ISO 27566 Clause 5.4 - Security Characteristics
Ensure age assurance systems resist fraud, presentation attacks, and credential misuse with encryption, integrity protections, audit logging, and regular security testing
Where this comes from
Provision: Clause 5.4 - Security Characteristics
Instrument: ISO/IEC 27566-1:2025
Citation: ISO/IEC 27566-1:2025, Age assurance systems -- Framework, Clause 5.4: Security Characteristics
Text version: ISO/IEC 27566-1:2025
Who it applies to
…unless:
- Age verification method: No age verification
What engineering work it implies
- Role-Based Access Control for Child SafetyCovers part of it
Implement granular access controls with age-appropriate feature gating and moderation workflows.
Sample acceptance criteria Landfall generates for this obligation:
- Personal data is encrypted in transit and at rest
- Access to personal data is role-restricted and access is logged
- A documented incident-response / breach-notification procedure exists and is tested
- Third-party processors are bound by equivalent security obligations
- Key rotation completes without loss of access to data encrypted under the prior key
Questions people ask
- From when does this apply?
- ISO 27566 Clause 5.4 - Security Characteristics applies from 15 January 2025. Its current status is: in force.
- What engineering work does this imply?
- Typically: Role-Based Access Control for Child Safety.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.