What is ISO 19299 - Electronic fee collection about?
ISO 19299 defines an information security framework for all organizational and technical entities of an EFC scheme and for the related interfaces, based on the system architecture defined in ISO 17573-1.
The security framework describes a set of security requirements and associated security measures.
ISO 19299 contains a list of potential threats to EFC systems and a possible relation to the defined security requirements. These threats can be used for a threat analysis to identify the relevant security requirements for an EFC system.
The relevant security measures to secure EFC systems can then be derived from the identified security requirements.
Each actor in an existing EFC system implements the defined security measures and supervises their effectiveness. When a security measure is found not working properly, an improvement process is started. The development of the EFC security framework follows this approach, with the following limitations:
- No standard security policy exists, nor can it be defined: The security policy can only be defined by the responsible stakeholders and it is limited by laws and regulations.
- No standard risk assessment is possible: Risk assessment compares possible losses to stakeholders with the required resources (e.g. equipment, knowledge, time) to perform an attack. In a real system, risk assessment is based on the evaluation of the costs and benefits of each countermeasure.
- No specific system design or configuration was deemed as universally applicable. Only the available EFC base standards were taken as references. Specific technical details of a particular system need to be additionally taken into consideration when implementing security measures.
Who is ISO 19299 - Electronic fee collection for?
ISO 19299 on electronic fee collection is useful for:
- Toll plaza on highways
- Paid Parking zones
- Electronic fee collection device manufacturer
Why should you use ISO 19299 - Electronic fee collection?
The development process for a security concept and implementation to protect any existing electronic fee collection (EFC) system normally includes several steps as follows using ISO 19299:
- Definition of the security objectives and policy statements in a security policy
- Threat analysis with a risk assessment to define the security requirements
- Development of the security measures followed by the development of security test specifications
This guidance is very useful for the manufacturers and users of electronic fee systems.
What’s changed since the last update?
BS EN ISO 19299:2020 supersedes PD CEN ISO/TS 19299:2015. BS EN ISO 19299:2020 includes some technical changes with respect to PD CEN ISO/TS 19299:2015. These include:
- Added requirements and security measures for the use of common payment media according to ISO/TS 21193
- Updated data protection considerations in Annex G, in order to take into account, the European Union’s new General Data Protection Regulation (i.e., Directive 2016/679/EC).