4. State of the art in security standards in different sectors
4.1. Work of European standardisation organisations
4.1.2. Analysis of different standardisation organisations and their security-related
4.1.2.1. European Committee for Standardisation (CEN)
Of the three ESOs, CEN153 is responsible for ENs in all the technical sectors except for the electrotechnical and the telecommunications sectors.154
The main bodies of the CEN, governed by the General Assembly (GA), responsible for the conception of standards are the Technical Committees (TCs) and the Subcommittees (SCs), within which specific Working Groups (WGs) related to clearly defined subjects create the draft standards that are reported to the either the TC or the SC. Overviewing the TCs is the Technical Board (BT), controlling the standards programmes, approving CEN policies and strategies, takes decisions on standardisation issues and organises cooperation with
153See CEN, no date. http://www.cen.eu/Pages/default.aspx
154 See CEN, no date, http://www.cen.eu/about/Pages/default.aspx for a detailed decription of the fields in which CEN is active.
tional and/or intergovernmental organisations.155 Another important body is the Project Committee (PC), seen as a technical body with the aim of creating “a specific short time standardisation task within a given target date”156 and disbanded after completing the task.
Finally, Workshops (WS) which can be developed fast are important for the development of standards and specifications in rapidly-changing fields of technology.
In the next sections, the most important technical bodies in the field of security standards will be presented, including an overview of the related standards – where available – that have been developed or are currently being developed.
Mandate M/487 led to a report of the security landscape in 2012 in which the European TCs in relevant security areas were identified. The scope was broad to also include the safety as-pect and fire safety/fighting in general. This inclusion led to a relevance-classification of the TCs, ranging from low relevance to high relevance in the security context. For our analysis, selected TCs with high relevance in the security standardisation were selected as examples.
They are presented in Figure 20.
CEN TC Standardisation for
Aims at the development of a single standard
Focus: specifying “general requirements for services in fire safety systems and/or general security systems, especially in regard to the planning, design, installation, commissioning, verification, handover or maintenance”157 of such systems
CEN/
TC 164
Security of drink-ing water supply
Has established a large amount of the standards
A few standards address security issues, e.g.:
• EN 15975-1:2011, Security of drinking water supply - Guidelines for risk and crisis management - Part 1: Crisis management and
• EN 15975-2:2013, Security of drinking water supply - Guidelines for risk and crisis management - Part 2: Risk management158
155 See European Committee for Standardisation, “Technical Board”, 28 August 2014, http://boss.cen.eu/TechnicalStructures/Pages/BT.aspx
156 See European Committee for Standardisation, “Project Committee”, 28 August 2014, http://boss.cen.eu/TechnicalStructures/Pages/ProjCmte.aspx
157See Website of the Technical Committee:
http://www.iso.org/iso/home/standards_development/list_of_iso_technical_committees.htm
158 See European Commission, DG Enterprise and Industry, Security Research and Development, Mandate M/487 to Estab-lish Security Standards, Final Report Phase 1 Analysis of the Current Security Landscape, 2012, Annexe C;
http://standards.cen.eu/dyn/www/f?p=204:110:0::::FSP_PROJECT:30474&cs=1DC596AC378112DEAA73B0BD03D2B377 B and
http://standards.cen.eu/dyn/www/f?p=204:110:0::::FSP_PROJECT:34082&cs=1AA89C0488D68938C415AF7F162C579F4
(figure continues)
CEN/
The aim is to create standards for user interface or human-machine interface in application like banking, retail, passenger transport and borders.
Security standards issued: EN 1332 Identification card system, EN 1332-1:2009: Identification card system – Man-Machine Interface, EN 14890-1:2008 – Application Interface for smart cards used as Secure Signature Creation Devices
A definition of critical infrastructure provides European Commission (2004)159
CEN/
TC 251
Medical security Mainly responsible for the creation of ICT standards in medical, social care and welfare settings
CEN/
Published several standards relating to protective measures in regard to the storage of cash and other valuables towards fire prevention and the prevention of burglaries buildings, applying the following, particularly in an urban setting161:
• Different strategies, security levels; and
• Building and area layout, etc.
159 European Commission, Critical Infrastructure Protection in the fight against terrorism (COM/2004/0702), 2004, http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2004:0702:FIN:EN:PDF.
160 An overview of those standards can be found here:
http://standards.cen.eu/dyn/www/f?p=204:32:0::::FSP_ORG_ID,FSP_LANG_ID:6244,25&cs=1F7BB1CF3AE29C75644A2 8F3E97469504
161 See CEN, CEN/TC 325 – Crime prevention through building, facility and area design, CEN/TC 325 Scope, 2014.
http://standards.cen.eu/dyn/www/f?p=204:7:0::::FSP_ORG_ID:6306&cs=133518429ECB0D4DDB06C8583A7A5CD0D
(figure continues)
CEN/
Standard EN 16352:2013 Logistics – Specifications for reporting crime incidents created common rules for the data collection and processing within the reporting of crimes, unrelated to the origin of the reporter or data collector162
Relates closely to the functions ‘information collection, storage and management to produce intelligence’ as well as ‘prevention’ in CRISP’s
Aims at the standardisation of security products and systems for perimeter protection
Focusses only onterrains surrounding buildings, but not on systems within the buildings.
Focuses on border security as well as the protection of critical infrastructure limits
A TR has been created, which provides information for the design of perimeter protection standards164
TC is not active at the moment Vulnerability Assessment and Protection of People at Risk
Focus of the TS: security risks in the field of CBRN Incidents with potential large scale effects
Consists mainly of tools for the development of vulnerability assessment, awareness and management165
Work correlates with the functions described in the glossary of security products, systems and services in CRISP’s Deliverable 1.1, not only regarding pre-vention, but also regarding the assessment of a secu-rity issue and the creation of situational awareness166 CEN/
TC 417
Security for mari-time and port set-ting
Focuses on quality standards for security services in that field
One standard is currently under enquiry CEN/
TC 419
Forensic science processes
No standards output yet.
Focus on all steps scene of the crime, the transporta-tion and storage of material, interpretatransporta-tion of the re-sults
Source: Own figure
Figure 20: Overview of the work of selected CEN TCs in the security field
162 See also EN 16352:2013 Logistics – Specifications for reporting crime incidents, p. 12.
163 See D1.1 Glossary of security products and systems 164 See CEN, op. cit., 2014
165 See CEN, op. cit., 2014 166 See CRISP D1.1
The work of the committees will be analysed in more detail in Chapter 4.3.
As shown on the basis of its TCs, CEN provides a large amount of European standards amongst the different security areas and is to be regarded as the main ESO responsible for security ENs.