Take-Aways (AI)
  • Cloud use is per­mit­ted pro­vi­ded avai­la­bi­li­ty, relia­bi­li­ty and secu­ri­ty are ensu­red fol­lo­wing a risk assessment.
  • Nine requi­re­ments demand cloud gover­nan­ce: sce­na­rio ana­ly­sis, risk assess­ment, decis­i­on-making aut­ho­ri­ty, con­trac­tu­al regu­la­ti­ons and documentation.
  • BAV will moni­tor imple­men­ta­ti­on in future, with a focus on sup­plier manage­ment and busi­ness con­ti­nui­ty management.

The Fede­ral Office of Trans­port FOT on April 23, 2025 Indu­stry let­ter on cloud com­pu­ting for rail­road appli­ca­ti­ons to the rail­road under­ta­kings. The let­ter spe­ci­fi­es the exi­sting requi­re­ments of the Rail­road Ordi­nan­ce (EBV) and the Imple­men­ting regu­la­ti­ons (AB-EBV) for the use of clouds.

The exi­sting requi­re­ments do not expli­ci­t­ly regu­la­te cloud com­pu­ting. The use of clouds in rail­road appli­ca­ti­ons is the­r­e­fo­re per­mit­ted if the gene­ral requi­re­ments for avai­la­bi­li­ty, relia­bi­li­ty and secu­ri­ty, among others, are met. The FOT the­r­e­fo­re requi­res an assess­ment of the risk of cloud fail­ure, among other things, befo­re use. The FOT then for­mu­la­tes nine requi­re­ments (Cloud‑1 to Cloud‑9), which requi­re cloud gover­nan­ce from the com­pa­nies cover­ed and which can be gene­ra­li­zed bey­ond the rail­road sector:

  • Sce­na­rio ana­ly­sis (Cloud‑1): Sce­na­ri­os for inci­dents with secu­ri­ty or avai­la­bi­li­ty-rele­vant effects must be syste­ma­ti­cal­ly iden­ti­fi­ed. Taking into account the enti­re sup­p­ly chain, the fol­lo­wing in par­ti­cu­lar must be con­side­red: tech­ni­cal fail­ures, fail­ures due to mis­con­duct, cyber inci­dents (inclu­ding sabo­ta­ge and insi­der attacks) and willful ser­vice inter­rup­ti­ons by the ser­vice pro­vi­der, e.g. on the orders of a poli­ti­cal authority.
  • Risk assess­ment (Cloud‑2 to Cloud‑4): The pro­ba­bi­li­ty and ext­ent of the iden­ti­fi­ed inci­dents must be deter­mi­ned, com­pen­sa­to­ry mea­su­res (fall-back levels) to safe­guard rail ope­ra­ti­ons must be inve­sti­ga­ted and, taking into account the syste­mic importance of the com­pa­ny, it must be asses­sed whe­ther the resi­du­al risk can be accepted.
  • Gover­nan­ce (Cloud‑5): The decis­i­on to use the cloud must be based on the risk assess­ment by a sui­ta­ble body within the com­pa­ny. This decis­i­on must be review­ed peri­odi­cal­ly and in the event of rele­vant changes.
  • Con­tract design (Cloud‑6): The requi­re­ments for the cloud, both func­tion­al and non-func­tion­al (e.g. pro­ce­s­ses for report­ing inci­dents), must be defi­ned and set out in a con­tract with the ser­vice provider.
  • Docu­men­ta­ti­on (Cloud‑7 to Cloud‑9): The risk assess­ment and the decis­i­on must be docu­men­ted and made available to the FOT on request. The inclu­si­on of the pro­cess in the manage­ment system must be review­ed. In addi­ti­on, a detail­ed over­view must be kept of all clouds used that are rele­vant to ope­ra­ti­ons or security.

In future, the FOT intends to review imple­men­ta­ti­on as part of its super­vi­so­ry acti­vi­ties, both at the pro­ce­du­ral level (plan­ning appr­ovals, type appr­ovals) and in terms of moni­to­ring (audits, ope­ra­tio­nal checks). A par­ti­cu­lar focus will be pla­ced on the topics of sup­plier manage­ment and busi­ness con­ti­nui­ty management.