- Cloud use is permitted provided availability, reliability and security are ensured following a risk assessment.
- Nine requirements demand cloud governance: scenario analysis, risk assessment, decision-making authority, contractual regulations and documentation.
- BAV will monitor implementation in future, with a focus on supplier management and business continuity management.
The Federal Office of Transport FOT on April 23, 2025 Industry letter on cloud computing for railroad applications to the railroad undertakings. The letter specifies the existing requirements of the Railroad Ordinance (EBV) and the Implementing regulations (AB-EBV) for the use of clouds.
The existing requirements do not explicitly regulate cloud computing. The use of clouds in railroad applications is therefore permitted if the general requirements for availability, reliability and security, among others, are met. The FOT therefore requires an assessment of the risk of cloud failure, among other things, before use. The FOT then formulates nine requirements (Cloud‑1 to Cloud‑9), which require cloud governance from the companies covered and which can be generalized beyond the railroad sector:
- Scenario analysis (Cloud‑1): Scenarios for incidents with security or availability-relevant effects must be systematically identified. Taking into account the entire supply chain, the following in particular must be considered: technical failures, failures due to misconduct, cyber incidents (including sabotage and insider attacks) and willful service interruptions by the service provider, e.g. on the orders of a political authority.
- Risk assessment (Cloud‑2 to Cloud‑4): The probability and extent of the identified incidents must be determined, compensatory measures (fall-back levels) to safeguard rail operations must be investigated and, taking into account the systemic importance of the company, it must be assessed whether the residual risk can be accepted.
- Governance (Cloud‑5): The decision to use the cloud must be based on the risk assessment by a suitable body within the company. This decision must be reviewed periodically and in the event of relevant changes.
- Contract design (Cloud‑6): The requirements for the cloud, both functional and non-functional (e.g. processes for reporting incidents), must be defined and set out in a contract with the service provider.
- Documentation (Cloud‑7 to Cloud‑9): The risk assessment and the decision must be documented and made available to the FOT on request. The inclusion of the process in the management system must be reviewed. In addition, a detailed overview must be kept of all clouds used that are relevant to operations or security.
In future, the FOT intends to review implementation as part of its supervisory activities, both at the procedural level (planning approvals, type approvals) and in terms of monitoring (audits, operational checks). A particular focus will be placed on the topics of supplier management and business continuity management.