EPJ Web of Conferences (Jan 2014)

IT Security Standards and Legal Metrology – Transfer and Validation

  • Thiel F.,
  • Hartmann V.,
  • Grottker U.,
  • Richter D.

DOI
https://doi.org/10.1051/epjconf/20147700001
Journal volume & issue
Vol. 77
p. 00001

Abstract

Read online

Legal Metrology’s requirements can be transferred into the IT security domain applying a generic set of standardized rules provided by the Common Criteria (ISO/IEC 15408). We will outline the transfer and cross validation of such an approach. As an example serves the integration of Legal Metrology’s requirements into a recently developed Common Criteria based Protection Profile for a Smart Meter Gateway designed under the leadership of the Germany’s Federal Office for Information Security. The requirements on utility meters laid down in the Measuring Instruments Directive (MID) are incorporated. A verification approach to check for meeting Legal Metrology’s requirements by their interpretation through Common Criteria’s generic requirements is also presented.