Blockchain Security Standards Council (BSSC) Standards
Industry-led security standards for blockchain infrastructure, published May 2025. Four complementary standards: Node Operation Standard (NOS) for blockchain node security and resilience, Token Integration Standard (TIS) for digital asset integration and governance, Key Management Standard (KMS) for cryptographic key handling and wallet custody, and General Security & Privacy Standard (GSP) for baseline risk management. Founded by Anchorage Digital, Coinbase, Kraken, Fireblocks, Halborn, and OpenZeppelin.
Clauses: 43
Avg Coverage: 71.7%
Publisher: Blockchain Security Standards Council (BSSC) Version: 1.0 (May 2025) | Clause | Title | SP 800-53 Controls |
|---|---|---|
| GSP-01 | Information Security Governance and Leadership | |
| GSP-02 | Risk Assessment and Management Framework | |
| GSP-03 | Security Awareness and Training | |
| GSP-04 | Personnel Security and Background Screening | |
| GSP-05 | Incident Detection, Response, and Reporting | |
| GSP-06 | Business Continuity and Operational Resilience | |
| GSP-07 | Third-Party and Supply Chain Risk Management | |
| GSP-08 | Vulnerability Disclosure and Bug Bounty | |
| GSP-09 | Data Protection and Privacy | |
| GSP-10 | Regulatory Compliance and AML/CFT Controls | |
| GSP-11 | Access Control and Identity Management | |
| GSP-12 | Logging, Audit, and Monitoring | |
| GSP-13 | Encryption and Data-in-Transit Protection | |
| GSP-14 | Change Management and Configuration Control | |
| GSP-15 | Penetration Testing and Security Assessments | |
| KMS-01 | Cryptographic Key Management Policy | |
| KMS-02 | Key Generation and Randomness | |
| KMS-03 | Hardware Security Module (HSM) and Secure Enclave Usage | |
| KMS-04 | Multi-Party Computation (MPC) and Threshold Signing | |
| KMS-05 | Cold Storage and Air-Gapped Key Custody | |
| KMS-06 | Key Access Control and Multi-Signature Authorisation | |
| KMS-07 | Key Rotation, Revocation, and Lifecycle Management | |
| KMS-08 | Block Proposal and Signing Security | |
| KMS-09 | Wallet Custody Architecture and Controls | |
| KMS-10 | Key Backup, Recovery, and Disaster Recovery | |
| NOS-01 | Node Infrastructure Governance and Policy | |
| NOS-02 | Node Software Integrity and Supply Chain | |
| NOS-03 | Consensus Client Configuration Hardening | |
| NOS-04 | Peer Network Security and Isolation | |
| NOS-05 | Node Access Control and Authentication | |
| NOS-06 | Node Monitoring and Anomaly Detection | |
| NOS-07 | Node Resilience, Backup, and Recovery | |
| NOS-08 | Validator Key Operational Security | |
| NOS-09 | Node Physical and Environmental Security | |
| NOS-10 | Node Vulnerability Management and Patching | |
| TIS-01 | Token Integration Governance and Risk Assessment | |
| TIS-02 | Smart Contract Security and Auditing | |
| TIS-03 | Token Standard Compliance and Configuration | |
| TIS-04 | Bridge and Cross-Chain Integration Security | |
| TIS-05 | Oracle Security and Price Feed Integrity | |
| TIS-06 | DeFi Protocol Integration Controls | |
| TIS-07 | Token Custody and Asset Segregation | |
| TIS-08 | Smart Contract Upgrade and Governance |