GENERALIZED RISK ASSESSMENT PROCEDURE FOR SOFTWARE TESTING OF LEGALLY REGULATED MEASURING INSTRUMENTS

Author:

Gaman ValentynORCID, ,Kursin SerhiiORCID,Velychko OlehORCID, ,

Abstract

The legal metrology covers measuring instruments (MI), the measurement results of which are used in calculations for consumed energy resources, in the fields of information protection, security, environmental protection, etc. Most modern MIs use microcontrollers or are controlled by computers. The software (SW) of such MIs provides an opportunity not only to automate the processes of measurement and calculation of results but also to ensure long-term storage and data transfer. The manufacturer is responsible for investigating and assessing all possible risks related to the MI SW. The task of the conformity assessment body is to assess the conformity of MIs adequately in general and software, in particular, to the established requirements based on the analysis of risk classes. Standards for information security risk management, information technology security assessment, and information technology security assessment criteria consider only general issues of software security and risk assessment without taking into account the scope of its application. The existing regulatory documents on software risk management were considered. Modern methods of assessing the risks of the MI SW were studied. To assess the risks of software of legally regulated MIs, a general classification of threats and vulnerabilities of MI SW was made. For choosing threats that affect functionality, only those that affect metrological characteristics during measurement are taken into account. Possible manifestations of the impact of threats on stored data can be their distortion or destruction, and transmissions of data can be data distortion during transmission or data loss due to a break in the telecommunications connection. A proposed simplified risk assessment methodology for assessing the compliance of MI SW without statistical data on the probabilities of threats and the amount of harm from the implementation of threats is presented. Risk is defined as the probability of harm due to a certain vulnerability, taking into account the conditional amount of harm.

Publisher

Lviv Polytechnic National University

Subject

Industrial and Manufacturing Engineering,Metals and Alloys,Strategy and Management,Mechanical Engineering

Reference15 articles.

1. [1] Technical regulation of measuring equipment. Resolution of the Cabinet of Ministers of Ukraine, 24.02.2016, № 163. - Available at: https://zakon.rada.gov.ua/laws/show/163- 2016-%D0%BF#Text.

2. [2] Technical regulation of legally regulated measuring equipment. Resolution of the Cabinet of Ministers of Ukraine, 13.01.2016, № 94. - Available at: https://zakon.rada. gov.ua/laws/show/94-2016-%D0%BF#Text.

3. [3] WELMEC 7.2:2021. Issue 9. Software Guide (Measuring Instruments Directive 2014/32/EU1). - WELMEC, 2021. - 148 с. https://www.welmec.org/welmec/documents/ guides/7.2/2021/WELMEC_Guide_7.2_v2021.pdf.

4. [4] Directive 2014/32/EU of 26 February 2014 on the harmonization of the laws of the Member States relating to the making available on the market of measuring instruments (recast). - Available at: https://eur-lex.europa.eu/eli/dir/2014/32/oj. [5] ISO/IEC 27005:2022, "Information technology - Security techniques - Information security risk management", ISO, 2022.

5. [6] ISO/IEC 18045:2008, "Common Methodology for Information Technology Security Evaluation", ISO, 2008.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3