Skip to content

Evidence request lists

ISO/IEC 23837 - Security Requirements for Quantum Key Distribution

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Assurance

23837-SAR
Security Assurance Requirements

Specify assurance requirements covering development, guidance, life-cycle support, tests, and vulnerability assessment for this distribution method.

Artefacts an auditor will ask for
  • Assurance plan
  • Life-cycle records
  • Vulnerability assessment reports
Where this commonly fails
  • Vulnerability assessment shallow
  • Life-cycle records incomplete

Channel

23837-CHAN
Channel Integrity and Authentication

Authenticate the classical channel used for sifting and reconciliation so an attacker cannot impersonate either endpoint.

Artefacts an auditor will ask for
  • Pre-shared key procedure
  • Authentication algorithm specification
  • Key refresh logs
Where this commonly fails
  • Initial trust bootstrap undocumented
  • Authentication keys not refreshed

Clause 1-3: Introductory Provisions

23837-1.1
Scope

Defines the scope of security evaluation of QKD under the ISO/IEC 15408 series framework

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.2
Normative references

References to ISO/IEC 15408 series, ISO/IEC 19790, and related cryptographic module standards

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.3
Terms and definitions

Terminology specific to quantum key distribution security evaluation

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
27557-1
Scope

Defines scope of guidelines for organizational privacy risk management extended from ISO 31000:2018

Artefacts an auditor will ask for
  • Privacy risk assessment
  • Scope statement
  • Definitions glossary
  • Reference catalog
Where this commonly fails
  • Scope ambiguous
  • Reference list incomplete
  • Definitions inconsistent
  • No baseline assessment
27557-2
Normative references

References to ISO 31000:2018, ISO/IEC 27005, and ISO/IEC 29100

Artefacts an auditor will ask for
  • Privacy risk assessment
  • Scope statement
  • Definitions glossary
  • Reference catalog
Where this commonly fails
  • Scope ambiguous
  • Reference list incomplete
  • Definitions inconsistent
  • No baseline assessment
27557-3
Terms and definitions

Privacy risk management terminology including PII, privacy event, and organizational privacy risk

Artefacts an auditor will ask for
  • Privacy risk assessment
  • Scope statement
  • Definitions glossary
  • Reference catalog
Where this commonly fails
  • Scope ambiguous
  • Reference list incomplete
  • Definitions inconsistent
  • No baseline assessment

Clause 4: QKD Module Security Overview

23837-1.4.1
QKD module structural analysis

Structural analysis of the security functionality of QKD modules

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.4.2
Classification of QKD protocols

Classification framework for QKD protocols to facilitate analysis of security functional requirements

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.4.3
Security problems analysis

Analysis of security problems that QKD modules can face in their operational environment

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates

Clause 5: Security Functional Requirements for Conventional Network Components

23837-1.5.1
Network component SFRs overview

Baseline security functional requirements for conventional network components of QKD modules

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.5.2
Cryptographic module requirements

SFRs characterized under the framework of ISO/IEC 15408 and referring to ISO/IEC 19790 methodology

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.5.3
Network device testing requirements

Requirements aligned with standards on testing of cryptographic modules and network devices

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates

Clause 6: Security Functional Requirements for Quantum Optical Components

23837-1.6.1
Quantum optical component SFRs

Security functional requirements specific to quantum optical components in QKD modules

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.6.2
Photon source security

Requirements for security of single-photon and entangled-photon sources

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.6.3
Quantum channel security

Requirements for protecting the quantum channel against side-channel attacks and eavesdropping

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates

Clause 7: Security Functional Requirements for QKD Protocol Implementation

23837-1.7.1
Protocol implementation SFRs

Security functional requirements for the entire implementation of QKD protocols

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.7.2
Key distillation process security

Requirements for error correction, privacy amplification, and key verification processes

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-1.7.3
Authentication and classical post-processing

Security requirements for classical communication channels used in QKD post-processing

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates

Guidance

23837-GUI
Guidance Documentation

Provide preparative and operational guidance enabling secure installation, configuration, operation, and decommissioning.

Artefacts an auditor will ask for
  • Installation guide
  • Operational guide
  • Decommissioning procedure
Where this commonly fails
  • Operational guide lacks failure modes
  • Decommissioning steps missing

Incident

23837-INC
Incident Handling

Handle incidents affecting the modules including key compromise scenarios with defined notification and key replacement procedures.

Artefacts an auditor will ask for
  • Incident response plan
  • Key replacement procedure
  • Notification records
Where this commonly fails
  • No key replacement procedure
  • Notifications informal

Integration

23837-NET
Network Integration

Integrate the modules with existing key consumers and network management without weakening the assurance achieved.

Artefacts an auditor will ask for
  • Integration architecture
  • Interface specifications
  • Threat model for integration
Where this commonly fails
  • Management plane exposed
  • Integration threat model missing

Key Management

23837-KEYMGT
Output Key Management

Manage the lifecycle of keys produced by the module, including delivery to consumers, storage, rotation, and destruction.

Artefacts an auditor will ask for
  • Key management procedure
  • Consumer interface specification
  • Destruction records
Where this commonly fails
  • Keys held longer than needed
  • Destruction not verifiable

Lifecycle

23837-LCM
Life-cycle Management

Manage the module life-cycle from design through end-of-life including patching and surveillance of fielded units.

Artefacts an auditor will ask for
  • Life-cycle plan
  • Patch records
  • Surveillance reports
Where this commonly fails
  • Field surveillance absent
  • Patches require full re-evaluation

Operations

23837-MON
Operational Monitoring

Monitor operational parameters such as detector counts, error rates, and timing to detect anomalies indicating attack or drift.

Artefacts an auditor will ask for
  • Monitoring thresholds
  • Anomaly alerts
  • Incident response records
Where this commonly fails
  • No thresholds for error rate excursions
  • Alerts not actioned

Part 2: Evaluation and Testing Methods

23837-2.1
Evaluation activities for protocol implementation

Test and evaluation methods for security functional requirements on QKD protocol implementation

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-2.2
Evaluation activities for quantum optical components

Test and evaluation methods for security of quantum optical components

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-2.3
Evaluation activities for conventional network components

Test and evaluation methods for security of conventional network components in QKD modules

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates
23837-2.4
Evaluation assurance levels

Mapping of evaluation assurance levels to QKD module security assessment criteria

Artefacts an auditor will ask for
  • Security target
  • Protection profile
  • Evaluation report
  • Component test plan
Where this commonly fails
  • Component scope undefined
  • Side-channel testing absent
  • Authentication weak
  • Protocol implementation deviates

Physical Layer

23837-SRC
Source and Detector Characterisation

Characterise photon source and detector behaviour to confirm that emitted and measured states match the security proof assumptions.

Artefacts an auditor will ask for
  • Source characterisation report
  • Detector test data
  • Calibration records
Where this commonly fails
  • Side-channel emissions unmeasured
  • Detector efficiency mismatch not quantified

Physical Security

23837-PHY
Physical Security of Modules

Protect the physical-layer key distribution modules against tamper, unauthorised access, and environmental attacks.

Artefacts an auditor will ask for
  • Tamper evidence design
  • Enclosure test reports
  • Access logs
Where this commonly fails
  • Tamper detection not active
  • Environmental thresholds undefined

Post-processing

23837-EC
Error Correction Parameters

Document error correction algorithm and parameters, including leaked information accounted for in privacy amplification.

Artefacts an auditor will ask for
  • Algorithm specification
  • Parameter tables
  • Leakage accounting
Where this commonly fails
  • Leakage underestimated
  • Parameters drift without re-evaluation
23837-PA
Privacy Amplification

Apply privacy amplification with hash families and output lengths consistent with the calculated information available to an adversary.

Artefacts an auditor will ask for
  • Hash family specification
  • Output length justification
  • Implementation tests
Where this commonly fails
  • Output length not tied to leakage estimate
  • Hash family weakly justified

Proof

23837-PROOF
Security Proof Mapping

Map the implementation parameters to the assumptions of the underlying security proof and identify deviations.

Artefacts an auditor will ask for
  • Proof reference
  • Parameter mapping document
  • Deviation register
Where this commonly fails
  • Deviations not assessed for impact
  • Proof citations missing

Randomness

23837-RNG
Random Number Generation

Verify random number generation used for basis choice and post-processing meets entropy and statistical requirements.

Artefacts an auditor will ask for
  • RNG design document
  • Entropy estimation
  • Test suite results
Where this commonly fails
  • Entropy source not characterised
  • Health tests not continuous

Requirements

23837-SFR
Security Functional Requirements

Capture the security functional requirements for physical-layer key distribution modules, including key generation, sifting, error correction, and privacy amplification.

Artefacts an auditor will ask for
  • Security functional requirements document
  • Traceability matrix
  • Design rationale
Where this commonly fails
  • Privacy amplification parameters not justified
  • Traceability gaps to design

SDLC

23837-DEV
Development Process Assurance

Apply a defined secure development process including configuration management, flaw remediation, and developer testing.

Artefacts an auditor will ask for
  • Development process documentation
  • Configuration management plan
  • Flaw remediation log
Where this commonly fails
  • Configuration baselines drift
  • Flaw remediation untimely

Scope

23837-TOE
Target of Evaluation Definition

Define the target of evaluation including the physical-layer key distribution modules, optical interfaces, and supporting classical control plane in scope.

Artefacts an auditor will ask for
  • TOE description
  • Architecture diagram
  • Interface inventory
Where this commonly fails
  • Control plane excluded from scope
  • Optical interfaces undocumented

Side-channels

23837-SIDE
Side-channel Resistance

Assess resistance to side-channel attacks including detector blinding, time-shift, wavelength, and trojan-horse attacks on this distribution method.

Artefacts an auditor will ask for
  • Side-channel assessment report
  • Countermeasure design
  • Test logs
Where this commonly fails
  • Trojan-horse countermeasure absent
  • Detector blinding not tested

Testing

23837-TEST
Test Methods and Evaluation

Use defined test methods to evaluate conformance of modules to the functional and assurance requirements.

Artefacts an auditor will ask for
  • Test plans
  • Test reports
  • Evaluator competence records
Where this commonly fails
  • Tests not repeatable
  • Evaluator independence not demonstrated

Vulnerability

23837-VULN
Vulnerability Analysis

Conduct independent vulnerability analysis focusing on optical, electronic, and protocol-level attacks against this distribution method.

Artefacts an auditor will ask for
  • Vulnerability analysis report
  • Attack catalogue
  • Residual risk register
Where this commonly fails
  • Analysis limited to documentation review
  • Residual risk not communicated to operators
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.