Formalization of Software Risk Assessment Results in Legal Metrology Based on ISO/IEC 18045 Vulnerability Analysis

The Measuring Instruments Directive sets down essential requirements for measuring instruments subject to legal control in the EU. It dictates that a risk assessment must be performed before such instruments are put on the market. Because of the increasing importance of software in measuring instrum...

Full description

Saved in:
Bibliographic Details
Published inAnnals of Computer Science and Information Systems Vol. 18; pp. 443 - 447
Main Authors Esche, Marko, Salwiczek, Felix, Toro, Federico Grasso
Format Conference Proceeding Journal Article
LanguageEnglish
Published Polish Information Processing Society -- as since 2011 01.09.2019
Polish Information Processing Society
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:The Measuring Instruments Directive sets down essential requirements for measuring instruments subject to legal control in the EU. It dictates that a risk assessment must be performed before such instruments are put on the market. Because of the increasing importance of software in measuring instruments, a specifically tailored software risk assessment method has been previously developed and published. Related research has been done on graphical representation of threats by attack probability trees. The final stage is to formalize the method to prove its reproducibility and resilience against the complexity of future instruments. To this end, an inter-institutional comparison of the method is currently being conducted across national metrology institutes, while the weighing equipment manufacturers' association CECIP has provided a new measuring instrument concept, as a significant example of complex instruments. Based on the results of the comparison, a template to formalize the software risk assessment method is proposed here.
ISSN:2300-5963
DOI:10.15439/2019F84