Germany – Research and development services and related consultancy services – Research Project - DZSF - Evaluation of the Potential of Sector-Specific Cybersecurity Profiles
Railway-specific cybersecurity profiles define suitable requirements and specifications for certain processes or components in modules comparable to the BSI IT-Grundschutz. It is to be determined to what extent these can accelerate secu
Opportunity description
Railway-specific cybersecurity profiles define suitable requirements and specifications for certain processes or components in modules comparable to the BSI IT-Grundschutz. It is to be determined to what extent these can accelerate security engineering, as well as simplify and improve the secure operation of systems in the railway sector, and for which parts of the railway sector the comprehensive development of such profiles would be worthwhile. Digitalization and the increasing threat landscape make cybersecurity in the critical railway infrastructure particularly important. System complexity, regulatory requirements (e.g. NIS2, CRA), and the need for specialist knowledge are growing. Standards such as ISO/IEC 27000, Common Criteria and IEC 62443, or more specifically CLC/TS 50701, provide a comprehensive framework, but are extensive and leave considerable room for interpretation, meaning that individual risk assessments remain labor-intensive. BSI IT-Grundschutz demonstrates by example how standardized modules can bundle general requirements for typical processes/systems and thereby simplify engineering and operation. However, there has not yet been a similar dedicated concept for the railway system. The EU-Rail System Pillar approach, on the other hand, provides specifications that are as precise as possible for a generic system model. Railway-specific cybersecurity profiles could combine the advantages of both concepts. See information under point 2 "Procedure" Procedure: open. Estimated value: 126,805.14 EUR. Review the original TED notice for the complete requirement, lots, amendments and attachments.
Business details are available after sign in
Codes, capabilities, evidence, buyer details and marketplace actions are withheld from the public HTML and API response.