Overview
ISO/TS 17574:2017 - "Electronic fee collection - Guidelines for security protection profiles" - provides guidance for preparing and evaluating security requirements specifications (Protection Profiles or PP) for electronic fee collection (EFC) systems. The technical specification is informational and intended to be used alongside ISO/IEC 15408 (Common Criteria) and ISO/IEC TR 15446. It focuses on EFC-specific roles and interfaces (for example, On‑Board Equipment (OBE) with an integrated circuit card) and describes processes for defining the Target of Evaluation (TOE), threat analysis, and PP structure. Note: these guidelines are superseded where an applicable Protection Profile already exists.
Key topics and requirements
- Protection Profile preparation and evaluation: Guidance on drafting PPs that capture operator-centric security requirements for categories of EFC products or systems.
- EFC security architecture: Contextualizes PPs within the EFC environment (OBE, Road Side Equipment - RSE, secure application modules - SAM, ICCs, and communication links such as DSRC).
- Scope of TOE: Limits evaluation to EFC‑specific roles and interfaces; external financial or third‑party interfaces are typically out of scope.
- Threat analysis and risk assessment: Procedures and an example method for identifying threats, threat agents, and assets (Annex B).
- Document structure and procedures: Recommended PP structure, context, preparatory steps and procedures for preparing supporting documentation (Annex A).
- Assurance and conformity: Alignment with Common Criteria concepts (EAL, security functional and assurance requirements) and processes for registration and evaluation (Annex D, CCRA references).
- Supporting materials: Annexes listing relevant security standards in EFC context and procedural examples to aid implementers.
Applications and who uses it
ISO/TS 17574:2017 is practical for:
- EFC operators and toll service providers preparing operator-driven Protection Profiles or security requirements for procurement.
- National authorities and highway agencies defining security policy and registration of PPs.
- Device and system suppliers (OBE/RSE/ICC/SAM vendors) developing security targets (ST) that implement a PP.
- Evaluators and certification bodies performing Common Criteria-based assessments of EFC components.
- System integrators and security architects designing secure EFC solutions and selecting compliant products.
Practical uses include drafting PPs for OBEs, guiding vendor ST development, supporting procurement specifications, and enabling internationally recognized security evaluation and registration.
Related standards
- ISO/IEC 15408 (Common Criteria) - foundational for PPs and STs
- ISO/IEC TR 15446 - guidance on evaluation activities
- References to DSRC, GNSS, and other EFC‑relevant security standards are provided in Annex C
Keywords: ISO/TS 17574:2017, electronic fee collection, EFC, Protection Profile, ISO/IEC 15408, Common Criteria, On‑Board Equipment, OBE, DSRC, security requirements.