• No results found

4. State of the art in security standards in different sectors

4.1. Work of European standardisation organisations

4.1.2. Analysis of different standardisation organisations and their security-related

4.1.2.1. European Committee for Standardisation (CEN)

Of the three ESOs, CEN153 is responsible for ENs in all the technical sectors except for the electrotechnical and the telecommunications sectors.154

The main bodies of the CEN, governed by the General Assembly (GA), responsible for the conception of standards are the Technical Committees (TCs) and the Subcommittees (SCs), within which specific Working Groups (WGs) related to clearly defined subjects create the draft standards that are reported to the either the TC or the SC. Overviewing the TCs is the Technical Board (BT), controlling the standards programmes, approving CEN policies and strategies, takes decisions on standardisation issues and organises cooperation with

153See CEN, no date. http://www.cen.eu/Pages/default.aspx

154 See CEN, no date, http://www.cen.eu/about/Pages/default.aspx for a detailed decription of the fields in which CEN is active.

tional and/or intergovernmental organisations.155 Another important body is the Project Committee (PC), seen as a technical body with the aim of creating “a specific short time standardisation task within a given target date”156 and disbanded after completing the task.

Finally, Workshops (WS) which can be developed fast are important for the development of standards and specifications in rapidly-changing fields of technology.

In the next sections, the most important technical bodies in the field of security standards will be presented, including an overview of the related standards – where available – that have been developed or are currently being developed.

Mandate M/487 led to a report of the security landscape in 2012 in which the European TCs in relevant security areas were identified. The scope was broad to also include the safety as-pect and fire safety/fighting in general. This inclusion led to a relevance-classification of the TCs, ranging from low relevance to high relevance in the security context. For our analysis, selected TCs with high relevance in the security standardisation were selected as examples.

They are presented in Figure 20.

CEN TC Standardisation for

Aims at the development of a single standard

 Focus: specifying “general requirements for services in fire safety systems and/or general security systems, especially in regard to the planning, design, installation, commissioning, verification, handover or maintenance”157 of such systems

CEN/

TC 164

 Security of drink-ing water supply

 Has established a large amount of the standards

 A few standards address security issues, e.g.:

• EN 15975-1:2011, Security of drinking water supply - Guidelines for risk and crisis management - Part 1: Crisis management and

• EN 15975-2:2013, Security of drinking water supply - Guidelines for risk and crisis management - Part 2: Risk management158

155 See European Committee for Standardisation, “Technical Board”, 28 August 2014, http://boss.cen.eu/TechnicalStructures/Pages/BT.aspx

156 See European Committee for Standardisation, “Project Committee”, 28 August 2014, http://boss.cen.eu/TechnicalStructures/Pages/ProjCmte.aspx

157See Website of the Technical Committee:

http://www.iso.org/iso/home/standards_development/list_of_iso_technical_committees.htm

158 See European Commission, DG Enterprise and Industry, Security Research and Development, Mandate M/487 to Estab-lish Security Standards, Final Report Phase 1 Analysis of the Current Security Landscape, 2012, Annexe C;

http://standards.cen.eu/dyn/www/f?p=204:110:0::::FSP_PROJECT:30474&cs=1DC596AC378112DEAA73B0BD03D2B377 B and

http://standards.cen.eu/dyn/www/f?p=204:110:0::::FSP_PROJECT:34082&cs=1AA89C0488D68938C415AF7F162C579F4

(figure continues)

CEN/

 The aim is to create standards for user interface or human-machine interface in application like banking, retail, passenger transport and borders.

 Security standards issued: EN 1332 Identification card system, EN 1332-1:2009: Identification card system – Man-Machine Interface, EN 14890-1:2008 – Application Interface for smart cards used as Secure Signature Creation Devices

 A definition of critical infrastructure provides European Commission (2004)159

CEN/

TC 251

 Medical security  Mainly responsible for the creation of ICT standards in medical, social care and welfare settings

CEN/

 Published several standards relating to protective measures in regard to the storage of cash and other valuables towards fire prevention and the prevention of burglaries buildings, applying the following, particularly in an urban setting161:

• Different strategies, security levels; and

• Building and area layout, etc.

159 European Commission, Critical Infrastructure Protection in the fight against terrorism (COM/2004/0702), 2004, http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2004:0702:FIN:EN:PDF.

160 An overview of those standards can be found here:

http://standards.cen.eu/dyn/www/f?p=204:32:0::::FSP_ORG_ID,FSP_LANG_ID:6244,25&cs=1F7BB1CF3AE29C75644A2 8F3E97469504

161 See CEN, CEN/TC 325 – Crime prevention through building, facility and area design, CEN/TC 325 Scope, 2014.

http://standards.cen.eu/dyn/www/f?p=204:7:0::::FSP_ORG_ID:6306&cs=133518429ECB0D4DDB06C8583A7A5CD0D

(figure continues)

CEN/

Standard EN 16352:2013 Logistics – Specifications for reporting crime incidents created common rules for the data collection and processing within the reporting of crimes, unrelated to the origin of the reporter or data collector162

 Relates closely to the functions ‘information collection, storage and management to produce intelligence’ as well as ‘prevention’ in CRISP’s

 Aims at the standardisation of security products and systems for perimeter protection

 Focusses only onterrains surrounding buildings, but not on systems within the buildings.

 Focuses on border security as well as the protection of critical infrastructure limits

 A TR has been created, which provides information for the design of perimeter protection standards164

 TC is not active at the moment Vulnerability Assessment and Protection of People at Risk

 Focus of the TS: security risks in the field of CBRN Incidents with potential large scale effects

 Consists mainly of tools for the development of vulnerability assessment, awareness and management165

 Work correlates with the functions described in the glossary of security products, systems and services in CRISP’s Deliverable 1.1, not only regarding pre-vention, but also regarding the assessment of a secu-rity issue and the creation of situational awareness166 CEN/

TC 417

 Security for mari-time and port set-ting

 Focuses on quality standards for security services in that field

 One standard is currently under enquiry CEN/

TC 419

 Forensic science processes

 No standards output yet.

 Focus on all steps scene of the crime, the transporta-tion and storage of material, interpretatransporta-tion of the re-sults

Source: Own figure

Figure 20: Overview of the work of selected CEN TCs in the security field

162 See also EN 16352:2013 Logistics – Specifications for reporting crime incidents, p. 12.

163 See D1.1 Glossary of security products and systems 164 See CEN, op. cit., 2014

165 See CEN, op. cit., 2014 166 See CRISP D1.1

The work of the committees will be analysed in more detail in Chapter 4.3.

As shown on the basis of its TCs, CEN provides a large amount of European standards amongst the different security areas and is to be regarded as the main ESO responsible for security ENs.