SIST EN ISO 17574:2026
(Main)Electronic fee collection - Requirements for security protection profiles (ISO 17574:2026)
- Abstract
This document specifies electronic fee collection (EFC) requirements for the preparation and evaluation of security requirements specifications, referred to as protection profiles (PP) in the ISO/IEC 15408 series and in ISO/IEC TR 15446.
- Status
- Published
- Public Enquiry End Date
- 06-Oct-2025
- Publication Date
- 06-Oct-2026
- Technical Committee
- ITC - Information technology
- Current Stage
- 6060 - National Implementation/Publication (Adopted Project)
- Start Date
- 17-Sep-2026
- Due Date
- 22-Nov-2026
- Completion Date
- 07-Oct-2026
Overview
SIST EN ISO 17574:2026 specifies the requirements and guidelines for preparing and evaluating security protection profiles (PP) for electronic fee collection (EFC) systems. This international standard is part of a coordinated effort to enhance the security and reliability of tolling systems used in road transport. Developed in alignment with the ISO/IEC 15408 series and ISO/IEC TR 15446, this standard focuses primarily on defining robust security requirements for key EFC components, such as on-board equipment (OBE), to counteract common security threats and support trusted, interoperable EFC solutions.
By following these guidelines, operators, system developers, and evaluators can produce consistent, internationally recognized security documentation for EFC systems, laying the groundwork for secure and efficient toll collection on modern road networks.
Key Topics
Electronic Fee Collection Security Architecture:
The standard outlines the security environment for EFC, identifying vulnerabilities and threats that impact both system users and operators. It describes how to develop protection profiles that address these risks.Protection Profile (PP) Creation:
Detailed procedures guide organizations in defining the security objectives, requirements, and rationale that form a strong protection profile for EFC components (e.g., OBE, roadside equipment).Conformance and Evaluation:
Alignment with ISO/IEC 15408 criteria ensures the EFC security profiles are internationally recognized. The document also clarifies the distinction and relationships between PPs and security targets (ST), supporting transparent security assessments.Roles and Interfaces:
Focuses on securing specific roles and external interfaces pertinent to EFC systems-providing clear boundaries and responsibilities for each entity in the ecosystem.Preparation Examples and Best Practices:
Annexes illustrate practical steps for preparing PPs, including example threat analyses and summaries of relevant security standards.
Applications
SIST EN ISO 17574:2026 is essential for organizations involved in the design, deployment, and evaluation of electronic toll collection systems. Common applications include:
Tolling Operators and Solution Providers:
Ensuring their EFC solutions such as OBEs and roadside modules meet international security expectations, minimizing risks of fraud or system compromise.System Integrators:
Applying standardized security requirements during system development to achieve compliance with regulatory and contractual obligations.Independent Evaluators:
Using the protection profiles and supporting documentation as a basis for security evaluation and certification under the Common Criteria Recognition Arrangement (CCRA).National and Regional Authorities:
Referencing internationally recognized PPs to harmonize security across tolling schemes and support interoperable EFC initiatives.
Adhering to this standard not only strengthens system security but also facilitates cross-border interoperability and acceptance, benefiting both operators and end users.
Related Standards
SIST EN ISO 17574:2026 works in close association with several other international standards relevant to EFC security and road transport:
ISO/IEC 15408 (all parts):
Information security - Evaluation criteria for IT security, commonly known as Common Criteria, forms the basis for developing and assessing PPs and security targets.ISO/IEC TR 15446:
Provides guidance for the production of protection profiles and security targets.ISO 17573-2:
Electronic fee collection - System architecture for vehicle-related tolling - Vocabulary and definitions.
Organizations adopting SIST EN ISO 17574:2026 are encouraged to consult these related documents to ensure comprehensive security coverage and consistency across the entire EFC lifecycle.
By implementing SIST EN ISO 17574:2026, stakeholders in the electronic toll collection sector can effectively address modern security challenges, improve trust in tolling systems, and support the seamless integration of intelligent transport solutions.
Relations
- Effective Date
- 01-Nov-2026
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.
Great Wall Tianjin Quality Assurance Center
Established 1993, first batch to receive national accreditation with IAF recognition.
Hong Kong Quality Assurance Agency (HKQAA)
Hong Kong's leading certification body.
Sponsored listings
Frequently Asked Questions
SIST EN ISO 17574:2026 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Electronic fee collection - Requirements for security protection profiles (ISO 17574:2026)". This standard covers: This document specifies electronic fee collection (EFC) requirements for the preparation and evaluation of security requirements specifications, referred to as protection profiles (PP) in the ISO/IEC 15408 series and in ISO/IEC TR 15446.
This document specifies electronic fee collection (EFC) requirements for the preparation and evaluation of security requirements specifications, referred to as protection profiles (PP) in the ISO/IEC 15408 series and in ISO/IEC TR 15446.
SIST EN ISO 17574:2026 is classified under the following ICS (International Classification for Standards) categories: 03.220.20 - Road transport; 35.240.60 - IT applications in transport. The ICS classification helps identify the subject area and facilitates finding related standards.
SIST EN ISO 17574:2026 has the following relationships with other standards: It is inter standard links to SIST-TS CEN ISO/TS 17574:2017. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
SIST EN ISO 17574:2026 is associated with the following European legislation: EU Directives/Regulations: 2019/520; Standardization Mandates: M/598. When a standard is cited in the Official Journal of the European Union, products manufactured in conformity with it benefit from a presumption of conformity with the essential requirements of the corresponding EU directive or regulation.
SIST EN ISO 17574:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-november-2026
Nadomešča:
SIST-TS CEN ISO/TS 17574:2017
Elektronsko pobiranje pristojbin - Zahteve za zaščito varnostnih profilov EFC (ISO
17574:2026)
Electronic fee collection - Requirements for security protection profiles (ISO 17574:2026)
Elektronische Gebührenerhebung - Leitfaden für Sicherheitsprofile (ISO 17574:2026)
Perception de télépéage - Exigences relatives aux profils de protection de sécurité (ISO
17574:2026)
Ta slovenski standard je istoveten z: EN ISO 17574:2026
ICS:
03.220.20 Cestni transport Road transport
35.240.60 Uporabniške rešitve IT v IT applications in transport
prometu
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
EN ISO 17574
EUROPEAN STANDARD
NORME EUROPÉENNE
September 2026
EUROPÄISCHE NORM
ICS 03.220.20; 35.240.60 Supersedes CEN ISO/TS 17574:2017
English Version
Electronic fee collection - Requirements for security
protection profiles (ISO 17574:2026)
Perception de télépéage - Exigences relatives aux Elektronische Gebührenerhebung - Leitfaden für
profils de protection de sécurité (ISO 17574:2026) Sicherheitsprofile (ISO 17574:2026)
This European Standard was approved by CEN on 27 July 2026.
CEN members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this
European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical references
concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to any CEN
member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by
translation under the responsibility of a CEN member into its own language and notified to the CEN-CENELEC Management
Centre has the same status as the official versions.
CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia,
Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway,
Poland, Portugal, Republic of North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and
United Kingdom.
EUROPEAN COMMITTEE FOR STANDARDIZATION
COMITÉ EUROPÉEN DE NORMALISATION
EUROPÄISCHES KOMITEE FÜR NORMUNG
CEN-CENELEC Management Centre: Rue de la Science 23, B-1040 Brussels
© 2026 CEN All rights of exploitation in any form and by any means reserved Ref. No. EN ISO 17574:2026 E
worldwide for CEN national Members.
Contents Page
European foreword . 3
European foreword
This document (EN ISO 17574:2026) has been prepared by Technical Committee ISO/TC 204
"Intelligent transport systems" in collaboration with Technical Committee CEN/TC 278 “Intelligent
transport systems” the secretariat of which is held by NEN.
This European Standard shall be given the status of a national standard, either by publication of an
identical text or by endorsement, at the latest by March 2027, and conflicting national standards shall
be withdrawn at the latest by March 2027.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN shall not be held responsible for identifying any or all such patent rights.
This document supersedes CEN ISO/TS 17574:2017.
This document has been prepared under a standardization request addressed to CEN by the European
Commission. The Standing Committee of the EFTA States subsequently approves these requests for its
Member States.
Any feedback and questions on this document should be directed to the users’ national standards
body/national committee. A complete listing of these bodies can be found on the CEN website.
According to the CEN-CENELEC Internal Regulations, the national standards organizations of the
following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Endorsement notice
The text of ISO 17574:2026 has been approved by CEN as EN ISO 17574:2026 without any modification.
International
Standard
ISO 17574
First edition
Electronic fee collection —
2026-09
Requirements for security
protection profiles
Perception de télépéage — Exigences relatives aux profils de
protection de sécurité
Reference number
ISO 17574:2026(en) © ISO 2026
ISO 17574:2026(en)
© ISO 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
ISO 17574:2026(en)
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 2
5 EFC security architecture and protection profile processes . 2
5.1 General .2
5.2 EFC security architecture . .3
5.3 Protection profile preparatory steps .3
5.4 Relationship between actors .4
6 Outline of protection profile (PP) . 6
6.1 Structure .6
6.2 Context .6
Annex A (informative) Procedure to prepare the protection profile . 8
Annex B (informative) Example of threat analysis evaluation method .40
Annex C (informative) Relevant security standards in the context of the EFC .46
Bibliography . 47
iii
ISO 17574:2026(en)
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO document should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 204, Intelligent transport systems, in
collaboration with the European Committee for Standardization (CEN) Technical Committee CEN/TC 278,
Intelligent Transport Systems, in accordance with the Agreement on technical cooperation between ISO and
CEN (Vienna Agreement).
This first edition cancels and replaces the third edition (ISO/TS 17574:2017), which has been technically
revised.
The main changes are as follows:
— Clause 3 has been updated and ISO 17573-2 has been made the primary source for terms and definitions;
— requirements have been updated to reflect the latest edition of the ISO/IEC 15408 series.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.
iv
ISO 17574:2026(en)
Introduction
Electronic fee collection (EFC) systems are subject to several ways of fraud both by users and operators but
also from people outside the system. These security threats are countered with various types of security
measures linked to specified security requirements.
It is recommended that EFC operators prepare their own EFC protection profile (PP) according to this
document, as security requirements should be described from the operator's point of view.
A protection profile (PP) refers to a set of safety requirements for a category of products or systems that
meet specific needs. A typical example is a PP for on-board equipment (OBE) to be used in an EFC system.
However, the requirements in this document are superseded if a PP already exists for the subsystem in
question.
The target of evaluation (TOE) for EFC is limited to EFC specific roles and interfaces as shown in Figure 1.
Figure 1 shows the relationships and interactions among the entities related to the TOE of the EFC. As shown
in this figure, entities are overall management of the toll charging environment, EFC service provider, toll
charger and user of the service. Since the existing financial security standards and criteria are applicable to
other external roles and interfaces, they are assumed to be outside the scope of TOE for EFC.
Figure 1 — Scope of TOE for EFC
The security evaluation is performed by assessing the security-related properties of roles, entities and
interfaces defined in security targets (STs), as opposed to assessing complete processes which often are
distributed over more entities and interfaces than those covered by the TOE of this document.
NOTE Assessing security issues for complete processes is a complementary approach, which can be beneficial to
apply when evaluating the security of a system.
It should be noted that the requirements provided in this document are intended to be read in conjunction
with the ISO/IEC 15408 series. Annex A provides an example of how to prepare the security requirements for
EFC equipment, in this case, a dedicated short-range communication (DSRC)-based OBE with an integrated
circuit(s) card (ICC) containing data needed for the EFC. The example refers to a Japanese national EFC
system and should only be regarded as an example.
After an PP for EFC is prepared, it can be internationally registered by the organization that prepared the
PP for EFC so that other operators or countries that want to develop their EFC system security services can
refer to an already registered PP for EFC.
This document on security service framework and PP for EFC is based on the ISO/IEC 15408 series. The
ISO/IEC 15408 series includes a set of requirements for the security functions and assurance of IT-relevant
products and systems. Operators, organizations or authorities defining their own PP for EFC can use these
v
ISO 17574:2026(en)
requirements. The different PPs for EFC defined by operators, organizations or authorities will be similar
to the different PPs registered by several financial institutions, e.g. for payment instruments like IC cards
(ICCs).
The products and systems that were developed in accordance with the ISO/IEC 15408 series can be publicly
assured by the authentication of the government or designated private evaluation agencies.
vi
International Standard ISO 17574:2026(en)
Electronic fee collection — Requirements for security
protection profiles
1 Scope
This document specifies electronic fee collection (EFC) requirements for the preparation and evaluation of
security requirements specifications, referred to as protection profiles (PP) in the ISO/IEC 15408 series and
in ISO/IEC TR 15446.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 15408-1:2022, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Part 1: Introduction and general model
ISO/IEC 15408-2:2022, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Part 2: Security functional components
ISO/IEC 15408-3:2022, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Part 3: Security assurance components
ISO/IEC 15408-4:2022, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Part 4: Framework for the specification of evaluation methods and activities
ISO/IEC 15408-5:2022, Information security, cybersecurity and privacy protection — Evaluation criteria for IT
security — Part 5: Pre-defined packages of security requirements
ISO 17573-2, Electronic fee collection — System architecture for vehicle related tolling — Part 2: Vocabulary
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO 17573-2 apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
ISO 17574:2026(en)
4 Abbreviated terms
CC common criteria
CCRA common criteria recognition arrangement
CN cellular networks
DSRC dedicated short-range communication
EAL evaluation assurance level
EFC electronic fee collection
GNSS global navigation satellite systems
HMI human-machine interface
ICC integrated circuit(s) card
IT information technology
OBE on-board equipment
PP protection profile
RSE roadside equipment
SAM secure application module
SFP security function policy
SFR security functional requirement
ST security target
TOE target of evaluation
TSF target of evaluation security functions
5 EFC security architecture and protection profile processes
5.1 General
This clause gives an overview of the context and use of this document in terms of the EFC security
architecture and protection profile processes.
This document is intended to be read in conjunction with the ISO/IEC 15408 series and ISO/IEC TR 15446.
Although a reader unfamiliar with the standards can read the first part of the document to have an overview
on how to prepare a PP for EFC equipment, the annexes, in particular Annexes A.4 and A.5, require the reader
to be familiar with the ISO/IEC 15408 series. This document uses an OBE with an integrated circuit(s) card
(ICC) as an example to describe both the structure of the PP, as well as the proposed content.
In Annex A, the procedure for preparing PP for EFC is illustrated, which is described by using an OBE as an
example of EFC equipment. The communication link (between the OBE and the RSE) is based on DSRC.
Annex B gives an example of how a threat analysis can be done, while Annex C provides an overview of
the relevant security standards in the context of the EFC, which provides the background of EFC roles and
interfaces.
ISO 17574:2026(en)
5.2 EFC security architecture
Figure 2 illustrates the position of this document within the broader context of the EFC security architecture,
highlighting the relationships between related domains and information dependencies. The shaded boxes
are the aspects mostly related to the preparation of PPs for EFC systems.
Regarding the security design framework, there are five domains. Functionality of these domains are
described as below.
— Operator domain defines the data protection requirement of the TOE as PP.
— System domain develops the ST based on the requirement. For development of the ST, threat and risk
assessment are done with balancing the cost and effect of the security measures.
— Legal domain defines the relevant regulations and standards.
— Application domain defines the requirement and constraints of the TOE.
— Audit domain conducts the audit and evaluation of validities of design of implementation for data
protection measures. As the feedback of the audit and evaluation, reasons are reported to System domain
and Operator domain.
Key
action
information
Figure 2 — Overall view of security design framework
5.3 Protection profile preparatory steps
The main purpose of a PP is to analyse the security environment of a subject and then to specify the
requirements for each of the threats identified by the security environment analysis. The subject studied is
called the target of evaluation (TOE). In this document, an OBE with an ICC is used as an example of the TOE.
The preparatory work of PP for EFC consists of the steps shown in Table 1, according to the contents
described in Clause 6.
ISO 17574:2026(en)
For the first step, a general outline of TOE is prepared as overview. As the second step, features, interface
of TOE and its use case are defined and in the third step, security environment and its security policies are
defined. As the fourth step, security objectives are defined. Based on this preparation, the security functional
requirements and the assurance requirements are defined based on the requirements in ISO/IEC 15408. As
the 6th step, rationale of the defined functional and assurance requirements are checked.
Table 1 — Process of preparing a protection profile for EFC equipment
Step Description prepared by Toll service Contents
provider
1 Overview Overview of the description
2 Descriptions of the TOE An entity, an interface and necessity, security problems to be
addressed
3 Descriptions of the security environ- Threat analysis and security policies must be described concretely
ment
4 Security objectives How and what extends the security needs are to be met
5 Security functional and assurance The security functional requirements explain what must be done
requirements using requirements by the TOE and the environment of the TOE to meet the security
objectives. The assurance requirements explain the degree of con-
for the security functions provided in
fidence expected in the security functions of the TOE
ISO/IEC 15408.
6 Rationale Security Objectives and Security Requirements should be checked.
A PP may be registered publicly by the entity preparing the PP to make it known and available to other
parties that can use the same PP for their own EFC systems.
5.4 Relationship between actors
A security target (ST) represents a set of security requirements and specifications to be used as the basis
for evaluation of an identified TOE. While the PP can be looked upon as the EFC toll service provider’s
requirements, the ST can be looked upon as the relevant equipment’s supplier documentation for the
compliance of TOE with the PP (e.g. an OBE as the TOE).
Figure 3 shows a simplified picture and example of the relationships among toll service provider, the EFC
equipment supplier and an evaluator. The toll service provider prepares the PP and provides it to OBE
supplier to specify the security target to design and manufacturing the OBE. The PP is registered to National
Register for the future use for development of a new OBE. The OBE supplier prepares the ST and submits this
to the evaluator. The evaluator confirms the ST with the PP. After the evaluation, the OBE supplier designs
and manufactures the OBE.
[4]
NOTE The Common Criteria Recognition Arrangement includes provision for an international registrar.
ISO 17574:2026(en)
Figure 3 — Relationships among operators, suppliers and evaluators
The ST is similar to the PP, except that it contains additional implementation-specific information detailing
how the security requirements are realized in a particular product or system. Hence, the ST includes the
following parts not present in a PP:
— a TOE summary specification that presents the TOE-specific security functions and assurance measures;
— an optional PP part that explains PPs with which the ST is claimed to be conformant (if any);
— a justification containing additional evidence establishing that the TOE summary specifications ensure
satisfaction of the implementation-independent requirements and that claims about PP conformance are
satisfied;
— actual security functions of EFC products will be designed based on this ST (see example in Figure 4).
The PP is prepared by referring to ISO/IEC 15408 or the PP database. A new PP is registered in the PP
database. The ST of the OBE is prepared referring to the PP stored in the database.
ISO 17574:2026(en)
Figure 4 — Example of design based on a PP
6 Outline of protection profile (PP)
6.1 Structure
The content of a PP for a part or interface of an EFC system shall be in accordance with ISO/IEC 15408-1:2022,
Clause 10. An example is provided in Annex B.
a) Top page for title
b) Overview
c) Target of Evaluation
d) Conformance
e) Security Environment
f) Security Objectives
g) Security Requirements
h) Rationale
6.2 Context
Guidelines for preparing PP are as follows:
a) Overview (see A.1)
b) Target of evaluation (TOE, see A.2)
ISO 17574:2026(en)
The scope of the TOE shall be specified.
c) Conformance
The conformance claims of PPs shall be specified.
d) Security environment (see A.3)
Development, operation and control methods of the TOE are described to clarify the working and operation
requirements. Regarding these requirements, IT assets, for which the TOE must be protected, and the
security threats to which the TOE is exposed, shall be specified.
e) Security objectives (see A.4)
Security policies for threats to the TOE are determined. The policies are divided into technical, operational
and control policy.
Security objectives should be consistent with the operational aim or product purpose of the TOE.
Operational and control policies are defined as personnel and physical objectives applicable to the status, in
which the TOE is used or operated. The operational and control policy include control and operational rules
for operators.
f) Security requirements (see A.5)
In accordance with the security objectives specified in A.4, specific security requirements for security
threats stated in A.3 are specified. The security requirements consist of functional requirements and
assurance requirements for security quality.
Functional requirements are provided, selecting necessary requirements from ISO/IEC 15408-2 and
determining parameters, which shall be in accordance with ISO/IEC 15408-2:2022, Clause 6 to Clause 18.
Regarding assurance requirements, assurance requirements specified in ISO/IEC 15408-3 are adopted
by determining evaluation levels for assurance requirements, which shall be in accordance with
ISO/IEC 15408-3:2022, Clause 5 to Clause 15.
The evaluation method and activities are included in the security requirements, which shall be in accordance
with ISO/IEC 15408-4:2022, Clauses 5 and 6.
The evaluation assurance levels are included in the security requirements, which shall be in accordance
with ISO/IEC 15408-5:2022, Clause 4.
g) Rationale of justification and effectiveness (see A.6)
The content of PP is checked when necessary and covers security requirements for the TOE. The checked
items are as follows:
— all security environments needed are covered;
— security objectives should completely meet the security environments;
— security requirements should implement security objectives.
ISO 17574:2026(en)
Annex A
(informative)
Procedure to prepare the protection profile
A.1 Overview
A.1.1 General
A general outline of the protection profile (PP) is described in this annex.
This annex provides an example of how to prepare the security requirements for EFC relevant equipment, in
this case, an OBE with an ICC containing data needed for EFC.
A.1.2 Identification information
Identification information for the document with example is as follows:
a) document title
EXAMPLE 1 document title: OBE Security protection profile
b) version or release number
EXAMPLE 2 reference or version number: 1.0
c) preparation date
EXAMPLE 3 preparation date: 2002-10-20
d) name of the person responsible for preparing the PP document
EXAMPLE 4 prepared by: ABC Association
A.1.3 Target of evaluation (TOE) description
TOE in the prepared PP contains the following:
a) product
EXAMPLE 1 product: EFC OBE
b) version or release number
EXAMPLE 2 version or release number: 1.0
c) developer
EXAMPLE 3 developer: ABC Co., Ltd
A.1.4 In accordance with ISO/IEC 15408 (all parts)
The prepared PP according to ISO/IEC 15408 (all parts) and the edition of ISO/IEC 15408 are stated explicitly.
The PP shall be prepared according to the ISO/IEC 15408 series and its relation to the ISO/IEC 15408
series shall be stated in the PP. The statement of conformance includes conformance to each part of the
ISO/IEC 15408 series and state the relevant edition used.
ISO 17574:2026(en)
An example of conformance statement according to ISO/IEC 15408 (all parts) is shown as follows:
EXAMPLE
— ISO/IEC 15408-1:2022(Edition 4)
— ISO/IEC 15408-2:2022 (Edition 4)
— ISO/IEC 15408-3:2022 (Edition 4)
— ISO/IEC 15408-4:2022 (Edition 1)
— ISO/IEC 15408-5:2022 (Edition 1)
A.1.5 Outline of TOE
A.1.5.1 Type of TOE
For users of security PP a type of TOE described in PP is described explicitly to help them determine the
application.
EXAMPLE
Type of TOE: EFC OBE
A.1.5.2 TOE functional outline
For users of security PP, a type of device described in PP is described explicitly to help them determine the
application. Examples are as follows:
EXAMPLE
TOE functional outline of an OBE
a) EFC function:
1) mutual authentication with ICC;
2) transcription (caching) of ICC data to OBE;
3) encryption of radio communication with RSE;
4) assurance of message integrity;
5) mutual authentication with RSE;
6) storage of secured information (encryption key) used in OBE during EFC transaction.
b) Set-up function:
1) authentication of set-up card;
2) caching of vehicle information from ICC to OBE.
c) HMI function:
1) report of EFC billing results to users;
2) guidance of EFC lane.
ISO 17574:2026(en)
A.1.5.3 Evaluation Assurance Level (EAL)
Evaluation Assurance Levels for objectives are selected. Each EAL defines a package consisting of assurance
components and determines the degree of assurance requirements on security systems. The justification for
the selected EAL is stated.
EXAMPLE
EAL is 5 for the EFC OBE
OBE functions as equipment for e-Commerce in EFC transactions. The security systems of OBE are vulnerable to an
attack under the control of individual users. Therefore, a high assurance level (EAL) is needed for OBE.
A.2 Target of evaluation (TOE)
A.2.1 TOE objectives and methodology
A.2.1.1 TOE use objectives
The following example indicates objectives for TOE use and the type of environment in which it is used.
EXAMPLE EFC members (users) use the EFC system at tollgates by inserting the ICC with EFC member contract
information for settlement. Vehicle information such as an automobile inspection certification is stored in OBE
beforehand. For storing vehicle information, a personalization card for initialization is used. The OBE (TOE), which
reads/writes data to ICCs for set-ups/settlements and transmits/receives data to roadside equipment for toll collection
transactions, protects the interface and internal data from external threats.
A.2.1.2 TOE use methodology
The preparation and procedures of the TOE use methodologies are described as below.
a) User preparation; steps to be taken by user before use of TOE. An example is “User’s preparation: Users
request an operator to install an OBE and set up vehicle information such as automobile inspection
certification to OBE. In addition, users receive the ICC with EFC member contract information.”.
b) Operator’s preparation; necessary hardware/software and control systems are described when
operator operates TOE. An example is “Operator preparations: Operators issue set-up information in
response to user’s requests.”.
c) Operational procedures; procedures for operation and maintenance are described. An example is
“Operation procedures: When a user is passing through tollgates, the toll is billed to the ICCs for
settlement with EFC member contract information, which is inserted in the installed OBE with vehicle
information. When a legitimate ICC for settlement is inserted in the OBE with correct vehicle information,
the toll fee is calculated in the communication zone of RSE at tollgates. For a change or update of EFC
member contract information, such as vehicle information, set-up cards and ICC are updated (re-issued/
re-registered).”.
d) Use procedures; procedures for users are described. An example is “Use procedures: A user uses the
ICCs with EFC member contract information at tollgates within the EFC system according to the EFC
member contract or OBE manuals.”.
e) Limitations of use: limitations of use such as time zones and geographical zones are described. An
example for “Limitations of use is: In general, OBE is available at any time of day, as long as EFC lanes are
open at tollgates.”.
ISO 17574:2026(en)
A.2.2 TOE functions
A.2.2.1 Functions provided by TOE
The following example shows the functions for data transactions provided by the TOE which require
protection.
EXAMPLE
a) EFC transactions:
1) EFC communication control function;
2) non-secure data record function;
3) HMI input/output control function;
4) ICC insert status detect function;
5) OBE self-check function.
b) Security module:
1) data storage or protection function;
2) user access control function;
3) authentication function (DSRC, ICC);
4) encryption/decryption function;
5) ICC interface function;
6) EFC transaction interface function;
7) personalization card read function.
A.2.2.2 Functions not provided by TOE
When the TOE function is a part of the functions of an entire system, the scope of the TOE in the whole
system is shown in Figure A.1 which shows an example where the OBE is the scope of the TOE. For reference,
Figure A.2 is showing the overall security policy scope.
Figure A.1 — Example where the TOE is shown in its context
ISO 17574:2026(en)
Figure A.2 — Overall security policy scope
A.2.2.3 Missing functions
When functions, which usually should be provided by the TOE in subclause A.2.2, are not included in the
TOE, the function contents and reasoning for exclusion should be described.
A.2.3 TOE structure
A.2.3.1 Hardware structure
The structure with related hardware units on TOE operation is described. The scope of TOE in the structure
should be shown as in the example given in Figure A.3. Also, the overall EFC system model of the EFC Security
Framework should be shown as in Figure A.4.
Figure A.3 — Example of TOE hardware structure
ISO 17574:2026(en)
Figure A.4 — EFC system model of the EFC Security Framework
A.2.3.2 Software structure
The software structure of the TOE should be stated. The distribution of functions should be described,
especially when the operation of the TOE depends on the operating system (OS) and data control programs.
A.2.3.3 Rationale
It should be verified that the described items are consistent.
a) Absence of inconsistent provision items.
b) Absence of undefined or unclear sections of provided contents in this subclause.
A.3 Conformance
A.3.1 Conformance claim and conformance statement of TOE
A.3.1.1 General
Regarding conformance related to the PP, two kinds of relationships are defined. One is the relationship
between the PP and the based common criteria (CC), the other relationship is between the ST and the PP.
Regarding these relationships, both conformance claim and conformance statement are to be described.
ISO 17574:2026(en)
A.3.1.2 Conformance claim
Conformance claim is related to the relationship between the PP and the based CC.
a) Edition of the relevant parts of the CC is defined.
If all security functional requirements (SFRs) are based only upon functional requirement in ISO/IEC 15408-2
and ISO/IEC 15408-3, “conformant” should be selected otherwise “extended” should be selected.
EXAMPLE 1 Conforms with ISO/IEC 15408
b) Conformance to the CC Part2 is defined.
EXAMPLE 2 CC part2 conformant and extended
c) Conformance to the CC Part3 is defined.
EXAMPLE 3 CC part3 conformant and extended
d) Conformance claim rationale
Reason and logical basis of the choice of conformance claim is to be described.
A.3.1.3 Conformance statements
The conformance statement describes the way other PPs or STs shall conform to the PP. The conformance
statement shall be one of the three types of conformance:
— demonstrable,
— strict,
— exact.
EXAMPLE Conformance manner is “Strict”.
A.4 Security environment
A.4.1 General
Security requirements to determine security objectives for the TOE operation are provided.
A.4.2 Operational environments
A.4.2.1 General
The methodology of the use of the TOE such as the operational procedures, operational time, operational
sites, operational overview, use sites and limits and requirements are described.
A.4.2.2 Operational procedures
Regarding the operational procedures of the TOE, the operation of an integrated EFC system including the
related vehicles and ICC for payment are described.
A.4.2.3 Operational time
The operational time of the TOE is described.
EXAMPLE The operational time is any time that OBE equipped vehicles use roads tolled via EFC system
ISO 17574:2026(en)
A.4.2.4 Operational sites
Operational sites of the TOE are described.
A.4.2.5 Operational overview
The procedures from the purchase (obtain) to the disposal of the TOE by users are described including
installation of the TOE, set-up of the TOE and operation at toll roads.
EXAMPLE 1 Users purchase EFC OBE at OBE dealers (car dealers, car shops). An OBE is installed in a vehicle. In
addition, the on-board information needed for the EFC operation such as vehicle information is stored as on-board
information.
EXAMPLE 2 After an EFC member contract is established, users get an ICC, which is issued by credit card companies.
EXAMPLE 3 Users will be able to use the EFC system by inserting an ICC in an OBE installed in a vehicle.
EXAMPLE 4 Users use toll roads with the ICC inserted in an OBE in an OBE equipped vehicle and pass through the
tollgates without stopping.
EXAMPLE 5 Users can voluntarily dispose of unnecessary OBE.
A.4.2.6 Use sites
Sites, where users can use TOE, are described.
EXAMPLE Toll roads, along which EFC RSE are installed.
A.4.2.7 Limits and requirements
Limits and requirements in use such as available numbers of TOE are described.
EXAMPLE 1 The number of OBE installed per vehicle is limited to one.
EXAMPLE 2 OBE is fixed (built-in) in a vehicle.
EXAMPLE 3 OBE can be used any time of day as long as EFC lanes are open for operation.
A.4.3 Physical control
A.4.3.1 General
Physical control related to the operation of the TOE is described.
A.4.3.2 Installation sites and control
Installation sites and physical control of the TOE are described.
EXAMPLE 1 OBE is fixed (built-in) in a vehicle.
A.4.3.3 User unit
For use of the TOE, the physical control requirements of ICC for payments, which users possess, are described.
EXAMPLE 2 Users are responsible for their ICC.
ISO 17574:2026(en)
A.4.4 Personnel requirements
The personnel requirements for the responsibility and confidence of the TOE operations are described. In
addition, the requirements for potential uses, motivations, methods and expertise of attacks are provided.
a) TOE-related agents
The following items regarding the manufacturers, operators and users of TOE are stated.
1) Type
2) Role
3) Authorization
4) Reliance
5) Risk of illicit use
6) Expertise
7) Trail
EXAMPLE 1
Personnel requirements:
Type: Manufacturer of OBE.
Role: Manufacturing and shipping based on standard specification of EFC OBE.
Authorization: None.
Reliance: No responsibility for security control.
Risk of illicit use: There are risks of illicit use since the responsibility for security control is absent.
Expertise: No need of expertise for security.
Trail: Negative list check is implemented while OBE equipped vehicle are passing through
tollgates.
b) Attackers
The following items are described for illicit user requirements against which countermeasures are
taken by the TOE.
1) Type
2) Purpose of illicit use
3) Motivation
4) Means
5) Expertise
EXAMPLE 2 Attackers:
— Type: Illicit third party among EFC users.
— Purpose of illicit use: OBE data forgery, manipulation, obtaining of personal information. Forgery and illicit
modification of OBE medium.
— Motivation: To reduce toll fees or avoid toll fee claims by illicit use of information. Sale of forged OBE.
ISO 17574:2026(en)
— Means: Forgery of vehicle information on OBE. Forgery of interface data between OBE and ICC to counterfeit
someone’s card. Forgery of EFC OBE by analysing OBE internally.
— Expertise: Comprehend the internal transaction by analysing EFC OBE internally.
A.4.5 Connectivity and operational environments
The environment for TOE connectivity and operation is provided. Only the structure, which is provided in
this subclause, shall be TOE.
a) Connectivity; Transactions for RSE at tollgates and ICC needed for the operation of the TOE are
described. An example is:
EXAMPLE Connectivity:
— OBE exchanges information via radio communication (5,8 GHz) with RSE at tollgates.
— OBE reads ICC data (card number, EFC member contract information) before the vehicle passes through a
toll
...



