ISO-19299 Historical Revision Information
Electronic fee collection - Security framework

ISO-19299 - 1ST EDITION - SUPERSEDED
Show Complete Document History

Document Center Inc. is an authorized dealer of ISO standards.
The following bibliographic material is provided to assist you with your purchasing decision:


The overall scope of ISO/TS 19299:2015 is an information security framework for all organizational and technical entities of an EFC scheme and in detail for the interfaces between them, based on the system architecture defined in ISO 17573. The security framework describes a set of requirements and associated security measures for stakeholders to implement and thus ensure a secure operation of their part of an EFC system as required for a trustworthy environment according to its security policy.

The scope of ISO/TS 19299:2015 comprises the following:

  • definition of a trust model;

Basic assumptions and principles for establishing trust between the stakeholders.

  • security requirements;
  • security measures - countermeasures;

Security requirements to support actual EFC system implementations.

  • security specifications for interface implementation;

These specifications represent an add-on for security to the corresponding standards.

  • key management;

Covering the (initial) setup of key exchange between stakeholders and several operational procedures like key renewal, certificate revocation, etc.

  • security profiles;
  • implementation conformance statement provides a checklist to be used by an equipment supplier, a system implementation, or an actor of a role declaring his conformity to ISO/TS 19299:2015;
  • general information security objectives of the stakeholders which provide a basic motivation for the security requirements;
  • threat analysis on the EFC system model and its assets using two different complementary methods, an attack-based analysis, and an asset-based analysis;
  • security policy examples;
  • recommendations for privacy-focused implementation;
  • proposal for end-entity certificates.
ORDER

To find similar documents by classification:

03.220.20 (Road transport Including road transport services Road traffic control equipment and installations, see 93.080.30)

35.240.60 (IT applications in transport and trade Including EDIFACT and e-commerce)

This document comes with our free Notification Service, good for the life of the document.

This document is available in either Paper or PDF format.

Document Number

ISO/TS 19299:2015

Revision Level

1ST EDITION

Status

Superseded

Publication Date

Oct. 1, 2015

Committee Number

ISO/TC 204