Conformity assessment
The requirement for mandatory confirmation of compliance with functional and information security requirements is stipulated by Federal Law on Technical Regulation No. 184-FZ.
Technical regulations require mandatory confirmation of compliance of automated railway control system software (ARCS software) by registering a declaration of conformity and involving an accredited laboratory in testing.
ARCS software should be permitted for operation only if a positive conclusion is received from a testing laboratory (center) confirming the software's compliance with established requirements and a declaration of conformity is registered with the requirements of the Technical Regulations and other regulatory documents.
There are two ways of mandatory confirmation of compliance:
- Declaration of Conformity — a form of confirmation of conformity, in which compliance with the requirements of TR TS is ensured by the applicant registering a declaration of conformity. The declaration is accepted either on the basis of the applicant's own evidence or combined with evidence obtained with the involvement of an accredited party.
- Certification — a form of confirmation of conformity, in which compliance with the requirements of TR CU is ensured by the presence of a certificate of conformity. In this case, product testing is carried out exclusively by the certification body / testing laboratory.
The information security assessment of automated railway control system software is conducted:
- through certification in the FSTEC certification system of Russia;
- through testing conducted by competent testing laboratories, which results in an expert opinion from the certification body for information security tools in railway transport (ISP) and registration of confirmation of the compliance of the automated railway control system software with information security requirements in the Register of Railway Transport Software that has passed the assessment of compliance with information security requirements (Register), maintained by the ISP.