| Zugriffsnummer | 43053 |
| Dokumenttyp | Konferenzartikel in Zeitschrift |
| Peer Review | mit Peer Review |
| Sprache | Englisch |
| Titel | Formalization of software risk assessment results in legal metrology based on ISO/IEC 18045 vulnerability analysis |
| Autor(in); Institution |
Esche, Marko; 8.5, Metrologische Informationstechnik, PTB-Berlin
Salwiczek, Felix; 8.5, Metrologische Informationstechnik, PTB-Berlin
Federico, Grasso Toro; METAS, SWITZERLAND
|
| Quelle/Jahr | Proceedings of the 2019 Federated Conference on Computer Science and Information Systems. Annals of Computer Science and Information Systems: 18 (2019), 443 - 447 |
| Availability | [online only] |
| Herausgeber(in) |
Ganzha, M.
Maciaszek, L.
Paprzycki, M.
|
| ISSN | 2300-5963 |
| ISBN | 978-83-952357-8-8 |
| DOI | |
| Verlag | Warszawa: Polish Information Processing Society |
| Konferenzangaben | Federated Conference on Computer Science and Information Systems (FedCSIS), Leipzig, 1-4, September, 2019, Deutschland |
| Freie Schlagworte | Software Risk Assessment ; Formalization ; ISO 18045 |
| Zusammenfassung | The Measuring Instruments Directive sets down essential requirements for measuring instruments subject to legal control in the EU. It dictates that a risk assessment must be performed before such instruments are put on the market. Because of the increasing importance of software in measuring instruments, a specifically tailored software risk assessment method has been previously developed and published. Related research has been done on graphical representation of threats by attack probability trees. The final stage is to formalize the method to prove its reproducibility and resilience against the complexity of future instruments. To this end, an inter-institutional comparison of the method is currently being conducted across national metrology institutes, while the weighing equipment manufacturers’ association CECIP has provided a new measuring instrument concept, as a significant example of complex instruments. Based on the results of the comparison, a template to formalize the software risk assessment method is proposed here. |
| Kostenfreier Zugang | Open Access Gold |