Software Risk Assessment for Measuring Instruments in Legal Metrology
Оценка рисков программного обеспечения для средств измерений в законодательной метрологии
2015-10-11
SCID: 54.1/gpc8r4q6
Discuss with AI
ISO/IEC 15408ISO/IEC 27005legal metrologymeasuring instrumentssoftware risk assessment
Figures from the paper
Abstract (AI)
In Europe, measuring instruments subject to legal control are responsible for an annual turnover of 500 billion Euros and need to pass a conformity assessment with respect to European directives or national legislation before they can be used.Today, measuring instruments are frequently integrated into open networks and even branch into the areas of cloud computing and Internet of Things.Since software is one of the key components of such devices, Germany's national metrology institute, the Physikalisch-Technische Bundesantalt, is developing a method to assess the risks and evaluate current threats associated with software.The method uses the structure of and combines elements from the international ISO/IEC standards 27005 and 15408.It could be helpful for conformity assessment bodies and industry alike and supports the comparability of risk assessment results.Despite its focus on legal metrology, the method is applicable to other areas where software risk assessment is required, too.
Key Findings
1
Germany’s national metrology institute is developing a software risk-assessment method for identifying risks and evaluating current threats in measuring instruments.
2
Legal-controlled measuring instruments generate approximately €500 billion in annual European turnover and must undergo conformity assessment before use.
3
The approach is intended to improve comparability of risk-assessment results and assist both conformity-assessment bodies and industry, with applicability beyond legal metrology.
4
The increasing integration of measuring instruments with open networks, cloud computing, and the Internet of Things creates new software-related security risks.
5
The method combines structural elements from ISO/IEC 27005 and ISO/IEC 15408 to support systematic software risk assessment.
Research Object
Software in measuring instruments subject to legal metrology control
Research Subject
Software-related risks and current threats, assessed for conformity and comparability in legal metrology
Publication Details
Publication Date
2015-10-11
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest