Electric signalling systems for railways - Part 105: Risk-based assessment and handling of IT-security vulnerabilities and incidents

Pre-standard

DIN VDE V 0831-105:2024-12

VDE V 0831-105:2024-12

Electric signalling systems for railways - Part 105: Risk-based assessment and handling of IT-security vulnerabilities and incidents

German title
Elektrische Bahn-Signalanlagen - Teil 105: Risikobasierte Bewertung und Behandlung von IT-Sicherheits-Schwachstellen und -Vorfällen
Publication date
2024-12
Original language
German
Pages
41
Procedure
Pre-Standard

96.69 EUR VAT included

90.36 EUR VAT excluded

Format and language options

Shipment (3-5 working days)
  • 96.69 EUR

Monitor with the Standards Ticker

This option is only available after login.
Easily subscribe: Save time and money now!

You can also subscribe to this document - together with other important standards in your industry. This makes your work easier and pays for itself after a short time.

Sparschwein_data
Subscription advantages
Sparschwein Vorteil 1_data

Important standards for your industry, regularly updated

Sparschwein Vorteil 2_data

Much cheaper than buying individually

Sparschwein Vorteil 3_data

Useful functions: Filters, version comparison and more

Publication date
2024-12
Original language
German
Pages
41
Procedure
Pre-Standard
Loading recommended items...

Quick delivery via download or delivery service

Buy securely with a credit card or pay upon receipt of invoice

All transactions are encrypted

Overview

This document is applicable to safety-related electrical, electronic and programmable electronic (E/E/PES) systems including subsystems and equipment for electrical railway signalling systems. This document describes activities and methods with the aim of specifying a procedure for handling IT security vulnerabilities and incidents. Risk-based statements on implementation times for measures are also specified for this purpose. This document is applicable to the assessment and handling of risks arising from IT security threats as a result of security gaps. Only the basic steps are explained here; the details shall be regulated in the applicable guidelines and processes of the operator/manufacturer. There are no regional or international standards for the scope of application of this document. This document does not address vulnerabilities in functional security or physical access. It also does not address vulnerabilities caused solely by the fact that, in the case of time-limited documents which were the basis for bringing the system into operation, expired. Suitable processes for the timely extension / renewal of these bases are to be defined elsewhere. Typical examples of application include the establishment of security lifecycle management (SLCM) and the implementation of vulnerability management.

Cooperation at DIN

Loading recommended items...