Skip to main content

Tattile gains double cybersecurity certification

IEC-62443 and ISO-27001 cover software and infrastructure IT security
By Adam Hill January 25, 2024 Read time: 2 mins
Tattile: certified

Tattile has achieved two key cybersecurity certifications for its products: IEC-62443 (focused on software security) and ISO-27001 (infrastructure IT security).

The Italian company, which specialises in cameras for ITS applications, warns that security bugs are growing, and cites research from Cybersecurity Ventures that the global annual cost of cybercrime is estimated to exceed $20 trillion by 2026.

ANPR cameras are not exempt from cyberattacks for several reasons, the manufacturer says: "Being placed in public areas, they could be approached by ill-intentioned people. Working inside the interconnection of networks, cameras can be part of larger systems and interconnected with other devices and systems."

Cameras may be vulnerable to unknown threats if they don't receive regular updates from the manufacturer or users due to software and firmware vulnerabilities, Tattile adds.

The company developed its Stark software platform from scratch, using the DevSecOps methodology and says it planned from the start to achieve the double cybersecurity certification.

IEC-62443 been established by several global testing, inspection and certification bodies, defining elements such as test methods, surveillance audit policies and public documentation policies. 

Tattile says the DevSecOps methodology reduces risk via dedicated tools that continuously analyse all the code bases, and ensures products are secure by design.

Also, as new cyberattacks continue to emerge, security patches and related software updates need to be applied to the system: Stark by Tattile provides "at least 12 annual updates", the company says.

Meanwhile, ISO/IEC-27001:2013 (ISO-27001) ensures that the processing of information (including data provided by customers) is compliant with international standards such as GDPR.

For more information on companies in this article

Related Content

  • US incident management needs national standardisation
    January 26, 2012
    I-95 Corridor Coalition's Tom Martin discusses the state of the art in incident management and what visitors to this year's ITS World Congress can expect of the first ever Emergency Responder-Incident Management Day. Developments in incident management are driven in the main by need. A bald statement, and one which holds no surprises, it nevertheless quantifies the evolutionary process within the I-95 Corridor Coalition over the last decade and more. Spread over 16 states from Maine to Florida, the Coalitio
  • Next Generation 911, updating the US 911 emergency system
    February 1, 2012
    Continuing developments in telecommunications and public expectation have left the US's legacy, analogue 911 emergency call system trailing. Linda D. Dodge, Public Safety Program Manager for the ITS programme in USDOT's Research and Innovative Technology Administration, the sponsor of the Next Generation 911 initiative, writes about efforts towards updating
  • Monitoring, detection and control systems inside tunnels can do much to improve traveller safety
    August 6, 2013
    ITS technology can do a great deal to improve tunnel safety, as Colin Sowman discovers. It was back in April 2004 that the European Parliament adopted the EU Directive which lays down the Minimum Safety Requirements for Tunnels in the Trans-European Road Network (2004/54/EC). This was the first unitary legislation setting minimum safety standards for European road tunnels and was designed to harmonise the management of tunnel safety at a national level. Operators of existing tunnels have until 30 April 201
  • Benefits of traffic data sharing with app developers
    November 10, 2015
    Timothy Compston finds out if exchanging traffic and road condition data with private app developers makes sense for both drivers and road authorities. Much has been said about the potential benefits for authorities in sharing data with traffic and navigation app developers, and receiving ‘crowdsourced’ information in return – so how is it working in practice?