Standard: SIST EN ISO 19299:2020
Title: Electronic fee collection - Security framework (ISO 19299:2020)
Overview
SIST EN ISO 19299:2020 specifies an information security framework for Electronic Fee Collection (EFC) schemes. Based on the system architecture in ISO 17573-1, the standard defines security requirements and associated security measures for all organizational and technical entities in an EFC ecosystem - from toll chargers and toll service providers to back-end systems and roadside equipment. Annex D supplies a catalogue of potential threats to EFC systems and maps them to relevant security requirements to support threat analysis and control selection.
Keywords: Electronic fee collection, security framework, ISO 19299:2020, EFC security, toll systems, threat analysis.
Key technical topics and requirements
- Trust model and PKI: Defines stakeholder trust relations and certificate lifecycle (issuance, renewal, revocation), sub‑CA and end‑entity certificate handling and CRL use.
- Security requirements: Prescriptive controls for information security management systems (ISMS), data storage, communication interfaces, toll chargers (TC), toll service providers (TSP) and interoperability management.
- Communication interface security: Security measures for DSRC‑EFC, CCC, LAC, ICC and front-end/back-end interfaces; end‑to‑end protection and message integrity/authentication.
- Security measures and countermeasures: Implementation guidance for general security, interface-specific protections, RSE and OBE hardening, and operational controls.
- Key management: Guidance for asymmetric and symmetric key generation, exchange, lifecycle, storage and session key handling.
- Conformance and documentation: Security profiles (Annex A), Implementation Conformance Statement (ICS) proforma (Annex B) and example security/policy templates (Annexes E–F).
- Privacy guidance: Annex G provides recommendations for privacy-focused implementations in EFC deployments.
- Threat analysis support: Annex D lists threats and links them to security requirements to help prioritize measures.
Practical applications - who uses this standard
- Toll operators and toll service providers (TSPs) designing or operating interoperable EFC systems.
- System integrators and vendors implementing roadside equipment (RSE), on‑board equipment (OBE/ICC) and secure back ends.
- Security architects and ISMS teams assessing risks, defining PKI and key management, and implementing countermeasures.
- Regulators, interoperability managers and auditors evaluating conformance, safety and privacy controls across multi‑stakeholder EFC schemes.
- Project managers using the ICS proforma and security profiles to document compliance and vendor requirements.
Related standards
This standard is essential for securing tolling and electronic fee collection deployments, enabling interoperable, resilient and privacy-aware EFC operations.