← Frameworks / Digital Asset Security

Blockchain Security Standards Council (BSSC) Standards

Industry-led security standards for blockchain infrastructure, published May 2025. Four complementary standards: Node Operation Standard (NOS) for blockchain node security and resilience, Token Integration Standard (TIS) for digital asset integration and governance, Key Management Standard (KMS) for cryptographic key handling and wallet custody, and General Security & Privacy Standard (GSP) for baseline risk management. Founded by Anchorage Digital, Coinbase, Kraken, Fireblocks, Halborn, and OpenZeppelin.

Clause Title SP 800-53 Controls
GSP-01 Information Security Governance and Leadership
GSP-02 Risk Assessment and Management Framework
GSP-03 Security Awareness and Training
GSP-04 Personnel Security and Background Screening
GSP-05 Incident Detection, Response, and Reporting
GSP-06 Business Continuity and Operational Resilience
GSP-07 Third-Party and Supply Chain Risk Management
GSP-08 Vulnerability Disclosure and Bug Bounty
GSP-09 Data Protection and Privacy
GSP-10 Regulatory Compliance and AML/CFT Controls
GSP-11 Access Control and Identity Management
GSP-12 Logging, Audit, and Monitoring
GSP-13 Encryption and Data-in-Transit Protection
GSP-14 Change Management and Configuration Control
GSP-15 Penetration Testing and Security Assessments
KMS-01 Cryptographic Key Management Policy
KMS-02 Key Generation and Randomness
KMS-03 Hardware Security Module (HSM) and Secure Enclave Usage
KMS-04 Multi-Party Computation (MPC) and Threshold Signing
KMS-05 Cold Storage and Air-Gapped Key Custody
KMS-06 Key Access Control and Multi-Signature Authorisation
KMS-07 Key Rotation, Revocation, and Lifecycle Management
KMS-08 Block Proposal and Signing Security
KMS-09 Wallet Custody Architecture and Controls
KMS-10 Key Backup, Recovery, and Disaster Recovery
NOS-01 Node Infrastructure Governance and Policy
NOS-02 Node Software Integrity and Supply Chain
NOS-03 Consensus Client Configuration Hardening
NOS-04 Peer Network Security and Isolation
NOS-05 Node Access Control and Authentication
NOS-06 Node Monitoring and Anomaly Detection
NOS-07 Node Resilience, Backup, and Recovery
NOS-08 Validator Key Operational Security
NOS-09 Node Physical and Environmental Security
NOS-10 Node Vulnerability Management and Patching
TIS-01 Token Integration Governance and Risk Assessment
TIS-02 Smart Contract Security and Auditing
TIS-03 Token Standard Compliance and Configuration
TIS-04 Bridge and Cross-Chain Integration Security
TIS-05 Oracle Security and Price Feed Integrity
TIS-06 DeFi Protocol Integration Controls
TIS-07 Token Custody and Asset Segregation
TIS-08 Smart Contract Upgrade and Governance