SlideShare una empresa de Scribd logo
1 de 11
WP4 Key Outcomes
Berlin, 4th September 2015
Irene Kamara
Vrije Universiteit Brussel (LSTS)
Overview
Aims and structure of WP4
Key findings of WP4
Input for next WPs
2
Aims of WP4
 To identify and analyse the core issues associated with certification
 To come up with the requirements by which existing evaluation and
certification schemes could be used and possibly further developed,
enhanced, adapted and integrated for the assessment and
certification of products used for physical security of people and
infrastructures (i.e. best practice).
 Three deliverables & five tasks
 Other important elements:
 Legal study for each of the four tasks
 STEFi – Security-Trust-Efficiency-Freedom Infringements
 S.W.O.T. analysis
 Three case studies: drones, alarm systems and CCTV
3
Key outcomes
 STEFi criteria repository (D.4.3)
 Legal demands for security PSS on four STEFi
dimensions (D.4.1)
 Best practices of existing security evaluation and
certification schemes (D.4.3)
 Key issues relating to certification (D.4.1, D.4.3)
 Shortcomings and threats of existing schemes (D.4.3)
 Risks for CRISP scheme and methodology (D.4.2)
 Recommendations for security certification schemes
(D.4.3)
 Potential impact of security PSS to freedoms and rights,
especially data protection & privacy (D.4.2)
4
1. Shortcomings of existing schemes
 Majority of schemes: no clauses on freedoms and rights
 Efficiency aspect usually not considered
 Limited availability of scheme documentation : lack of
transparency
 Schemes built on national or local regulations only 
obstacle for harmonisation
 Lack of transparency regarding validity or renewal of
certificate
5
2. Recommendations
 Open and transparent scope, rules and processes.
 Strong monitoring mechanisms to supervise the compliance
of the PSS with the certification rules and its normative
references.
 Accountability mechanisms: clear distribution of responsibilities
 Reliable normative references, such as European standards
 Governance which involves several stakeholders
 Multinational participation in the development process of the scheme
to guarantee its pan-European nature
 Differentiation of testing and evaluation levels for different security
functions/needs
 Open and transparent scope, rules and processes
 Thorough rules on documentation to ensure accuracy and openness
to the interested parties
 Publication of the revoked and expired certificates
6
3. Role of certification in enhancing end-user trust in
security PSS
 Trust both in terms of the PSS and the certification
body/process
 Certification that guarantees technical reliability and
safety
 Transparency obligations to the security product
manufacturers
 Certification that supports Privacy by Design
 Accountability
 Independence of the certification body
 Involvement of stakeholders
 Regular review of compliance and up-to-date auditing
procedures
7
4. Other key findings
 Legal gap in regulating certification in Europe
 Schemes not always stand-alone documents, but often
complemented by other documentation (such as guidance, general
rules, other scheme rules etc.)
8
“a minimum set of legal rules in the form of legal
obligations could provide the market, and mainly the
consumers of the certified products, with the legal
certainty and boost the trust and confidence for the
certified products”
“Fragmentation in scheme documentation has an
impact on the comprehensiveness of the
requirements they test”
5. STEFi requirements scoring in existing
schemes
 Security is the most addressed dimension as expected –risk
management requirements score higher
 Trust not directly addressed –mainly achieving trust by proving
respect to rights and legislation
 Reliability and perception (observability) score higher
 Transparency and user/ scrutinised awareness score lower
 Efficiency
 General efficiency indicators, unintended economic effects and
customisation of the PSS to the user needs score high
 Energy efficiency and interoperability score low
 Fi: data protection & data security requirements addressed more
often compared to other rights. But not all STEFi attributes fulfiled
 Location of data, equal treatment, profiling and automated decision
score higher
 Non-discrimination, presumption of innocence score lower
9
STEFi requirements scoring in existing schemes
 Codes of conduct and normative parts tend to include
some of the societal aspects
 But: quite often the societal aspects are not audited –
only as reference/recommendation
 Standards and certification schemes: technical aspects
 Gap can be filled from CRISP scheme
10
Thank you

Más contenido relacionado

La actualidad más candente (6)

E Society Ict En
E Society Ict EnE Society Ict En
E Society Ict En
 
WCET Presentation
WCET PresentationWCET Presentation
WCET Presentation
 
Rainer Zimmermann (European Commission): The role of the European Commission ...
Rainer Zimmermann (European Commission): The role of the European Commission ...Rainer Zimmermann (European Commission): The role of the European Commission ...
Rainer Zimmermann (European Commission): The role of the European Commission ...
 
CaselliM_CV
CaselliM_CVCaselliM_CV
CaselliM_CV
 
Open Sample Intro Pgraham 0910
Open Sample Intro Pgraham 0910Open Sample Intro Pgraham 0910
Open Sample Intro Pgraham 0910
 
Saint Louis University, Improved Microchips for Analytical Tools
Saint Louis University, Improved Microchips for Analytical ToolsSaint Louis University, Improved Microchips for Analytical Tools
Saint Louis University, Improved Microchips for Analytical Tools
 

Destacado

Interoperability and Open Standards EC 19 Nov2008
Interoperability and Open Standards EC 19 Nov2008Interoperability and Open Standards EC 19 Nov2008
Interoperability and Open Standards EC 19 Nov2008
aclorrain
 
Stakeholder analysis of Delhi Metro
Stakeholder analysis of Delhi MetroStakeholder analysis of Delhi Metro
Stakeholder analysis of Delhi Metro
jerry christo
 
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Asociación XBRL España
 

Destacado (20)

CRISP evaluation using the STEFi approach
CRISP evaluation using the STEFi approachCRISP evaluation using the STEFi approach
CRISP evaluation using the STEFi approach
 
CRISP - Overview and results
CRISP - Overview and results CRISP - Overview and results
CRISP - Overview and results
 
2. crisp final conf ste fi workshop_reflections iec-tc79 wg12
2. crisp final conf ste fi workshop_reflections iec-tc79 wg122. crisp final conf ste fi workshop_reflections iec-tc79 wg12
2. crisp final conf ste fi workshop_reflections iec-tc79 wg12
 
Euralarm - Glen Dale on security industry perspective on certification of sec...
Euralarm - Glen Dale on security industry perspective on certification of sec...Euralarm - Glen Dale on security industry perspective on certification of sec...
Euralarm - Glen Dale on security industry perspective on certification of sec...
 
Kochi metro stakeholder analysis
Kochi metro stakeholder analysisKochi metro stakeholder analysis
Kochi metro stakeholder analysis
 
EU Data Protection, Legislation and Certification
EU Data Protection, Legislation and Certification EU Data Protection, Legislation and Certification
EU Data Protection, Legislation and Certification
 
1st eStandards conference: next steps for standardization in large scale eHea...
1st eStandards conference: next steps for standardization in large scale eHea...1st eStandards conference: next steps for standardization in large scale eHea...
1st eStandards conference: next steps for standardization in large scale eHea...
 
Interoperability and Open Standards EC 19 Nov2008
Interoperability and Open Standards EC 19 Nov2008Interoperability and Open Standards EC 19 Nov2008
Interoperability and Open Standards EC 19 Nov2008
 
Promoting (meta)-data standards - The European Commission ISA Programme per...
 Promoting (meta)-data standards- The European Commission ISA Programme per... Promoting (meta)-data standards- The European Commission ISA Programme per...
Promoting (meta)-data standards - The European Commission ISA Programme per...
 
2016 jun16 msp european catalogue
2016 jun16 msp   european catalogue2016 jun16 msp   european catalogue
2016 jun16 msp european catalogue
 
Delhi Metro Railway's Stakeholder Management
Delhi Metro Railway's Stakeholder Management Delhi Metro Railway's Stakeholder Management
Delhi Metro Railway's Stakeholder Management
 
Blind - Standardisation and standards as research and innovation indicators
Blind - Standardisation and standards as research and innovation indicatorsBlind - Standardisation and standards as research and innovation indicators
Blind - Standardisation and standards as research and innovation indicators
 
Policy and Standardisation perspective - CRISP Final Conference
Policy and Standardisation perspective - CRISP Final ConferencePolicy and Standardisation perspective - CRISP Final Conference
Policy and Standardisation perspective - CRISP Final Conference
 
Stakeholder analysis of Delhi Metro
Stakeholder analysis of Delhi MetroStakeholder analysis of Delhi Metro
Stakeholder analysis of Delhi Metro
 
Kochi Metro Rail Project.doc
Kochi Metro Rail Project.docKochi Metro Rail Project.doc
Kochi Metro Rail Project.doc
 
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
Estándares en Unión Europea: Marco, Desafíos y Oportunidades - Francisco Garc...
 
CRISP and HECTOS projects - key findings
CRISP and HECTOS projects - key findings CRISP and HECTOS projects - key findings
CRISP and HECTOS projects - key findings
 
Standardisation and certification basics
Standardisation and certification basicsStandardisation and certification basics
Standardisation and certification basics
 
Can Trust In Security TEchnologies be Enhanced through Certification?
Can Trust In Security TEchnologies be Enhanced through Certification?Can Trust In Security TEchnologies be Enhanced through Certification?
Can Trust In Security TEchnologies be Enhanced through Certification?
 
Smart Video Surveillance and Privacy - CRISP Final Conference
Smart Video Surveillance and Privacy - CRISP Final ConferenceSmart Video Surveillance and Privacy - CRISP Final Conference
Smart Video Surveillance and Privacy - CRISP Final Conference
 

Similar a CRISP Work package 4 Key Outcomes

Critical Security And Compliance Issues In Internet Banking
Critical Security And Compliance Issues In Internet BankingCritical Security And Compliance Issues In Internet Banking
Critical Security And Compliance Issues In Internet Banking
Thomas Donofrio
 
070215 Plenary Ray
070215 Plenary Ray070215 Plenary Ray
070215 Plenary Ray
maniclub
 
Highlights from ExL Pharma's Proactive GCP Compliance
Highlights from ExL Pharma's Proactive GCP ComplianceHighlights from ExL Pharma's Proactive GCP Compliance
Highlights from ExL Pharma's Proactive GCP Compliance
ExL Pharma
 
AAMI Human Factors October
AAMI Human Factors OctoberAAMI Human Factors October
AAMI Human Factors October
Victoria Slee
 

Similar a CRISP Work package 4 Key Outcomes (20)

CRISP project: overview of findings and lessons learned.
CRISP project: overview of findings and lessons learned.CRISP project: overview of findings and lessons learned.
CRISP project: overview of findings and lessons learned.
 
Critical Security And Compliance Issues In Internet Banking
Critical Security And Compliance Issues In Internet BankingCritical Security And Compliance Issues In Internet Banking
Critical Security And Compliance Issues In Internet Banking
 
IT Compliance in 2015 - Beyond the “v” model
IT Compliance in 2015 - Beyond the “v” modelIT Compliance in 2015 - Beyond the “v” model
IT Compliance in 2015 - Beyond the “v” model
 
David Whitaker: Managing Your Vendors
David Whitaker: Managing Your VendorsDavid Whitaker: Managing Your Vendors
David Whitaker: Managing Your Vendors
 
070215 Plenary Ray
070215 Plenary Ray070215 Plenary Ray
070215 Plenary Ray
 
Iso 27001 isms presentation
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentation
 
pepe111
pepe111pepe111
pepe111
 
EuroPriSe and ISDP 10003 2015
EuroPriSe and ISDP 10003 2015EuroPriSe and ISDP 10003 2015
EuroPriSe and ISDP 10003 2015
 
EuroPriSe and ISDP10003 2015 -
EuroPriSe and ISDP10003  2015 - EuroPriSe and ISDP10003  2015 -
EuroPriSe and ISDP10003 2015 -
 
Presentation USEPA Workshop Next Generation Compliance december 12, 2012 Wash...
Presentation USEPA Workshop Next Generation Compliance december 12, 2012 Wash...Presentation USEPA Workshop Next Generation Compliance december 12, 2012 Wash...
Presentation USEPA Workshop Next Generation Compliance december 12, 2012 Wash...
 
Highlights from ExL Pharma's Proactive GCP Compliance
Highlights from ExL Pharma's Proactive GCP ComplianceHighlights from ExL Pharma's Proactive GCP Compliance
Highlights from ExL Pharma's Proactive GCP Compliance
 
Security policies
Security policiesSecurity policies
Security policies
 
Data Analytics for Auditors Analysis and Monitoring
Data Analytics for Auditors Analysis and MonitoringData Analytics for Auditors Analysis and Monitoring
Data Analytics for Auditors Analysis and Monitoring
 
Effective ex post Evaluation: Purpose and Challenges
Effective ex post Evaluation: Purpose and ChallengesEffective ex post Evaluation: Purpose and Challenges
Effective ex post Evaluation: Purpose and Challenges
 
FDA News Presentation
FDA News PresentationFDA News Presentation
FDA News Presentation
 
AAMI Human Factors October
AAMI Human Factors OctoberAAMI Human Factors October
AAMI Human Factors October
 
Criterios Minimos de Seguridad CTPAT 2019 conference
Criterios Minimos de Seguridad CTPAT 2019 conferenceCriterios Minimos de Seguridad CTPAT 2019 conference
Criterios Minimos de Seguridad CTPAT 2019 conference
 
MAGI Presentation
MAGI PresentationMAGI Presentation
MAGI Presentation
 
Learning technologies 2014: The Trickle Down Effect of Compliance
Learning technologies 2014: The Trickle Down Effect of ComplianceLearning technologies 2014: The Trickle Down Effect of Compliance
Learning technologies 2014: The Trickle Down Effect of Compliance
 
Keeping Score on Testing
Keeping Score on TestingKeeping Score on Testing
Keeping Score on Testing
 

Último

一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
Airst S
 
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
CssSpamx
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
JosephCanama
 
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
A AA
 
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
e9733fc35af6
 
一比一原版(USYD毕业证书)澳洲悉尼大学毕业证如何办理
一比一原版(USYD毕业证书)澳洲悉尼大学毕业证如何办理一比一原版(USYD毕业证书)澳洲悉尼大学毕业证如何办理
一比一原版(USYD毕业证书)澳洲悉尼大学毕业证如何办理
A AA
 
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.pptCorporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
RRR Chambers
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
ss
 
Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
mahikaanand16
 

Último (20)

一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
 
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
Corporate Sustainability Due Diligence Directive (CSDDD or the EU Supply Chai...
Corporate Sustainability Due Diligence Directive (CSDDD or the EU Supply Chai...Corporate Sustainability Due Diligence Directive (CSDDD or the EU Supply Chai...
Corporate Sustainability Due Diligence Directive (CSDDD or the EU Supply Chai...
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
 
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargaining
 
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
 
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
 
一比一原版(USYD毕业证书)澳洲悉尼大学毕业证如何办理
一比一原版(USYD毕业证书)澳洲悉尼大学毕业证如何办理一比一原版(USYD毕业证书)澳洲悉尼大学毕业证如何办理
一比一原版(USYD毕业证书)澳洲悉尼大学毕业证如何办理
 
Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdf
 
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.pptCorporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
Contract law. Indemnity
Contract law.                     IndemnityContract law.                     Indemnity
Contract law. Indemnity
 
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
 
Police Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringPolice Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. Steering
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdf
 
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation StrategySmarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
Smarp Snapshot 210 -- Google's Social Media Ad Fraud & Disinformation Strategy
 
Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in Law
 

CRISP Work package 4 Key Outcomes

  • 1. WP4 Key Outcomes Berlin, 4th September 2015 Irene Kamara Vrije Universiteit Brussel (LSTS)
  • 2. Overview Aims and structure of WP4 Key findings of WP4 Input for next WPs 2
  • 3. Aims of WP4  To identify and analyse the core issues associated with certification  To come up with the requirements by which existing evaluation and certification schemes could be used and possibly further developed, enhanced, adapted and integrated for the assessment and certification of products used for physical security of people and infrastructures (i.e. best practice).  Three deliverables & five tasks  Other important elements:  Legal study for each of the four tasks  STEFi – Security-Trust-Efficiency-Freedom Infringements  S.W.O.T. analysis  Three case studies: drones, alarm systems and CCTV 3
  • 4. Key outcomes  STEFi criteria repository (D.4.3)  Legal demands for security PSS on four STEFi dimensions (D.4.1)  Best practices of existing security evaluation and certification schemes (D.4.3)  Key issues relating to certification (D.4.1, D.4.3)  Shortcomings and threats of existing schemes (D.4.3)  Risks for CRISP scheme and methodology (D.4.2)  Recommendations for security certification schemes (D.4.3)  Potential impact of security PSS to freedoms and rights, especially data protection & privacy (D.4.2) 4
  • 5. 1. Shortcomings of existing schemes  Majority of schemes: no clauses on freedoms and rights  Efficiency aspect usually not considered  Limited availability of scheme documentation : lack of transparency  Schemes built on national or local regulations only  obstacle for harmonisation  Lack of transparency regarding validity or renewal of certificate 5
  • 6. 2. Recommendations  Open and transparent scope, rules and processes.  Strong monitoring mechanisms to supervise the compliance of the PSS with the certification rules and its normative references.  Accountability mechanisms: clear distribution of responsibilities  Reliable normative references, such as European standards  Governance which involves several stakeholders  Multinational participation in the development process of the scheme to guarantee its pan-European nature  Differentiation of testing and evaluation levels for different security functions/needs  Open and transparent scope, rules and processes  Thorough rules on documentation to ensure accuracy and openness to the interested parties  Publication of the revoked and expired certificates 6
  • 7. 3. Role of certification in enhancing end-user trust in security PSS  Trust both in terms of the PSS and the certification body/process  Certification that guarantees technical reliability and safety  Transparency obligations to the security product manufacturers  Certification that supports Privacy by Design  Accountability  Independence of the certification body  Involvement of stakeholders  Regular review of compliance and up-to-date auditing procedures 7
  • 8. 4. Other key findings  Legal gap in regulating certification in Europe  Schemes not always stand-alone documents, but often complemented by other documentation (such as guidance, general rules, other scheme rules etc.) 8 “a minimum set of legal rules in the form of legal obligations could provide the market, and mainly the consumers of the certified products, with the legal certainty and boost the trust and confidence for the certified products” “Fragmentation in scheme documentation has an impact on the comprehensiveness of the requirements they test”
  • 9. 5. STEFi requirements scoring in existing schemes  Security is the most addressed dimension as expected –risk management requirements score higher  Trust not directly addressed –mainly achieving trust by proving respect to rights and legislation  Reliability and perception (observability) score higher  Transparency and user/ scrutinised awareness score lower  Efficiency  General efficiency indicators, unintended economic effects and customisation of the PSS to the user needs score high  Energy efficiency and interoperability score low  Fi: data protection & data security requirements addressed more often compared to other rights. But not all STEFi attributes fulfiled  Location of data, equal treatment, profiling and automated decision score higher  Non-discrimination, presumption of innocence score lower 9
  • 10. STEFi requirements scoring in existing schemes  Codes of conduct and normative parts tend to include some of the societal aspects  But: quite often the societal aspects are not audited – only as reference/recommendation  Standards and certification schemes: technical aspects  Gap can be filled from CRISP scheme 10