Blockchain Security Standards Council (BSSC) Standards
Industry-led security standards for blockchain infrastructure, published May 2025. Four complementary standards: Node Operation Standard (NOS) for blockchain node security and resilience, Token Integration Standard (TIS) for digital asset integration and governance, Key Management Standard (KMS) for cryptographic key handling and wallet custody, and General Security & Privacy Standard (GSP) for baseline risk management. Founded by Anchorage Digital, Coinbase, Kraken, Fireblocks, Halborn, and OpenZeppelin.
Controls: 105
Total Mappings: 226
Publisher: Blockchain Security Standards Council (BSSC) Version: 1.0 (May 2025) AC (7) AT (4) AU (8) CA (6) CM (9) CP (8) IA (4) IR (6) MP (3) PE (6) PL (2) PM (3) PS (5) PT (4) RA (5) SA (5) SC (10) SI (4) SR (6)
AC Access Control
| Control | Name | BSSC Standards References |
|---|---|---|
| AC-01 | Policy and Procedures | GSP-11 |
| AC-02 | Account Management | GSP-11KMS-06NOS-05 |
| AC-03 | Access Enforcement | GSP-11KMS-06KMS-09NOS-05TIS-07 |
| AC-04 | Information Flow Enforcement | NOS-04TIS-04 |
| AC-05 | Separation of Duties | GSP-11KMS-04KMS-06 |
| AC-06 | Least Privilege | GSP-11KMS-04KMS-05KMS-06KMS-09NOS-05NOS-08TIS-07 |
| AC-17 | Remote Access | NOS-05 |
AT Awareness and Training
AU Audit and Accountability
| Control | Name | BSSC Standards References |
|---|---|---|
| AU-01 | Policy and Procedures | GSP-12 |
| AU-02 | Event Logging | GSP-10GSP-12NOS-06 |
| AU-03 | Content of Audit Records | GSP-12 |
| AU-06 | Audit Record Review, Analysis, and Reporting | GSP-12NOS-06 |
| AU-09 | Protection of Audit Information | GSP-12KMS-09TIS-07 |
| AU-10 | Non-repudiation | KMS-08TIS-05 |
| AU-11 | Audit Record Retention | GSP-12 |
| AU-12 | Audit Record Generation | NOS-06 |
CA Security Assessment and Authorization
| Control | Name | BSSC Standards References |
|---|---|---|
| CA-01 | Policy and Procedures | GSP-10KMS-01NOS-01TIS-01 |
| CA-02 | Control Assessments | GSP-10GSP-15TIS-02TIS-06 |
| CA-05 | Plan of Action and Milestones | KMS-07 |
| CA-06 | Authorization | GSP-01TIS-08 |
| CA-07 | Continuous Monitoring | GSP-15NOS-10 |
| CA-08 | Penetration Testing | GSP-08GSP-15TIS-02 |
CM Configuration Management
| Control | Name | BSSC Standards References |
|---|---|---|
| CM-01 | Policy and Procedures | GSP-14 |
| CM-02 | Baseline Configuration | GSP-14NOS-03 |
| CM-03 | Configuration Change Control | GSP-14KMS-07NOS-10TIS-08 |
| CM-04 | Impact Analyses | NOS-10 |
| CM-05 | Access Restrictions for Change | GSP-14TIS-08 |
| CM-06 | Configuration Settings | GSP-14NOS-03TIS-03 |
| CM-07 | Least Functionality | NOS-03TIS-03 |
| CM-08 | System Component Inventory | GSP-14NOS-03 |
| CM-14 | Signed Components | NOS-02 |
CP Contingency Planning
| Control | Name | BSSC Standards References |
|---|---|---|
| CP-01 | Policy and Procedures | GSP-06 |
| CP-02 | Contingency Plan | GSP-06NOS-07 |
| CP-04 | Contingency Plan Testing | GSP-06 |
| CP-07 | Alternate Processing Site | NOS-07 |
| CP-08 | Telecommunications Services | NOS-07 |
| CP-09 | System Backup | GSP-06KMS-10NOS-07 |
| CP-10 | System Recovery and Reconstitution | GSP-06KMS-10NOS-07 |
| CP-11 | Alternate Communications Protocols | GSP-06 |
IA Identification and Authentication
IR Incident Response
MP Media Protection
PE Physical and Environmental Protection
PL Planning
PM Program Management
PS Personnel Security
PT Personally Identifiable Information Processing and Transparency
RA Risk Assessment
SA System and Services Acquisition
| Control | Name | BSSC Standards References |
|---|---|---|
| SA-04 | Acquisition Process | GSP-07KMS-03TIS-03TIS-06 |
| SA-08 | Security and Privacy Engineering Principles | KMS-02TIS-03 |
| SA-09 | External System Services | GSP-07 |
| SA-10 | Developer Configuration Management | NOS-02TIS-08 |
| SA-11 | Developer Testing and Evaluation | GSP-08GSP-15NOS-02TIS-02TIS-04 |
SC System and Communications Protection
| Control | Name | BSSC Standards References |
|---|---|---|
| SC-05 | Denial-of-service Protection | NOS-04 |
| SC-07 | Boundary Protection | NOS-04TIS-04 |
| SC-08 | Transmission Confidentiality and Integrity | GSP-13NOS-04TIS-05 |
| SC-12 | Cryptographic Key Establishment and Management | GSP-13KMS-01KMS-02KMS-03KMS-04KMS-05KMS-07KMS-08KMS-09KMS-10NOS-08TIS-07 |
| SC-13 | Cryptographic Protection | GSP-13KMS-01KMS-02KMS-03KMS-08NOS-08 |
| SC-17 | Public Key Infrastructure Certificates | KMS-01 |
| SC-20 | Secure Name/Address Resolution Service (Authoritative Source) | NOS-04 |
| SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | NOS-04 |
| SC-23 | Session Authenticity | GSP-13 |
| SC-28 | Protection of Information at Rest | GSP-09GSP-13 |
SI System and Information Integrity
SR Supply Chain Risk Management
| Control | Name | BSSC Standards References |
|---|---|---|
| SR-01 | Policy and Procedures | GSP-07 |
| SR-02 | Supply Chain Risk Management Plan | GSP-07 |
| SR-03 | Supply Chain Controls and Processes | GSP-07NOS-02 |
| SR-04 | Provenance | NOS-02 |
| SR-05 | Acquisition Strategies, Tools, and Methods | GSP-07TIS-06 |
| SR-06 | Supplier Assessments and Reviews | TIS-02 |