Standards & assuranceStandards with scope.
Standards with scope.
Claims with a basis.
Reference, implementation, evaluation and certification are different states.
Standards matrix
External sources are linked explicitly. Product capability is not inferred from a standard name.
| Standard / framework | Scope | Publication status | Limitations & evidence |
|---|---|---|---|
| ISO/IEC 27001:2022 ↗ | Information security management | Published organizational certificate | SIS351224I008; printed expiry: 04 Dec 2027. Current surveillance status requires verification. |
| ISO/IEC 24745:2022 ↗ | Biometric information protection | Reference standard | Design mapping: domain separation, identity binding and template lifecycle. No product assessment report supplied. |
| ISO/IEC 30107-3:2023 ↗ | PAD testing & reporting | Evaluation method | Reports must identify device, algorithm and attack scope. No L2/L3 level is inferred. |
| ISO/IEC 19795-1:2021 ↗ | Biometric performance testing | Evaluation method | Results depend on the test set, threshold, gallery and environment. |
| ISO/IEC 27017 ↗ | Cloud security controls | Assess when applicable | Assess against the cloud deployment and contract; no certification claim. |
| ISO/IEC 27018 ↗ | Cloud personal information protection | Assess when applicable | Identify processor roles, data location and subprocessors. |
| OWASP API Security Top 10 - 2023 ↗ | API security risks | Reference framework | Object authorization, resource limits and API inventory. |
| NIST CSF 2.0 ↗ | Cybersecurity risk governance | Reference framework | Map governance and operational outcomes; not a product certification. |
| 91/2025/QH15 ↗ | Personal Data Protection Law | Vietnam legal framework | Effective 01 Jan 2026. Apply according to roles and processing activities. |
| 356/2025/ND-CP ↗ | Implementing decree | Vietnam legal framework | Effective 01 Jan 2026. Deployment policies require legal review. |