configuration, operation, and decommissioning.
- Installation guide
- Operational guide
- Decommissioning procedure
- Operational guide lacks failure modes
- Decommissioning steps missing
Incident
Handle incidents affecting the modules including key compromise scenarios with defined notification and key replacement procedures.
- Incident response plan
- Key replacement procedure
- Notification records
- No key replacement procedure
- Notifications informal
Integration
Integrate the modules with existing key consumers and network management without weakening the assurance achieved.
- Integration architecture
- Interface specifications
- Threat model for integration
- Management plane exposed
- Integration threat model missing
Key Management
Manage the lifecycle of keys produced by the module, including delivery to consumers, storage, rotation, and destruction.
- Key management procedure
- Consumer interface specification
- Destruction records
- Keys held longer than needed
- Destruction not verifiable
Lifecycle
Manage the module life-cycle from design through end-of-life including patching and surveillance of fielded units.
- Life-cycle plan
- Patch records
- Surveillance reports
- Field surveillance absent
- Patches require full re-evaluation
Operations
Monitor operational parameters such as detector counts, error rates, and timing to detect anomalies indicating attack or drift.
- Monitoring thresholds
- Anomaly alerts
- Incident response records
- No thresholds for error rate excursions
- Alerts not actioned
Part 2: Evaluation and Testing Methods
Test and evaluation methods for security functional requirements on QKD protocol implementation
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Test and evaluation methods for security of quantum optical components
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Test and evaluation methods for security of conventional network components in QKD modules
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Mapping of evaluation assurance levels to QKD module security assessment criteria
- Security target
- Protection profile
- Evaluation report
- Component test plan
- Component scope undefined
- Side-channel testing absent
- Authentication weak
- Protocol implementation deviates
Physical Layer
Characterise photon source and detector behaviour to confirm that emitted and measured states match the security proof assumptions.
- Source characterisation report
- Detector test data
- Calibration records
- Side-channel emissions unmeasured
- Detector efficiency mismatch not quantified
Physical Security
Protect the physical-layer key distribution modules against tamper, unauthorised access, and environmental attacks.
- Tamper evidence design
- Enclosure test reports
- Access logs
- Tamper detection not active
- Environmental thresholds undefined
Post-processing
Document error correction algorithm and parameters, including leaked information accounted for in privacy amplification.
- Algorithm specification
- Parameter tables
- Leakage accounting
- Leakage underestimated
- Parameters drift without re-evaluation
Apply privacy amplification with hash families and output lengths consistent with the calculated information available to an adversary.
- Hash family specification
- Output length justification
- Implementation tests
- Output length not tied to leakage estimate
- Hash family weakly justified
Proof
Map the implementation parameters to the assumptions of the underlying security proof and identify deviations.
- Proof reference
- Parameter mapping document
- Deviation register
- Deviations not assessed for impact
- Proof citations missing
Randomness
Verify random number generation used for basis choice and post-processing meets entropy and statistical requirements.
- RNG design document
- Entropy estimation
- Test suite results
- Entropy source not characterised
- Health tests not continuous
Requirements
Capture the security functional requirements for physical-layer key distribution modules, including key generation, sifting, error correction, and privacy amplification.
- Security functional requirements document
- Traceability matrix
- Design rationale
- Privacy amplification parameters not justified
- Traceability gaps to design
SDLC
Apply a defined secure development process including configuration management, flaw remediation, and developer testing.
- Development process documentation
- Configuration management plan
- Flaw remediation log
- Configuration baselines drift
- Flaw remediation untimely
Scope
Define the target of evaluation including the physical-layer key distribution modules, optical interfaces, and supporting classical control plane in scope.
- TOE description
- Architecture diagram
- Interface inventory
- Control plane excluded from scope
- Optical interfaces undocumented
Side-channels
Assess resistance to side-channel attacks including detector blinding, time-shift, wavelength, and trojan-horse attacks on this distribution method.
- Side-channel assessment report
- Countermeasure design
- Test logs
- Trojan-horse countermeasure absent
- Detector blinding not tested
Testing
Use defined test methods to evaluate conformance of modules to the functional and assurance requirements.
- Test plans
- Test reports
- Evaluator competence records
- Tests not repeatable
- Evaluator independence not demonstrated
Vulnerability
Conduct independent vulnerability analysis focusing on optical, electronic, and protocol-level attacks against this distribution method.
- Vulnerability analysis report
- Attack catalogue
- Residual risk register
- Analysis limited to documentation review
- Residual risk not communicated to operators
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.