EN ISO 19299:2020 PDF
Electronic fee collection - Security framework (ISO 19299:2020)
Electronic fee collection - Security framework (ISO 19299:2020)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 144
- Дата публикации:
- 9 сентября 2020 г.
- Издание:
- CEN EN 19299 edition 2 version 1
- ICS:
- 03.220.20
This document defines an information security framework for all organizational and technical entities of an EFC scheme and for the related interfaces, based on the system architecture defined in ISO 17573-1. The security framework describes a set of security requirements and associated security measures. Annex D contains a list of potential threats to EFC systems and a possible relation to the defined security requirements. These threats can be used for a threat analysis to identify the relevant security requirements for an EFC system. The relevant security measures to secure EFC systems can then be derived from the identified security requirements.
Abstract
Standard: EN ISO 19299:2020 Title: Electronic fee collection - Security framework (ISO 19299:2020)
Overview
EN ISO 19299:2020 specifies an information security framework for Electronic Fee Collection (EFC) schemes. Based on the system architecture in ISO 17573-1, the standard defines security requirements and associated security measures for all organizational and technical entities in an EFC ecosystem - from toll chargers and toll service providers to back-end systems and roadside equipment. Annex D supplies a catalogue of potential threats to EFC systems and maps them to relevant security requirements to support threat analysis and control selection.
Keywords: Electronic fee collection, security framework, ISO 19299:2020, EFC security, toll systems, threat analysis.
Key technical topics and requirements
- Trust model and PKI: Defines stakeholder trust relations and certificate lifecycle (issuance, renewal, revocation), sub‑CA and end‑entity certificate handling and CRL use.
- Security requirements: Prescriptive controls for information security management systems (ISMS), data storage, communication interfaces, toll chargers (TC), toll service providers (TSP) and interoperability management.
- Communication interface security: Security measures for DSRC‑EFC, CCC, LAC, ICC and front-end/back-end interfaces; end‑to‑end protection and message integrity/authentication.
- Security measures and countermeasures: Implementation guidance for general security, interface-specific protections, RSE and OBE hardening, and operational controls.
- Key management: Guidance for asymmetric and symmetric key generation, exchange, lifecycle, storage and session key handling.
- Conformance and documentation: Security profiles (Annex A), Implementation Conformance Statement (ICS) proforma (Annex B) and example security/policy templates (Annexes E–F).
- Privacy guidance: Annex G provides recommendations for privacy-focused implementations in EFC deployments.
- Threat analysis support: Annex D lists threats and links them to security requirements to help prioritize measures.
Practical applications - who uses this standard
- Toll operators and toll service providers (TSPs) designing or operating interoperable EFC systems.
- System integrators and vendors implementing roadside equipment (RSE), on‑board equipment (OBE/ICC) and secure back ends.
- Security architects and ISMS teams assessing risks, defining PKI and key management, and implementing countermeasures.
- Regulators, interoperability managers and auditors evaluating conformance, safety and privacy controls across multi‑stakeholder EFC schemes.
- Project managers using the ICS proforma and security profiles to document compliance and vendor requirements.
Related standards
- ISO 17573-1 (EFC system architecture) - used as the architectural basis for ISO 19299:2020.
- CEN/CENELEC adoption: EN ISO 19299:2020 (identical text for European implementation).
This standard is essential for securing tolling and electronic fee collection deployments, enabling interoperable, resilient and privacy-aware EFC operations.
Технические детали
- Технический комитет
- CEN/TC 278 - Road transport and traffic telematics
- SKU
- EN ISO 19299:2020
Похожие стандарты
Упомянутые в описании и другие стандарты EN
ISO 19299:2020
ДействующийElectronic fee collection — Security framework
Overview ISO 19299:2020 - Electronic fee collection - Security framework defines an information security framework for Electronic Fee Collection (EFC) systems. Based on the system architecture in ISO…
SIST EN ISO 17573-1:2019
ДействующийElectronic fee collection - System architecture for vehicle related tolling - Part 1: Reference model (ISO 17…
Overview EN ISO 17573-1:2019 - "Electronic fee collection - System architecture for vehicle-related tolling - Part 1: Reference model" defines a high-level architecture and common language for electr…
EN ISO 6599-1:2026
ДействующийPackaging - Conditioning for testing - Part 1: Paper sacks (ISO 6599-1:2026)
Overview EN ISO 6599-1:2026 - Packaging - Conditioning for testing - Part 1: Paper sacks is a key international standard developed by CEN and ISO. This document defines the conditioning atmospheres a…
EN ISO 4885:2026
ДействующийFerrous materials - Heat treatments - Vocabulary (ISO 4885:2026)
Overview EN ISO 4885:2026 - Ferrous Materials – Heat Treatments – Vocabulary is an international standard developed by CEN, aligning with ISO 4885:2026. This document provides comprehensive definitio…
EN ISO/IEC 29151:2026
ДействующийInformation security, cybersecurity and privacy protection - Controls, requirements, and guidance for persona…
Overview EN ISO/IEC 29151:2026 specifies controls, requirements, and guidance to ensure the proper protection of personally identifiable information (PII) within the fields of information security, c…
EN ISO 9693:2026
ДействующийDentistry - Compatibility testing for metal-ceramic and ceramic-ceramic systems (ISO 9693:2026)
Overview EN ISO 9693:2026 - Dentistry: Compatibility Testing for Metal-Ceramic and Ceramic-Ceramic Systems establishes internationally recognized requirements and test methods for evaluating the ther…
EN ISO 26082-1:2026
ДействующийLeather - Physical and mechanical test methods for the determination of soiling - Part 1: Rubbing (Martindale…
Overview EN ISO 26082-1:2026 is a European standard titled "Leather - Physical and mechanical test methods for the determination of soiling - Part 1: Rubbing (Martindale) method" adopted by CEN. This…
EN ISO/IEEE 11073-10101:2020/A1:2026
ДействующийHealth informatics - Device interoperability - Part 10101: Point-of-care medical device communication - Nomen…
Overview EN ISO/IEEE 11073-10101:2020/A1:2026 is an amendment to the internationally recognized standard for health informatics and device interoperability, focusing specifically on the nomenclature…