IT Risk Management

profiledananjayad2@
AnnexII-RiskAssessmentSpreadsheet.xlsx

Intro

Flying 2.0 Enabling automated air travel by identifying and addressing the challenges of IoT & RFID technology ANNEX III – Risk Assessment Spreadsheet

Metrics

Metrics [scales used to assess assets, vulnerabilties, threats and risks]
Asset Value Measurement Scale
Value Magnitude
1 Very Low
2 Low
3 Medium
4 High
5 Very High
Threat Value Measurement Scale
Value Description
1 Very Low
2 Low
3 Medium
4 High
5 Very High
Vulnerability Value Measurement Scale
Value Description
1 Very Low
2 Low
3 Medium
4 High
5 Very High
Information Security Risk Measurement Scale
Minimum Risk Maximum Risk
1 2 3 4 5 6 7 8 9 10 11 12 13
Very Low Low Medium High Very High
Risk Assessment Scale
Vulnerability Value 1 2 3 4 5
Threat Value 1 2 3 4 5 1 2 3 4 5 1 2 3 4 5 1 2 3 4 5 1 2 3 4 5
Asset Value 1 0 1 2 3 4 2 3 4 5 6 3 4 5 6 7 4 5 6 7 8 5 6 7 8 9
2 1 2 3 4 5 3 4 5 6 7 4 5 6 7 8 5 6 7 8 9 6 7 8 9 10
3 2 3 4 5 6 4 5 6 7 8 5 6 7 8 9 6 7 8 9 10 7 8 9 10 11
4 3 4 5 6 7 5 6 7 8 9 6 7 8 9 10 7 8 9 10 11 8 9 10 11 12
5 4 5 6 7 8 6 7 8 9 10 7 8 9 10 11 8 9 10 11 12 9 10 11 12 13

Assets

Assets [tangible or intangible: any devices, technologies, applications, processes, data of value ]
ID Asset Description or reference to above described elements Owner [involved actors / organisations] Value Impact Areas (as in worksheet "Impact Areas")
Intangible IA1 IA2 IA3 IA4 IA5 IA6 IA7 IA8 IA9 IA10 IA11
A1 Automated reservation, check-in and boarding procedure Controls the entrance of passengers into the restricted area of the airport and finally to the aircraft Airport, airlines, citizens 4 2 4 2 2 3 3 3 4 2 3 3
A2 Electronic visa issuing process Process of getting a visa and linking with check-in [not mandatory at this stage] State, citizens 4 2 4 3 2 3 4 3 4 2 3 3
A3 Luggage and goods handling Process for managing the flow of luggage and supplies to shops and airport operations Airlines, airport 3 2 3 2 1 2 2 3 3 2 3 3
A4 Automated traffic management Getting to and from the airport; smart routing; does not include air traffic management Airport, state, commercial operators 4 2 3 1 1 2 2 2 4 2 2 2
A5 Passports and National ID cards Passports and national ID cards RFID-equipped, with digital photo and biometrics (fingerprint). The devices may store the following data: - Personal data - Biometrics, such as facial image, fingeprints State/national authority issuing it, citizen/passenger 4 2 4 3 2 3 4 3 4 2 4 2
A6 Mobile ‘smart’ devices Small computing devices that allow the transmission of voice and data. Functions integrated usually in one device: Mobile phone, digital camera (working also as 2D barcode reader), NFC reader/tag, Bluetooth, LCD (2D barcode can be displayed), GNSS receiver. Smart phones, PDAs, laptops, e-book reader etc. The devices may store the following data: - Personal data - Personal preferences - Location data - Electronic boarding passes - Electronic visa They may also store and/or generate - Non-personal data - Passports and National ID cards - Passenger Name Record data Citizen/passenger For electronic boarding passes and /or visas, the owner could also be the airline company and state, respectively. 4 2 4 2 2 2 3 3 4 3 3 3
A7 Health monitoring devices Allergy bracelet Implants / In body monitoring sensors. Airline seat sensors. he devices may store the following data: - Personal data - Health data Citizen/passenger, airlines, airports 5 5 2 3 2 2 2 2 3 2 4 2
A8 Travel documents (paper) Paper versions of tickets and boarding passes. May contain the following data: - Personal data - Location data - Non-personal data Citizen/passenger, airline company 3 2 3 2 2 3 3 1 3 2 3 2
A9 RFID & barcode readers Readers in automatic check-in kiosks, security control, etc as well as passenger mobile devices State, Airport authorities, airlines, companies, passengers 4 2 3 2 1 2 4 2 3 2 3 2
A10 Credit Cards/Debit card/Payment cards/'e-wallet' RFID-enabled or not. Used to make transactions. Citizen/passenger, issuing bank 4 2 4 2 2 2 2 4 4 2 4 3
A11 Other RFID cards Transport systems and small payments cards, frequent-flyer RFID-based cards. Issuing companies and authorities, passengers 3 2 3 2 1 1 2 2 3 2 2 2
A12 Scanners & detectors Liquids and gels (LAG) detectors; Body scanners Airports, State, Security companies 3 2 3 3 2 2 2 2 2 1 3 2
A13 Networks Wi-Fi, WiMax, conventional broadband, ZIGBEE, smart dust mesh networks, etc Service providers, including airports and airlines 4 2 4 3 2 2 2 3 3 3 4 2
A14 State databases Database containing data on passengers held by the State authorities for official travel purposes. State, International bodies (SIS, Interpol, Europol) 4 3 3 4 4 4 3 2 2 2 4 2
A15 Commercial and other databases Databases containing data on passengers held by others not related to the State databases in A14. Companies, shops, travel agencies 4 2 3 4 3 3 1 2 3 2 3 3
A16 Temporary handset airport guides Device given to passengers to help them navigate the airport and to provide translation facility Airport management 2 1 2 2 2 1 2 2 2 2 1 1
A17 Luggage and goods The passengers’ luggage. Citizen/passenger, shops 3 2 3 2 2 1 2 2 3 2 2 2
A18 Check-in infrastructure Check-in desks, kiosks etc. Airlines, airport 3 2 3 2 2 2 3 3 3 2 2 2
A19 Airport facilities All the physical facilities of the airport; includes also shops, stands, information desks etc. Shops, airports 3 1 3 2 1 1 2 3 3 2 2 3
A20 Cars / vehicles Cars /vehicles used in the scenario Citizens / state 4 3 3 1 1 1 4 2 4 1 1 3
A1 4 A1. Automated reservation, check-in and boarding procedure
A2 4 A2. Electronic visa issuing process
A3 3 A3. Luggage and goods handling
A4 4 A4. Automated traffic management
A5 4 A5. Passports and National ID cards
A6 4 A6. Mobile ‘smart’ devices
A7 5 A7. Health monitoring devices
A8 3 A8. Travel documents (paper)
A9 4 A9. RFID & barcode readers
A10 4 A10. Credit Cards/Debit card/Payment cards/'e-wallet'
A11 3 A11. Other RFID cards
A12 3 A12. Scanners & detectors
A13 4 A13. Networks
A14 4 A14. State databases
A15 4 A15. Commercial and other databases
A16 2 A16. Temporary handset airport guides
A17 3 A17. Luggage and goods
A18 3 A18. Check-in infrastructure
A19 3 A19. Airport facilities
A20 4 A20. Cars / vehicles

Impact Areas

Impact Areas [estimation of impact of the identified threats; it is closely related to the asset value, so you need to consider that]
No. Impact Description
I01 Health / Life / Safety Refers to the physical and psychological condition of an individual; his/her physical and psychological well-being and absence of disease.
I02 Time / efficiency Time needed to check-in, security controls or boarding
I03 Human rights Human rights, e.g. privacy, autonomy, non-discrimination, dignity
I04 Social values Social inclusion, e-inclusion, trusted human relationships, etc.
I05 Legal and regulatory Existing legal regulatory framework needs to be respected. It foresees consequences for violations and for failure to fulfil the obligations foreseeen in it. It delineates the passenger rights. PNR is also based on bilateral/international agreements on the transfer of information of the passengers.
I06 Mobility of individuals The ability and potential of people to move across countries.
I07 Financial / economical Cost considerations for airlines, airports, companies and individuals
I08 Comfort, convenience and ease of access Smooth processes, services on demand, usability. The provision of services for people with usabilities
I09 Interoperability Interoperability between networks, sensors, devices, organisations, passengers and users is central to the scenario. An IoT like network will depend on a high level of interoperability between all of the different contexts and situations in which devices will need to communicate. However interoperable networks carry with them significant risks and issues, such as privacy, access controls, access to data, secondary and primary uses of data and data 'shelf' life. These would be apart from the technical problems such as standardisation in network protocols for example. Interoperable networks may also provide more room for fraud or other criminal activity in that compromising one part may allow unauthorised access to another. The same is true if interoperability extends to interdependency in the case of failures and problems.
I10 Trust Trust is essential in all aspects of the scenario. Passengers must trust the information on their devices. Operators must trust personal data provided, and information provided to them by other operators. Trust is also needed in the automated procedures by airlines and airport operators. And border authorities must likewise trust in the systems to perform.
I11 Business activities

Implemented controls

Implemented Controls [existing safeguards etc. already in place and that need to be considered. These may be found in the assumptions for example]
Existing Control ID Control Description Control Category Control Nature Affected Assets
C1 Multiple ways of getting to the airport (personal vehicle, buses, taxis, trains etc): intermodality Containment & Recovery Semi - automated A1. Automated reservation, checking and boarding procedure
C2 Comparison of individuals physical traits with those documented on a valid official document (passport, national ID card, crew pass, personnel pass) for identification and authentication purposes Preventive Manual A1. Automated reservation, checking and boarding procedure
C3 Automatic authentication of passengers by means of their biometric features Preventive Automated A1. Automated reservation, checking and boarding procedure
C4 Authorisation of passengers by a paper boarding pass and verified by the airline personnel Preventive Manual A1. Automated reservation, checking and boarding procedure
C5 Authorisation of passengers by electronic boarding pass verified by the departure control system of the airline Preventive Automated A1. Automated reservation, checking and boarding procedure
C6 Valid crew or airport personnel pass with digital photo Preventive Automated A1. Automated reservation, checking and boarding procedure
C7 Security checks in smart corridors with metal detectors, EDS and LAG detectors Detective Preventive Automated A1. Automated reservation, checking and boarding procedure
C8 Airport security monitoring and emergencies identification through the usage of smart devices Detective Corrective Automated A1. Automated reservation, checking and boarding procedure
C8 Airport security monitoring and emergencies identification through the usage of smart devices Detective Corrective Automated A19. Airport facilities
C8 Airport security monitoring and emergencies identification through the usage of smart devices Detective Corrective Automated A18. Check-in infrastructure
C9 Departure Control System (DCS) Preventive Automated A1. Automated reservation, checking and boarding procedure
C10 Verification of only one person in the booth Deterrent Preventive Automated A1. Automated reservation, checking and boarding procedure
C11 Global Entry System authentication for schengen visa holders using PNR Preventive Automated A1. Automated reservation, checking and boarding procedure
C12 Communication of the payment transaction record to the shuttle service operator Preventive Automated A4. Automated traffic management
C13 Sharing and co - ordination of traffic data Preventive Deterrent Automated A4. Automated traffic management
C14 Automobile's licence plate number capture by the digital video camera and respective record storage Detective Automated A4. Automated traffic management
C15 Website RFID tags on purchased goods for identification of the rightful owner Preventive Detective Automated A3. Luggage and goods handling
C15 Website RFID tags on purchased goods for identification of the rightful owner Preventive Detective Automated A17. Luggage and goods
C16 Reception of purchased goods after scanning the boarding pass on a specific reader inside the plane Preventive Detective Automated A3. Luggage and goods handling
C17 Reception of purchased goods after scanning the boarding pass on a specific reader inside the plane Preventive Detective Automated A17. Luggage and goods
C17 Automated return of unused credit from TfL Corrective Automated A10. Credit Cards/Debit card/Payment cards/'e-wallet'
C18 Flight confirmation during goods purchase Detective Preventive Automated A3. Luggage and goods handling
C18 Flight confirmation during goods purchase Detective Preventive Automated A17. Luggage and goods
C19 GPI RFID chip Preventive Automated A6 Mobile 'smart' devices
C20 GA message for boarding Corrective Preventive Automated A1. Automated reservation, checking and boarding procedure
C21 Special seats embedded with pressure and temperature sensors on aircraft Detective Automated A7 Health monitoring devices
C22 SMS record kept by taxi service as a proof Detective Automated A4 Automated Traffic Management

Vulnerabilities

Vulnerabilities [of the tangible / intangible assets]
No Vulnerability Description Exposure [Metric Values are 1-5]* Severity [Metric Values are 1-5]* Vulnerability Assessment Value* Comments / Additional Info
V1 Inappropriate design of procedures 3 4 2.4 This vulnerability could be due to lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures), etc. V1. Inappropriate design of procedures V1 V1.
V2 Excessive dependency on IT systems, network and external infrastructure 4 3 2.4 An excessive dependency arises when one relies on IT systems. It is a sort of "mug's game" in the sense that virtually every system will fail to a lesser or greater extent at some point or other. V2. Excessive dependency on IT systems, network and external infrastructure V2 V2.
V3 Lack of back-up / failover procedures 3 3 1.8 When things do go wrong, there is no adequate back-up system in place to take over. Availability/robustness has not been considered in the system design, , or appropriate failure modes have not been addressed. V3. Lack of back-up / failover procedures V3 V3.
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 2 4 1.6 This includes unfriendly authentication mechanisms, too frequent requests for password change, too quick automatic log-offs, etc. This vulnerability may also arise because there has not been sufficient training given to staff in detecting and understanding security threats. V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4 V4.
V5 Lack of usability / unfriendly user interface(s) of device(s) 3 3 1.8 This vulnerability is due to the difficulty of using device interfaces. The interfaces are not intuitive or user friendly. It may arise from excessive or unnecessary functionality options available to the users. A device may be too complicated for ease of use. V5. Lack of usability / unfriendly user interface(s) of device(s) V5 V5.
V6 Lack of interoperability between devices and/or technologies and/or systems 3 4 2.4 A simple example of the lack of interoperability appears when the RFID reader at the airport cannot write data to the RFID tag on Akira's suitcase. This vulnerability is depending on the governance. V6. Lack of interoperability between devices and/or technologies and/or systems V6 V6.
V7 Collected data is insufficient or incorrect [lack of adequate controls at data entry] 3 4 2.4 This vulnerability arises when systems do not collect enough or appropriate data or garble the data they do collect. For example, the data collected by passenger name records (PNR) may not be sufficient to identify a terrorist or an improper entry on no-fly lists, incorrect entries in relation to visa status, and mistaken identification of individuals by commercial entities V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7 V7.
V8 Dependency on power systems 4 3 2.4 If a natural disaster, for example, disrupts an airport's power system, everything comes to a halt. V8. Dependency on power systems V8 V8.
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 3 3 1.8 This vulnerability may refer to systems, devices, data access or network access. This also includes authentication of RFID and RFID readers, and since many RFIDs are writeable, this may increase the vulnerability. V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls V9 V9.
V10 Flawed/insufficient design and/or capacity of devices and systems 2 2 0.8 Poorly designed devices or systems may create a vulnerability, whereby they are not sufficiently robust or resilient to withstand attacks by hackers (for example) or they may not do what is expected of them, especially at critical times. V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10.
V11 Lack of adequate controls in biometrics' enrolment stage 3 2 1.2 Biometrics are not 100 per cent reliable. Part of the reason why they are not may occur at the enrolment stage when an individual's iris or fingerprints or other feature are scanned. V11. Lack of adequate controls in biometrics' enrolment stage V11 V11.
V12 Lack of harmonisation and interoperability of procedures 2 2 0.8 Security or other procedures may vary from one airport to another, creating opportunities for evil-doers. V12. Lack of harmonisation and interoperability of procedures V12 V12.
V13 Lack of or inappropriate protection of RFID tags 2 3 1.2 V13. Lack of or inappropriate protection of RFID tags V13 V13.
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] 3 4 2.4 It's often been said that the weakest link in any system is human. If personnel are inadequately trained, they become a vulnerability. They need to be trained adequately to detect and understand security threats and what to do in the event of a system malfunction. V14. Lack of sufficiently skilled and/or trained personnel [airport, airline] V14 V14.
V15 Insufficient equipment 2 5 2 Airports with insufficient equipment may create a security vulnerability. The vulnerability might also pose problems to the efficient processing of passengers from check-in to boarding. V15. Insufficient equipment V15 V15.
V16 Inappropriate expansion of the trust perimeter 2 3 1.2 Too many people may have access to personal information. Often the biggest threat comes from insiders. V16. Inappropriate expansion of the trust perimeter V16 V16.
V17 Lack of dependable sensors, GPS 2 3 1.2 V17. Lack of dependable sensors, GPS V17 V17.
V18 Lack of respect to the data minimisation and proportionality principles 2 2 0.8 The data collected and processed shall be adequate, relevant and not excessive in relation to the purposes they are collected. An example of such lack of respect to the data minimisation and proportionality principles can be mentioned the case, when an LBS system collects not only the information absolutely needed for the provision of the service, but it also stores excessive information. The need-to-know principle is not enforced by any means. V18. Lack of respect to the data minimisation and proportionality principles V18 V18.
V19 Lack of respect to the purpose limitation (finality principle) 4 4 3.2 When the purpose limitation principle is not respected, more data are collected and processed than is strictly necessary the specified purpose. For instance, Christina's approximate physical location is revealed to both the cell communication provider as well as the navigation service that provides the map and traffic conditions applications. V19. Lack of respect to the purpose limitation (finality principle) V19 V19.
V20 Lack of respect to the transparency principle 4 4 3.2 Lack of respect to the transparency principle means that the data subject is not able to determine the relevant data processing practices. In the IoT a lot of information is transmitted and processed via automated processes, most of which remain unnoticed by the data subject. V20. Lack of respect to the transparency principle V20 V20.
V21 Inappropriate / inadequate identity management 3 3 1.8 While the traffic and local map are being downloaded in real time, Christina's approximate physical location is revealed to both the cell communication provider as well as the navigation service that provides the map and traffic conditions applications. Appropriate identity management would protect Christina's privacy in this case. V21. Inappropriate / inadequate identity management V21 V21.
V22 Inadequacy of RF traffic regulations 2 4 1.6 V22. Inadequacy of RF traffic regulations V22 V22.
V23 Over dependency on biometrics 2 2 0.8 Biometric identification has relatively high error rates (especially automatic face recognition). Also modern biometric sensors (especially fingerprint and iris sensors) are difficult to compromise ('liveness detection'), still is also possible to spoof them. Awareness of imperfection of biometric systems is an important factor of overall security [P. Rotter (ed.) Biometrics Deployment Study. Large-scale biometrics deployment in Europe. Identifying challenges and threats. JRC-IPTS report EUR 23564 EN 2008, ISBN 978-92-79-10657-6. Available at: http://ftp.jrc.es/EURdoc/JRC48622.pdf V23. Over dependency on biometrics V23 V23.
V24 2 2 0.8 V24. V24 V24.
V25 Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (especially for RFID tags) 3 4 2.4 Inherent vulnerability of cards and devices (passports, RFID tags, etc.): they are small in size, and they are easy to lose, be stolen and/or copied. V25. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (especially for RFID tags) V25 V25.
V26 Actual RFID range longer than standard 2 3 1.2 Malicious RFID readers may be able to operate from a distance several times longer than the intended range (Kirschenbaum & Wool 2006). Moreover, shielding of RFID is often not possible. V26. Actual RFID range longer than standard V26 V26.
V27 RFID tags do not have a turn-off option 2 2 0.8 Unlike mobile phones or PDAs, most RFID tags cannot be turned off and are always ready to send data for a request received by radio waves. This feature is an inherent vulnerability. V27. RFID tags do not have a turn-off option V27 V27.
V28 Insufficient protection against reverse engineering 2 2 0.8 In RFID and contactless smart cards, due to limited resources, the methods for protection against reverse engineering, such as dummy structures, scramble buses and memory cells, etc., are rarely applied. Active methods for detection of reverse engineering attack are impractical in these devices. V28. Insufficient protection against reverse engineering V28 V28.
V29 Inadequate security measures of data storage (e.g. inadequate encryption measures) 3 1 0.6 In case RFID and contactless smart cards, due to limited resources, manufacturers often apply light cryptography and proprietary cryptographic methods. V29. Inadequate security measures of data storage (e.g. inadequate encryption measures) V29 V29.
V30 Over-sensitivity of devices (generating many false alarms) 2 2 0.8 Some devices are not 100 per cent reliable. They may produce inaccurate results or make false positives or negatives. V30. Over-sensitivity of devices (generating many false alarms) V30 V30.
V31 Sensitivity to magnetic fields 2 3 1.2 V31. Sensitivity to magnetic fields V31 V31.
V32 Devices & equipment used in unprotected environments 3 3 1.8 Devices used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] V32. Devices & equipment used in unprotected environments V32 V32.
V33 High error rates of biometric identification (esp. face-based recognition) 3 3 1.8 Face-based identification has the highest social acceptance among all biometric identification methods. Unfortunately, it has also high error rates, which leads to many false alarms and/or false acceptances. V33. High error rates of biometric identification (esp. face-based recognition) V33 V33.
V34 Communication of data over unprotected or publicly accessible channels 3 3 1.8 V34. Communication of data over unprotected or publicly accessible channels V34 V34.
V35 Data linkability 3 3 1.8 Different databases or data stored at different locations serving different purposes are / can be linked, thus enabling greater data matching, data mining, profiling, data aggregation or social sorting. Key question here is who is doing the linking and why - it could be for security reasons (catching terrorists before they fly), but it could also be for commercial exploitation by airlines, vendors, service providers operating in the airport as well as by evil-doers seeking to undermine air travel, airport systems or engaged in spoofing, phishing, spamming. V35. Data linkability V35 V35.
V36 Lack of data correction mechanisms (as normally data subjects do not have access to the databases) 4 3 2.4 Many entities are collecting personal data, but rather fewer of them have procedures in place enabling individuals (data subjects) to see what data they have about them. Procedures for correcting incorrect data may not exist or may be cumbersome and bureaucratic. V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36.
V37 Failure of biometrics sensors 2 3 1.2 V37. Failure of biometrics sensors V37 V37.
V38 Lack of common or harmonised legislation in EU Member States 3 2 1.2 Although Member States have transposed the EU Data Protection Directive, they have not done so in a fully harmonised way. In addition, there are lacunae in the legislation so that some matters are not addressed. V38. Lack of common or harmonised legislation in EU Member States V38 V38.
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) 4 5 4 Due to limited resources, RFID tags often use light, proprietary cryptography, which in some cases is not sufficient. Identifiers of tags which are sent in the beginning of communication are not encrypted at all (as a part of anti-collision protocol) and they may be used e.g. for tracking of people. V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39.
V40 Lack of respect to the legitimacy of data processing, e.g. consent 3 4 2.4 The processing of personal data is supposed to be legitimate. However, some data controllers and data processors may not have obtained the informed consent of data subjects. V40. Lack of respect to the legitimacy of data processing, e.g. consent V40 V40.
V41 Lack of respect to the data conservation principle 3 3 1.8 Personal data are supposed to be deleted when they are no longer necessary for the purposes for which they were collected or processed. V41. Lack of respect to the data conservation principle V41 V41.
V42 Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data) 2 3 1.2 Data subjects are supposed to be given the opportunity to rectify incorrect data or to block its further use. For instance, Akira wishes to unsubscribe from "Hazukashi Not" service and to have his account deleted. V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data) V42 V42.
*Indicative values - the final vulnerability value is estimated for every pair asset-vulnerability.

Threats

Threats and Threat Agents [perceived threats that could exploit the identified vulnerabilities of the assets]
Threat ID Threats Threat Agent (source of threat or person who initiates threat) TA Motivation TA Capacity (knowledge etc.) Comments Threat Assessment Value LOOKUP
T1 Denial of service attack / flood / buffer overflow Vandals/terrorists/Corporate raiders/professional criminals/hackers/ rogue; State Medium Varies from low to high A denial of service attack is sabotage, aimed at disrupting a service for fun or to achieve political or illegal goals. A DOS attack is sometimes known as a buffer overflow attack or flooding.. 3 T1. T1 3 T1. Denial of service attack / flood / buffer overflow 3
T2 Spoofing of credentials / bypass authentication Corporate raiders/professional criminals/hackers Medium 4 This threat is a stepping stone to achieve next stage of sabotage or penetration. 5 T2. T2 5 T2. Spoofing of credentials / bypass authentication 5
T3 Large-scale and/or inappropriate data mining and/or surveillance Marketing companies, online service providers, malicious attackers To collect large volume of potentially personal sensitive data for market analysis and profit making (H) 5 The ease with which data can be collected, aggregated and mined coupled with the motivation of large financial paybacks make this a widespread threat. Roger Clarke coined the term dataveillance to describe the phenomenon of surveillance by means of data analysis. Both airports and governments may also have an interest in analysing data, to prevent terrorist related incidents, to develop more targeted advertising. 4 T3. T3 4 T3. Large-scale and/or inappropriate data mining and/or surveillance 4
T4 Traffic analysis / scan / probe Corporate raiders/professional criminals/hackers High This threat is often found in conjunction with or preparation for another attack aimed at revealing protected sensitive operations. The threat gleans data implied in network communication patterns. Traffic analysis requires special skill and knowledge to be effective. 3 T4. T4 3 T4. Traffic analysis / scan / probe 3
T5 Man-in-the-middle attack Hacker To hijack network communication channel for sensitive data collection and misinformation feeding and identity theft (HML) 4 This is one of the most common attack methods, especially for information collection. However, such attacks on RFID and smart cards do not occur very often. Such attacks are usually carried to appropriate others' identity rather than getting access to restricted areas or data, which is usually encrypted. Man-in-the-middle (or relay) attacks for contactless smart card has been theoretically analysed by Kfir and Wool (2005). For practical aspects, see Hancke (2005). Countermeasures such as distance bounding based on response time (Hancke & Kuhn 2005; Reid et al. 2006) or signal-to-noise rate (Fishkin & Roy 2003) are rarely applied. 3 T5. T5 3 T5. Man-in-the-middle attack 3
T6 Social engineering attack Hacker, criminal, terrorists To obtain sensitive information and system penetration 4 Social engineering attacks are widespread and too-often effective. They play upon gullibility or human psychological weakness. Phishing could be regarded as a form of social engineering. 4 T6. T6 4 T6. Social engineering attack 4
T7 Theft [of cards, devices etc] Malicious attacker Financial gain, criminal activities (H) 4 There will always be evil-doers engaged in theft of others' property, be it smart cards, smart phones or whatever. Theft is not, of course, the only crime. Extortion, fraud and many other crimes are common in cyberspace. 4 T7. T7 4 T7. Theft [of cards, devices etc] 4
T8 Unauthorised access to / deletion / modification of devices / data etc. Malicious attacker This attacks refers to unauthorized access to data stored on RFID, smart cards (especially contactless) and personal devices. Also databases can be a subject of attack though the network, as well as data can be illegally accessed and modified by unauthorized personnel. 4 T8. T8 4 T8. Unauthorised access to / deletion / modification of devices / data etc. 4
T9 Loss or misuse [of cards, devices etc] Passenger, airport and airline personnel Loss or misuse of a card or device is also a common threat. 3 T9. T9 3 T9. Loss or misuse [of cards, devices etc] 3
T10 Use erroneous and/or unreliable data 4 T10 T10 4 T10. Use erroneous and/or unreliable data 4
T11 Procedures / instructions not followed Airport and airline personnel. Passengers This threat arises when, for example, a passenger doesn't follow instructions and makes a jam in the automated passport/immigration control or smart corridor. 3 T11 T11 3 T11. Procedures / instructions not followed 3
T12 Non-compliance with data protection legislation Commercial establishments, State 4 This threat arises when governments and business do not comply with provisions of data protection legislation and the principles stated therein, for example, regarding data minimisation, purpose specification, proportionality, informed consent, access to data by the data subject, etc. 4 T12 T12 4 T12. Non-compliance with data protection legislation 4
T13 Function creep (data used for other purposes than the ones for which they were originally collected) Commercial establishments 4 Function creep occurs when data are used for other purposes than the ones for which they were originally collected for. For example, in the air traffic scenario, a car rental company doing some market analysis might approach an airport operator to gain access to its data on airport parking. 4 T13 T13 4 T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
T14 Unauthorized check-in and boarding / identity theft Hacker, criminal, terrorist For example, an attacker might use a fake fingerprint with a stolen passport to board the plane. 4 T14 T14 4 T14. Unauthorized check-in and boarding / identity theft 4
T15 Cloning of credentials and tags (rfid related) Hacker Medium-High Medium-High An RFID clone can be either physically similar to the original tag or can be a notebook with a special antenna. Cloning is relatively easy for basic tags but even some advanced and apparently well protected tags with a challenge-response protocol have been cloned (Juels 2005; Bono et al. 2005; Courtois et al. 2008). 3 T15 T15 3 T15. Cloning of credentials and tags (rfid related) 3
T16 Unauthorised access to other restricted areas (apart from boarding e.g. Control room, personnel's' offices) Hacker, criminal, terrorist This threat can arise as a result of stealing or cloning authorisation tokens (like smart cards). 3 T16 T16 3 T16. Unauthorised access to other restricted areas (apart from boarding e.g. Control room, personnel's' offices) 3
T17 Side channel attack Smart cards or RFID tags may be subject to side channel attacks based on information gained from physical implementation of a cryptosystem, like variations of power consumption, time of computations or electromagnetic field (Bar-El 2003). It is often combined with other cryptanalysis methods. 2 T17 T17 2 T17. Side channel attack 2
T18 Blocking RFID or a GSM network can be blocked by exploiting vulnerabilities of information exchange protocols. Blocking can be also useful as a way to protect consumers' privacy (Juels, Rivest, Szydlo 2003). 2 T18 T18 2 T18. Blocking 2
T19 Jamming Hacker System operation interruption to futher achieve attack steps such as spoofing or decoyed attacks (L) 4 Jamming is malicious interference of a radio transmission. It can result in denial of service and forcing a system to use fallback procedures. Large-scale jamming requires extensive equipment setup and exposure of the transmission source. It is not commonly practised unless with a clear and critical agenda. 2 T19 T19 2 T19. Jamming 2
T20 Fake / rogue rfid readers / scanning of rfid reader and /or tag RFID Tags can be read by any RFID reader. Therefore, rogue RFID readers can scan for RFID and be used for unauthorized reading of information from a tag. As RFIDs often have light cryptography schemes (if any), powerful back-end systems can break the code in minutes, making the security protection ineffective. The range of a reader may be extended several times beyond the standard communication distance, for example ISO 14443 cards with standard range 10 cm can be scanned from 25-35 cm, which is enough to read a card in someone's pocket. Main countermeasures are: encryption, authentication of the reader, using short-range tags, shielding tags with an anti-skimming material (e.g. aluminium foil) and moving sensitive information to a protected database in the system's backend. 3 T20 T20 3 T20. Fake / rogue rfid readers / scanning of rfid reader and /or tag 3
T21 Physical rfid tag destruction The easiest way to disrupt RFID systems is to physically destroy the tags. Destruction becomes a serious issue when RFID tags are used as anti-theft protection. RFID tags in e-passports can be destroyed by owners who have concerns about possible abuse of their privacy - especially as an e-passport with a non-working RFID tag is still valid (Wortham 2007). 4 T21 T21 4 T21. Physical rfid tag destruction 4
T22 Malfunctioning/breakdown of systems /devices / equipment n/a n/a n/a This threat occurs when systems or devices malfunction due to hardware/software/implementation errors. 4 T22 T22 4 T22. Malfunctioning/breakdown of systems /devices / equipment 4
T23 E-visa not accepted at check in system fault 3 T23 T23 3 T23. E-visa not accepted at check in 3
T24 Worms, viruses & malicious code Hacker, rogue state Service disruption, system compromise, information theft 4 Worms, viruses and malicious code are a part of our daily cyber life. They are a prevalent and effective way of disrupting systems. Even very simple RFID tags, such as those used for tagging goods, can carry a malicious code (Rieback at al. 2006). 3 T24 T24 3 T24. Worms, viruses & malicious code 3
T25 Malicious attack on power systems Malicious attacker This threat might be aimed at forcing a system to use fallback procedures, e.g., in order to get unauthorised access to restricted areas. 3 T25 T25 3 T25. Malicious attack on power systems 3
T26 State surveillance on citizens State To achieve unethical citizen control political agenda (H) 5 Unjustified political agendas often lead to excessive surveillance on citizens. Every described case (true or invented) dramatically decreases trust and acceptance of technology (especially biometrics, RFID). 5 T26 T26 5 T26. State surveillance on citizens 5
T27 Trade union/labour strikes Labor union 3 T27 T27 3 T27. Trade union/labour strikes 3
T28 Adverse weather condition or other disaster n/a n/a n/a This threat is of low probability but potentially high consequence. The destruction wrought by natural disasters is difficult to predict. It could affect airport and telecommunication (network) operations. 4 T28 T28 4 T28. Adverse weather condition or other disaster 4
T29 Ad hoc network routing attack Corporate raiders/professional criminals/hackers Initial attack step to further achieve cloning, man-in-the-middle attack, or service interruption which leads to system compromise (M) 4 Personal mobile devices may create ad hoc networks in order to exchange data and information between users. These networks can be used by attacker to break into personal devices and compromise the communication and information exchange between parties. For example, DOS attacks can flood ad-hoc networks; rogue participants can de-route or compromise legitimate messages and information exchanges. 2 T29 T29 2 T29. Ad hoc network routing attack 2
T30 Low acceptance of devices / equipment / procedures Passengers / citizens / airport & airline personnel RFID is perceived by many people as a privacy threat. They have been called "spychips" (Albrecht, McIntyre 2005). Most of the concerns presented during an EU public consultation on RFID were related to privacy (Maghiros, Rotter, van Lieshout 2007). Also some biometrics have low social acceptance, especially fingerprints which are commonly regarded as linked to criminal investigations. 4 T30 T30 4 T30. Low acceptance of devices / equipment / procedures 4
T31 Data linkability Commercial establishments, State 4 The abundance of data collected and processed in the IoT and their storage in databases (commercial and state) facilitate their linkability. 4 T31 T31 4 T31. Data linkability 4
T32 Profiling Commercial establishments, State 4 The abundance of data collected and processed in the IoT can lead to the creation of user profiles (relating to consumer preferences, travelling habits, etc.). 4 T32 T32 4 T32. Profiling 4
T33 Exclusion of the data subject from the data processing process Commercial establishments, State 4 The automatisation of the processes in the IoT threatens to exclude the data subject from the data processing process. 4 T33 T33 4 T33. Exclusion of the data subject from the data processing process 4
T34 Trivialisation of unique identifiers Commercial establishments, State 4 The use of unique identifiers, such as the human fingerprint, is increasingly being used for trivial transactions, such as in the case when Elena registers her fingerprint in order to "secure" her boarding pass. 4 T34 T34 4 T34. Trivialisation of unique identifiers 4

Assets+Vulnerabilities

Mapping of Assets and Vulnerabilities
Asset ID Assets Vulnerability Description Vulnerability Value LOOKUP Value
A1 Automated reservation, check-in and boarding procedure V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. 3 V1. V1 A1V1 3
A1 Automated reservation, check-in and boarding procedure V10. Flawed/insufficient design and/or capacity of devices and systems 3 V10 V10 A1V10 3
A1 Automated reservation, check-in and boarding procedure V12. Lack of harmonisation and interoperability of procedures 3 V12 V12 A1V12 3
A1 Automated reservation, check-in and boarding procedure V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] 4 V14 V14 A1V14 4
A1 Automated reservation, check-in and boarding procedure V15. Insufficient equipment 2 V15 V15 A1V15 2
A1 Automated reservation, check-in and boarding procedure V16. Inappropriate expansion of the trust perimeter 4 V16 V16 A1V16 4
A1 Automated reservation, check-in and boarding procedure V18. Lack of respect to the data minimisation and proportionality principles 4 V18 V18 A1V18 4
A1 Automated reservation, check-in and boarding procedure V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 4 V19 V19 A1V19 4
A1 Automated reservation, check-in and boarding procedure V2. Excessive dependency on IT systems, network and external infrastructure 3 V2. V2 A1V2 3
A1 Automated reservation, check-in and boarding procedure V21. Inappropriate / inadequate identity management 3 V21 V21 A1V21 3
A1 Automated reservation, check-in and boarding procedure V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 3 V28 V28 A1V28 3
A1 Automated reservation, check-in and boarding procedure V3. Lack of back-up / failover procedures 4 V3. V3 A1V3 4
A1 Automated reservation, check-in and boarding procedure V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) 3 V36 V36 A1V36 3
A1 Automated reservation, check-in and boarding procedure V37. Failure of biometrics sensors 3 V37 V37 A1V37 3
A1 Automated reservation, check-in and boarding procedure V38. Lack of common or harmonised legislation in EU Member States 4 V38 V38 A1V38 4
A1 Automated reservation, check-in and boarding procedure V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A1V4 4
A1 Automated reservation, check-in and boarding procedure V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 2 V39 V39 A1V39 2
A1 Automated reservation, check-in and boarding procedure V5. Lack of usability / unfriendly user interface(s) of device(s) 4 V5. V5 A1V5 4
A1 Automated reservation, check-in and boarding procedure V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A1V6 3
A1 Automated reservation, check-in and boarding procedure V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] 3 V7. V7 A1V7 3
A1 Automated reservation, check-in and boarding procedure V8. Dependency on power systems 4 V8. V8 A1V8 4
A1 Automated reservation, check-in and boarding procedure V10. Flawed/insufficient design and/or capacity of devices and systems 3 V10 V10 A1V10 3
A1 Automated reservation, check-in and boarding procedure V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 3 V9. V9 A1V9 3
A1 Automated reservation, check-in and boarding procedure V20. Lack of respect to the transparency principle 3 V20 V20 A1V20 3
A1 Automated reservation, check-in and boarding procedure V41. Lack of respect to the data conservation principle 3 V41 V41 A1V41 3
A1 Automated reservation, check-in and boarding procedure V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 4 V42 V42 A1V42 4
A2 Electronic visa issuing process V8. Dependency on power systems 3 V8. V8 A2V8 3
A2 Electronic visa issuing process V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. 5 V1. V1 A2V1 5
A2 Electronic visa issuing process V12. Lack of harmonisation and interoperability of procedures 4 V12 V12 A2V12 4
A2 Electronic visa issuing process V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] 4 V14 V14 A2V14 4
A2 Electronic visa issuing process V3. Lack of back-up / failover procedures 4 V3. V3 A2V3 4
A2 Electronic visa issuing process V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] 3 V7. V7 A2V7 3
A2 Electronic visa issuing process V5. Lack of usability / unfriendly user interface(s) of device(s) 3 V5. V5 A2V5 3
A2 Electronic visa issuing process V23. Over dependency on biometrics 3 V23 V23 A2V23 3
A2 Electronic visa issuing process V6. Lack of interoperability between devices and/or technologies and/or systems 4 V6. V6 A2V6 4
A2 Electronic visa issuing process V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 3 V9. V9 A2V9 3
A2 Electronic visa issuing process V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A2V4 4
A2 Electronic visa issuing process V38. Lack of common or harmonised legislation in EU Member States 3 V38 V38 A2V38 3
A2 Electronic visa issuing process V18. Lack of respect to the data minimisation and proportionality principles 4 V18 V18 A2V18 4
A2 Electronic visa issuing process V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 4 V19 V19 A2V19 4
A2 Electronic visa issuing process V35. High data linkability 3 V35 V35 A2V35 3
A2 Electronic visa issuing process V15. Insufficient equipment 2 V15 V15 A2V15 2
A2 Electronic visa issuing process V40. Lack of respect to the legitimacy of data processing, e.g. consent 4 V40 V40 A2V40 4
A2 Electronic visa issuing process V41. Lack of respect to the data conservation principle 4 V41 V41 A2V41 4
A2 Electronic visa issuing process V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 5 V42 V42 A2V42 5
A2 Electronic visa issuing process V21. Inappropriate / inadequate identity management 3 V21 V21 A2V21
A2 Electronic visa issuing process V20. Lack of respect to the transparency principle 4 V20 V20 A2V20 4
A3 Luggage and goods handling V13. Lack of or inappropriate protection of RFID tags 2 V13 V13 A3V13 2
A3 Luggage and goods handling V25. Actual RFID range longer than standard 2 V25 V25 A3V25 2
A3 Luggage and goods handling V2. Excessive dependency on IT systems, network and external infrastructure 3 V2. V2 A3V2 3
A3 Luggage and goods handling V37. Failure of biometrics sensors 2 V37 V37 A3V37 2
A3 Luggage and goods handling V22. Collision of tag traffic / Radio-frequency interference 2 V22 V22 A3V22 2
A3 Luggage and goods handling V12. Lack of harmonisation and interoperability of procedures 3 V12 V12 A3V12 3
A3 Luggage and goods handling V5. Lack of usability / unfriendly user interface(s) of device(s) 2 V5. V5 A3V5 2
A3 Luggage and goods handling V15. Insufficient equipment 4 V15 V15 A3V15 4
A3 Luggage and goods handling V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 2 V24 V24 A3V24 2
A3 Luggage and goods handling V6. Lack of interoperability between devices and/or technologies and/or systems 4 V6. V6 A3V6 4
A4 Automated traffic management V17. Lack of dependable sensors, GPS 3 V17 V17 A4V17 3
A4 Automated traffic management V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 4 V39 V39 A4V39 4
A4 Automated traffic management V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] 2 V14 V14 A4V14 2
A4 Automated traffic management V2. Excessive dependency on IT systems, network and external infrastructure 3 V2. V2 A4V2 3
A4 Automated traffic management V18. Lack of respect to the data minimisation and proportionality principles 2 V18 V18 A4V18 2
A4 Automated traffic management V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 4 V19 V19 A4V19 4
A4 Automated traffic management V6. Lack of interoperability between devices and/or technologies and/or systems 2 V6. V6 A4V6 2
A4 Automated traffic management V38. Lack of common or harmonised legislation in EU Member States 2 V38 A4 2
A4 Automated traffic management V20. Lack of respect to the transparency principle 3 V20 V20 A4V20 3
A4 Automated traffic management V40. Lack of respect to the legitimacy of data processing, e.g. consent 3 V40 V40 A4V40 3
A4 Automated traffic management V41. Lack of respect to the data conservation principle 3 V41 V41 A4V41 3
A4 Automated traffic management V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 3 V42 V42 A4V42 3
A4 Automated traffic management V21. Inappropriate / inadequate identity management 3 V21 V21 A4V21 3
A5 Passports and National ID cards V20. Lack of appropriate user procedures, especially regarding the collection and processing of persona data: lack of informed consent, insufficient definition of the purpose for which the data are collected for, lack of transparency and data traceability (the user doesn't know when his data are being accessed, by whom and why) 4 V20 V20 A5V20 4
A5 Passports and National ID cards V23. Over dependency on biometrics 4 V23 V23 A5V23 4
A5 Passports and National ID cards V11. Lack of adequate controls in biometrics' enrollment stage 3 V11 V11 A5V11 3
A5 Passports and National ID cards V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 3 V4. V4 A5V4 3
A5 Passports and National ID cards V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 2 V24 V24 A5V24 2
A5 Passports and National ID cards V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A5V6 3
A5 Passports and National ID cards V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 2 V9. V9 A5V9 2
A5 Passports and National ID cards V25. Actual RFID range longer than standard 4 V25 V25 A5V25 4
A5 Passports and National ID cards V26. RFID tags do not have a turn-off option 3 V26 V26 A5V26 3
A5 Passports and National ID cards V27. Insufficient protection against reverse engineering 3 V27 V27 A5V27 3
A5 Passports and National ID cards V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 4 V28 V28 A5V28 4
A5 Passports and National ID cards V31. Devices & equipment used in unprotected environments 3 V31 V31 A5V31 3
A5 Passports and National ID cards V13. Lack of or inappropriate protection of RFID tags 4 V13 V13 A5V13 4
A5 Passports and National ID cards V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 3 V39 V39 A5V39 3
A5 Passports and National ID cards V12. Lack of harmonisation and interoperability of procedures 3 V12 V12 A5V12 3
A5 Passports and National ID cards V18. Lack of respect to the data minimisation and proportionality principles 4 V18 V18 A5V18 4
A5 Passports and National ID cards V21. Inappropriate / inadequate identity management 3 V21 V21 A5V21 3
A5 Passports and National ID cards V22. Collision of tag traffic / Radio-frequency interference 2 V22 V22 A5V22 2
A5 Passports and National ID cards V31. Devices & equipment used in unprotected environments 3 V31 V31 A5V31 3
A5 Passports and National ID cards V41. Lack of respect to the data conservation principle 4 V41 V41 A5V41 4
A5 Passports and National ID cards V38. Lack of common or harmonised legislation in EU Member States 3 V38 V38 A5V38 3
A6 Mobile ‘smart’ devices V21. Inappropriate / inadequate identity management 4 V21 V21 A6V21 4
A6 Mobile ‘smart’ devices V23. Over dependency on biometrics 4 V23 V23 A6V23 4
A6 Mobile ‘smart’ devices V11. Lack of adequate controls in biometrics' enrollment stage 3 V11 V11 A6V11 3
A6 Mobile ‘smart’ devices V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 3 V4. V4 A6V4 3
A6 Mobile ‘smart’ devices V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 2 V24 V24 A6V24 2
A6 Mobile ‘smart’ devices V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A6V6 3
A6 Mobile ‘smart’ devices V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 2 V9. V9 A6V9 2
A6 Mobile ‘smart’ devices V25. Actual RFID range longer than standard 4 V25 V25 A6V25 4
A6 Mobile ‘smart’ devices V26. RFID tags do not have a turn-off option 3 V26 V26 A6V26 3
A6 Mobile ‘smart’ devices V27. Insufficient protection against reverse engineering 3 V27 V27 A6V27 3
A6 Mobile ‘smart’ devices V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 4 V28 V28 A6V28 4
A6 Mobile ‘smart’ devices V31. Devices & equipment used in unprotected environments 3 V31 V31 A6V31 3
A6 Mobile ‘smart’ devices V13. Lack of or inappropriate protection of RFID tags 4 V13 V13 A6V13 4
A6 Mobile ‘smart’ devices V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 3 V39 V39 A6V39 3
A6 Mobile ‘smart’ devices V12. Lack of harmonisation and interoperability of procedures 3 V12 V12 A6V12 3
A6 Mobile ‘smart’ devices V18. Lack of respect to the data minimisation and proportionality principles 4 V18 V18 A6V18 4
A6 Mobile ‘smart’ devices V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 4 V19 V19 A6V19 4
A6 Mobile ‘smart’ devices V20. Lack of respect to the transparency principle 3 V20 V20 A6V20 3
A6 Mobile ‘smart’ devices V22. Collision of tag traffic / Radio-frequency interference 2 V22 V22 A6V22 2
A6 Mobile ‘smart’ devices V31. Devices & equipment used in unprotected environments 3 V31 V31 A6V31 3
A6 Mobile ‘smart’ devices V38. Lack of common or harmonised legislation in EU Member States 3 V38 V38 A6V38 3
A6 Mobile ‘smart’ devices V10. Flawed/insufficient design and/or capacity of devices and systems 3 V10 V10 A6V10 3
A6 Mobile ‘smart’ devices V40. Lack of respect to the legitimacy of data processing, e.g. consent 4 V40 V40 A6V40 4
A6 Mobile ‘smart’ devices V41. Lack of respect to the data conservation principle 4 V41 V41 A6V41 4
A6 Mobile ‘smart’ devices V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 4 V42 V42 A6V42 4
A6 Mobile ‘smart’ devices V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 3 V39 V39 A6V39 3
A6 Mobile ‘smart’ devices V34. Communication of data over unprotected or publicly accessible channels 4 V34 V34 A6V34 4
A7 Health monitoring devices V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A7V4 4
A7 Health monitoring devices V5. Lack of usability / unfriendly user interface(s) of device(s) 4 V5. V5 A7V5 4
A7 Health monitoring devices V6. Lack of interoperability between devices and/or technologies and/or systems 4 V6. V6 A7V6 4
A7 Health monitoring devices V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 2 V24 V24 A7V24 2
A7 Health monitoring devices V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 3 V28 V28 A7V28 3
A7 Health monitoring devices V29. Over-sensitivity of devices (give many false alarms) 4 V29 V29 A7V29 4
A7 Health monitoring devices V30. Sensitivity to magnetic fields 4 V30 V30 A7V30 4
A7 Health monitoring devices V31. Devices & equipment used in unprotected environments 3 V31 V31 A7V31 3
A7 Health monitoring devices V34. Communication of data over unprotected or publicly accessible channels 4 V34 V34 A7V34 4
A7 Health monitoring devices V18. Lack of respect to the data minimisation and proportionality principles 4 V18 V18 A7V18 4
A7 Health monitoring devices V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 4 V19 V19 A7V19 4
A7 Health monitoring devices V20. Lack of respect to the transparency principle 3 V20 V20 A7V20 3
A7 Health monitoring devices V40. Lack of respect to the legitimacy of data processing, e.g. consent 3 V40 V40 A7V40 3
A7 Health monitoring devices V41. Lack of respect to the data conservation principle 5 V41 V41 A7V41 5
A7 Health monitoring devices V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 5 V42 V42 A7V42 5
A7 Health monitoring devices V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 4 V39 V39 A7V39 4
A8 Travel documents (paper) V3. Lack of back-up / failover procedures 4 V3. V3 A8V3 4
A8 Travel documents (paper) V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 3 V4. V4 A8V4 3
A8 Travel documents (paper) V12. Lack of harmonisation and interoperability of procedures 2 V12 V12 A8V12 2
A8 Travel documents (paper) V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 4 V24 V24 A8V24 4
A9 RFID & barcode readers V2. Excessive dependency on IT systems, network and external infrastructure 3 V2. V2 A9V2 3
A9 RFID & barcode readers V3. Lack of back-up / failover procedures 3 V3. V3 A9V3 3
A9 RFID & barcode readers V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A9V4 4
A9 RFID & barcode readers V5. Lack of usability / unfriendly user interface(s) of device(s) 4 V5. V5 A9V5 4
A9 RFID & barcode readers V6. Lack of interoperability between devices and/or technologies and/or systems 4 V6. V6 A9V6 4
A9 RFID & barcode readers V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 3 V9. V9 A9V9 3
A9 RFID & barcode readers V10. Flawed/insufficient design and/or capacity of devices and systems 4 V10 V10 A9V10 4
A9 RFID & barcode readers V13. Lack of or inappropriate protection of RFID tags 3 V13 V13 A9V13 3
A9 RFID & barcode readers V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] 4 V14 V14 A9V14 4
A9 RFID & barcode readers V22. Collision of tag traffic / Radio-frequency interference 3 V22 V22 A9V22 3
A9 RFID & barcode readers V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 2 V24 V24 A9V24 2
A9 RFID & barcode readers V25. Actual RFID range longer than standard 3 V25 V25 A9V25 3
A9 RFID & barcode readers V27. Insufficient protection against reverse engineering 2 V27 V27 A9V27 2
A9 RFID & barcode readers V30. Sensitivity to magnetic fields 2 V30 V30 A9V30 2
A9 RFID & barcode readers V34. Communication of data over unprotected or publicly accessible channels 3 V34 V34 A9V34 3
A9 RFID & barcode readers V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 3 V19 V19 A9V19 3
A9 RFID & barcode readers V20. Lack of respect to the transparency principle 4 V20 V20 A9V20 4
A9 RFID & barcode readers V40. Lack of respect to the legitimacy of data processing, e.g. consent 3 V40 V40 A9V40 3
A9 RFID & barcode readers V41. Lack of respect to the data conservation principle 4 V41 V41 A9V41 4
A9 RFID & barcode readers V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 4 V42 V42 A9V42 4
A9 RFID & barcode readers V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 4 V39 V39 A9V39 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V21.Lack of appropriate user procedures, especially regarding the collection and processing of persona data: lack of informed consent, insufficient definition of the purpose for which the data are collected for, lack of transparency (the user doesn't know when his data are being accessed, by whom and why) 4 V21 V21 A10V21 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 3 V4. V4 A10V4 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 4 V24 V24 A10V24 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A10V6 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 2 V9. V9 A10V9 2
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V25. Actual RFID range longer than standard 4 V25 V25 A10V25 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V26. RFID tags do not have a turn-off option 3 V26 V26 A10V26 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V27. Insufficient protection against reverse engineering 3 V27 V27 A10V27 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 4 V28 V28 A10V28 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V31. Devices & equipment used in unprotected environments 3 V31 V31 A10V31 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V13. Lack of or inappropriate protection of RFID tags 4 V13 V13 A10V13 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V12. Lack of harmonisation and interoperability of procedures 3 V12 V12 A10V12 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V18. Lack of respect to the data minimisation and proportionality principles 4 V18 V18 A10V18 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V21. Inappropriate / inadequate identity management 3 V21 V21 A10V21 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V22. Collision of tag traffic / Radio-frequency interference 2 V22 V22 A10V22 2
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V31. Devices & equipment used in unprotected environments 4 V31 V31 A10V31 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V38. Lack of common or harmonised legislation in EU Member States 3 V38 V38 A10V38 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 4 V39 V39 A10V39 4
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V18. Lack of respect to the data minimisation and proportionality principles 3 V18 V18 A10V18 3
A10 Credit Cards/Debit card/Payment cards/'e-wallet' V40. Lack of respect to the legitimacy of data processing, e.g. consent 4 V40 V40 A10V40 4
A11 Other RFID cards V21.Lack of appropriate user procedures, especially regarding the collection and processing of persona data: lack of informed consent, insufficient definition of the purpose for which the data are collected for, lack of transparency (the user doesn't know when his data are being accessed, by whom and why) 4 V21 V21 A11V21 4
A11 Other RFID cards V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 3 V4. V4 A11V4 3
A11 Other RFID cards V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 3 V24 V24 A11V24 3
A11 Other RFID cards V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A11V6 3
A11 Other RFID cards V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 2 V9. V9 A11V9 2
A11 Other RFID cards V25. Actual RFID range longer than standard 4 V25 V25 A11V25 4
A11 Other RFID cards V26. RFID tags do not have a turn-off option 3 V26 V26 A11V26 3
A11 Other RFID cards V27. Insufficient protection against reverse engineering 3 V27 V27 A11V27 3
A11 Other RFID cards V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 4 V28 V28 A11V28 4
A11 Other RFID cards V31. Devices & equipment used in unprotected environments 3 V31 V31 A11V31 3
A11 Other RFID cards V13. Lack of or inappropriate protection of RFID tags 4 V13 V13 A11V13 4
A11 Other RFID cards V12. Lack of harmonisation and interoperability of procedures 3 V12 V12 A11V12 3
A11 Other RFID cards V21. Inappropriate / inadequate identity management 3 V21 V21 A11V21 3
A11 Other RFID cards V22. Collision of tag traffic / Radio-frequency interference 2 V22 V22 A11V22 2
A11 Other RFID cards V31. Devices & equipment used in unprotected environments 4 V31 V31 A11V31 4
A11 Other RFID cards V38. Lack of common or harmonised legislation in EU Member States 3 V38 V38 A11V38 3
A11 Other RFID cards V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 3 V39 V39 A11V39 3
A11 Other RFID cards V18. Lack of respect to the data minimisation and proportionality principles 3 V18 V18 A11V18 3
A11 Other RFID cards V40. Lack of respect to the legitimacy of data processing, e.g. consent 4 V40 V40 A11V40 4
A12 Scanners & detectors V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. 2 V1. V1 A12V1 2
A12 Scanners & detectors V2. Excessive dependency on IT systems, network and external infrastructure 4 V2. V2 A12V2 4
A12 Scanners & detectors V21.Lack of appropriate user procedures, especially regarding the collection and processing of persona data: lack of informed consent, insufficient definition of the purpose for which the data are collected for, lack of transparency (the user doesn't know when his data are being accessed, by whom and why) 4 V21 V21 A12V21 4
A12 Scanners & detectors V27. Insufficient protection against reverse engineering 2 V27 V27 A12V27 2
A12 Scanners & detectors V11. Lack of adequate controls in biometrics' enrollment stage 4 V11 V11 A12V11 4
A12 Scanners & detectors V37. Failure of biometrics sensors 3 V37 V37 A12V37 3
A12 Scanners & detectors V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] 4 V32 V32 A12V32 4
A12 Scanners & detectors V33. High error rates of biometric identification (esp. face-based recognition) 3 V33 V33 A12V33 3
A12 Scanners & detectors V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A12V4 4
A12 Scanners & detectors V23. Over dependency on biometrics 3 V23 V23 A12V23 3
A12 Scanners & detectors V29. Over-sensitivity of devices (give many false alarms) 3 V29 V29 A12V29 3
A12 Scanners & detectors V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 3 V39 V39 A12V39 3
A12 Scanners & detectors V22. Collision of tag traffic / Radio-frequency interference 3 V22 V22 A12V22 3
A12 Scanners & detectors V18. Lack of respect to the data minimisation and proportionality principles 4 V18 V18 A12V18 4
A12 Scanners & detectors V20. Lack of respect to the transparency principle 4 V20 V20 A12V20 4
A12 Scanners & detectors V40. Lack of respect to the legitimacy of data processing, e.g. consent 4 V40 V40 A12V40 4
A12 Scanners & detectors V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 4 V42 V42 A12V42 4
A12 Scanners & detectors V38. Lack of common or harmonised legislation in EU Member States 2 V38 V38 A12V38 2
A13 Networks V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. 3 V1. V1 A13V1 3
A13 Networks V2. Excessive dependency on IT systems, network and external infrastructure 4 V2. V2 A13V2 4
A13 Networks V3. Lack of back-up / failover procedures 3 V3. V3 A13V3 3
A13 Networks V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A13V4 4
A13 Networks V5. Lack of usability / unfriendly user interface(s) of device(s) 4 V5. V5 A13V5 4
A13 Networks V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A13V6 3
A13 Networks V8. Dependency on power systems 3 V8. V8 A13V8 3
A13 Networks V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 4 V9. V9 A13V9 4
A13 Networks V10. Flawed/insufficient design and/or capacity of devices and systems 3 V10 V10 A13V10 3
A13 Networks V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] 2 V14 V14 A13V14 2
A13 Networks V15. Insufficient equipment 2 V15 V15 A13V15 2
A13 Networks V16. Inappropriate expansion of the trust perimeter 3 V16 V16 A13V16 3
A13 Networks V21. Inappropriate / inadequate identity management 4 V21 V21 A13V21 4
A13 Networks V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 4 V39 V39 A13V39 4
A14 State databases V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. 3 V1. V1 A14V1 3
A14 State databases V2. Excessive dependency on IT systems, network and external infrastructure 4 V2. V2 A14V2 4
A14 State databases V3. Lack of back-up / failover procedures 3 V3. V3 A14V3 3
A14 State databases V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 3 V4. V4 A14V4 3
A14 State databases V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] 5 V7. V7 A14V7 5
A14 State databases V8. Dependency on power systems 2 V8. V8 A14V8 2
A14 State databases V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 4 V9. V9 A14V9 4
A14 State databases V10. Flawed/insufficient design and/or capacity of devices and systems 3 V10 V10 A14V10 3
A14 State databases V18. Lack of respect to the data minimisation and proportionality principles 5 V18 V18 A14V18 5
A14 State databases V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 4 V19 V19 A14V19 4
A14 State databases V20. Lack of respect to the transparency principle 5 V20 V20 A14V20 5
A14 State databases V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 2 V28 V28 A14V28 2
A14 State databases V35. High data linkability 4 V35 V35 A14V35 4
A14 State databases V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) 4 V36 V36 A14V36 4
A14 State databases V40. Lack of respect to the legitimacy of data processing, e.g. consent 4 V40 V40 A14V40 4
A14 State databases V41. Lack of respect to the data conservation principle 5 V41 V41 A14V41 5
A14 State databases V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 5 V42 V42 A14V42 5
A14 State databases V38. Lack of common or harmonised legislation in EU Member States 4 V38 V38 A14V38 4
A15 Commercial and other databases V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. 3 V1. V1 A15V1 3
A15 Commercial and other databases V2. Excessive dependency on IT systems, network and external infrastructure 4 V2. V2 A15V2 4
A15 Commercial and other databases V3. Lack of back-up / failover procedures 3 V3. V3 A15V3 3
A15 Commercial and other databases V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 3 V4. V4 A15V4 3
A15 Commercial and other databases V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] 4 V7. V7 A15V7 4
A15 Commercial and other databases V8. Dependency on power systems 2 V8. V8 A15V8 2
A15 Commercial and other databases V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 4 V9. V9 A15V9 4
A15 Commercial and other databases V10. Flawed/insufficient design and/or capacity of devices and systems 3 V10 V10 A15V10 3
A15 Commercial and other databases V18. Lack of respect to the data minimisation and proportionality principles 5 V18 V18 A15V18 5
A15 Commercial and other databases V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 4 V19 V19 A15V19 4
A15 Commercial and other databases V20. Lack of appropriate user procedures, especially regarding the collection and processing of persona data: lack of informed consent, insufficient definition of the purpose for which the data are collected for, lack of transparency and data traceability (the user doesn't know when his data are being accessed, by whom and why) 5 V20 V20 A15V20 5
A15 Commercial and other databases V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 2 V28 V28 A15V28 2
A15 Commercial and other databases V35. High data linkability 4 V35 V35 A15V35 4
A15 Commercial and other databases V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) 4 V36 V36 A15V36 4
A15 Commercial and other databases V40. Lack of respect to the legitimacy of data processing, e.g. consent 4 V40 V40 A15V40 4
A15 Commercial and other databases V41. Lack of respect to the data conservation principle 4 V41 V41 A15V41 4
A15 Commercial and other databases V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). 4 V42 V42 A15V42 4
A15 Commercial and other databases V38. Lack of common or harmonised legislation in EU Member States 4 V38 V38 A15V38 4
A16 Temporary handset airport guides V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A16V4 4
A16 Temporary handset airport guides V5. Lack of usability / unfriendly user interface(s) of device(s) 2 V5. V5 A16V5 2
A16 Temporary handset airport guides V6. Lack of interoperability between devices and/or technologies and/or systems 2 V6. V6 A16V6 2
A16 Temporary handset airport guides V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] 3 V14 V14 A16V14 3
A16 Temporary handset airport guides V15. Insufficient equipment 2 V15 V15 A16V15 2
A16 Temporary handset airport guides V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 2 V24 V24 A16V24 2
A16 Temporary handset airport guides V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] 1 V32 V32 A16V32 1
A17 Luggage and goods V13. Lack of or inappropriate protection of RFID tags 3 V13 V13 A17V13 3
A17 Luggage and goods V22. Collision of tag traffic / Radio-frequency interference 2 V22 V22 A17V22 2
A17 Luggage and goods V24. Inherent features (size, material etc.): easy to lose, stolen and/or copied (expecially for RFID tags) 3 V24 V24 A17V24 3
A17 Luggage and goods V25. Actual RFID range longer than standard 2 V25 V25 A17V25 2
A17 Luggage and goods V26. RFID tags do not have a turn-off option 2 V26 V26 A17V26 2
A18 Check-in infrastructure V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. 3 V1. V1 A18V1 3
A18 Check-in infrastructure V2. Excessive dependency on IT systems, network and external infrastructure 4 V2. V2 A18V2 4
A18 Check-in infrastructure V3. Lack of back-up / failover procedures 3 V3. V3 A18V3 3
A18 Check-in infrastructure V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 3 V4. V4 A18V4 3
A18 Check-in infrastructure V5. Lack of usability / unfriendly user interface(s) of device(s) 4 V5. V5 A18V5 4
A18 Check-in infrastructure V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A18V6 3
A18 Check-in infrastructure V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] 2 V7. V7 A18V7 2
A18 Check-in infrastructure V8. Dependency on power systems 2 V8. V8 A18V8 2
A18 Check-in infrastructure V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 3 V9. V9 A18V9 3
A18 Check-in infrastructure V12. Lack of harmonisation and interoperability of procedures 2 V12 V12 A18V12 2
A18 Check-in infrastructure V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] 4 V14 V14 A18V14 4
A18 Check-in infrastructure V23. Over dependency on biometrics 4 V23 V23 A18V23 4
A18 Check-in infrastructure V33. High error rates of biometric identification (esp. face-based recognition) 3 V33 V33 A18V33 3
A18 Check-in infrastructure V37. Failure of biometrics sensors 3 V37 V37 A18V37 3
A19 Airport facilities V2. Excessive dependency on IT systems, network and external infrastructure 3 V2. V2 A19V2 3
A19 Airport facilities V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A19V4 4
A19 Airport facilities V5. Lack of usability / unfriendly user interface(s) of device(s) 3 V5. V5 A19V5 3
A19 Airport facilities V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A19V6 3
A19 Airport facilities V8. Dependency on power systems 3 V8. V8 A19V8 3
A19 Airport facilities V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] 4 V14 V14 A19V14 4
A19 Airport facilities V16. Inappropriate expansion of the trust perimeter 4 V16 V16 A19V16 4
A19 Airport facilities V20. Lack of respect to the transparency principle 2 V20 V20 A19V20 2
A19 Airport facilities V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] 4 V32 V32 A19V32 4
A20 Cars / vehicles V2. Excessive dependency on IT systems, network and external infrastructure 3 V2. V2 A20V2 3
A20 Cars / vehicles V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc 4 V4. V4 A20V4 4
A20 Cars / vehicles V6. Lack of interoperability between devices and/or technologies and/or systems 3 V6. V6 A20V6 3
A20 Cars / vehicles V8. Dependency on power systems 4 V8. V8 A20V8 4
A20 Cars / vehicles V9. Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls 3 V9. V9 A20V9 3
A20 Cars / vehicles V10. Flawed/insufficient design and/or capacity of devices and systems 2 V10 V10 A20V10 2
A20 Cars / vehicles V12. Lack of harmonisation and interoperability of procedures 2 V12 V12 A20V12 2
A20 Cars / vehicles V17. Lack of dependable sensors, GPS 3 V17 V17 A20V17 3
A20 Cars / vehicles V18. Lack of respect to the data minimisation and proportionality principles 1 V18 V18 A20V18 1
A20 Cars / vehicles V19. Lack of respect to the purpose restriction principle (purpose limitation principle) 4 V19 V19 A20V19 4
A20 Cars / vehicles V20. Lack of respect to the transparency principle 3 V20 V20 A20V20 3
A20 Cars / vehicles V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) 3 V28 V28 A20V28 3
A20 Cars / vehicles V38. Lack of common or harmonised legislation in EU Member States 4 V38 V38 A20V38 4
A20 Cars / vehicles V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) 4 V39 V39 A20V39 4
A20 Cars / vehicles V40. Lack of respect to the legitimacy of data processing, e.g. consent 2 V40 V40 A20V40 2
A20 Cars / vehicles V41. Lack of respect to the data conservation principle 2 V41 V41 A20V41 2

Vulnerabilities+Threats

Mapping of Vulnerabilities and Threats
No Vulnerability Description Threats Threat value
V1 Inappropriate design of procedures T6. Social engineering attack 4
V1 Inappropriate design of procedures T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V1 Inappropriate design of procedures T11. Procedures / instructions not followed 3
V1 Inappropriate design of procedures T12. Non-compliance with data protection legislation 4
V1 Inappropriate design of procedures T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V1 Inappropriate design of procedures T14. Unauthorized check-in and boarding / identity theft 4
V1 Inappropriate design of procedures T27. Trade union/labour strikes 3
V2 Excessive dependency on IT systems, network and external infrastructure T1. Denial of service attack / Flood / Buffer overflow 3
V2 Excessive dependency on IT systems, network and external infrastructure T2. Spoofing of credentials / bypass authentication 5
V2 Excessive dependency on IT systems, network and external infrastructure T5. Man-in-the-middle attack 3
V2 Excessive dependency on IT systems, network and external infrastructure T22. Malfunctioning/breakdown of systems /devices / equipment 4
V2 Excessive dependency on IT systems, network and external infrastructure T24. Worms, viruses & malicious code 3
V2 Excessive dependency on IT systems, network and external infrastructure T25. Malicious attack on power systems 3
V2 Excessive dependency on IT systems, network and external infrastructure T28. Adverse weather condition or other disaster 4
V3 Lack of back-up / failover procedures T1. Denial of service attack / Flood / Buffer overflow 3
V3 Lack of back-up / failover procedures T6. Social engineering attack 4
V3 Lack of back-up / failover procedures T7. Theft [of cards, devices etc] 4
V3 Lack of back-up / failover procedures T9. Loss or misuse [of cards, devices etc] 3
V3 Lack of back-up / failover procedures T22. Malfunctioning/breakdown of systems /devices / equipment 4
V3 Lack of back-up / failover procedures T23. E-visa not accepted at check in 3
V3 Lack of back-up / failover procedures T25. Malicious attack on power systems 3
V3 Lack of back-up / failover procedures T28. Adverse weather condition or other disaster 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T2. Spoofing of credentials / bypass authentication 5
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T6. Social engineering attack 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T7. Theft [of cards, devices etc] 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T9. Loss or misuse [of cards, devices etc] 3
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T10. Use erroneous and/or unreliable data 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T11. Procedures / instructions not followed 3
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T12. Non-compliance with data protection legislation 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T14. Unauthorized check-in and boarding / identity theft 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T16. Unauthorised access to other restricted areas (apart from boarding e.g. Control room, personnel's' offices) 3
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T22. Malfunctioning/breakdown of systems /devices / equipment 4
V4 Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc T30. Low acceptance of devices / equipment / procedures 4
V5 Lack of usability / unfriendly user interface(s) of device(s) T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V5 Lack of usability / unfriendly user interface(s) of device(s) T9. Loss or misuse [of cards, devices etc] 3
V5 Lack of usability / unfriendly user interface(s) of device(s) T10. Use erroneous and/or unreliable data 4
V5 Lack of usability / unfriendly user interface(s) of device(s) T11. Procedures / instructions not followed 3
V5 Lack of usability / unfriendly user interface(s) of device(s) T14. Unauthorized check-in and boarding / identity theft 4
V5 Lack of usability / unfriendly user interface(s) of device(s) T30. Low acceptance of devices / equipment / procedures 4
V6 Lack of interoperability between devices and/or technologies and/or systems T9. Loss or misuse [of cards, devices etc] 3
V6 Lack of interoperability between devices and/or technologies and/or systems T22. Malfunctioning/breakdown of systems /devices / equipment 4
V6 Lack of interoperability between devices and/or technologies and/or systems T11. Procedures / instructions not followed 3
V6 Lack of interoperability between devices and/or technologies and/or systems T12. Non-compliance with data protection legislation 4
V6 Lack of interoperability between devices and/or technologies and/or systems T30. Low acceptance of devices / equipment / procedures 4
V7 Collected data is insufficient or incorrect [lack of adequate controls at data entry] T10. Use erroneous and/or unreliable data 4
V7 Collected data is insufficient or incorrect [lack of adequate controls at data entry] T12. Non-compliance with data protection legislation 4
V7 Collected data is insufficient or incorrect [lack of adequate controls at data entry] T11. Procedures / instructions not followed 3
V7 Collected data is insufficient or incorrect [lack of adequate controls at data entry] T14. Unauthorized check-in and boarding / identity theft 4
V7 Collected data is insufficient or incorrect [lack of adequate controls at data entry] T23. E-visa not accepted at check in 3
V8 Dependency on power systems T1. Denial of service attack / Flood / Buffer overflow 3
V8 Dependency on power systems T22. Malfunctioning/breakdown of systems /devices / equipment 4
V8 Dependency on power systems T25. Malicious attack on power systems 3
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T2. Spoofing of credentials / bypass authentication 5
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T3. Large-scale and/or inappropriate data mining and/or surveillance 4
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T5. Man-in-the-middle attack 3
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T6. Social engineering attack 4
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T7. Theft [of cards, devices etc] 4
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T9. Loss or misuse [of cards, devices etc] 3
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T10. Use erroneous and/or unreliable data 4
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T14. Unauthorized check-in and boarding / identity theft 4
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T15. Cloning of credentials and tags (RFID related) 3
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T17. Side channel attack 2
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T18. Blocking 2
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T19. Jamming 2
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag 3
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T21. Physical RFID tag destruction 4
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T24. Worms, viruses & malicious code 3
V9 Lack of or inadequate logical access (identification, authentication and authorisation) and physical access controls T29. Ad hoc network routing attack 2
V10 Flawed/insufficient design and/or capacity of devices and systems T1. Denial of service attack / Flood / Buffer overflow 3
V10 Flawed/insufficient design and/or capacity of devices and systems T11. Procedures / instructions not followed 3
V10 Flawed/insufficient design and/or capacity of devices and systems T12. Non-compliance with data protection legislation 4
V10 Flawed/insufficient design and/or capacity of devices and systems T22. Malfunctioning/breakdown of systems /devices / equipment 4
V10 Flawed/insufficient design and/or capacity of devices and systems T25. Malicious attack on power systems 3
V10 Flawed/insufficient design and/or capacity of devices and systems T28. Adverse weather condition or other disaster 4
V11 Lack of adequate controls in biometrics' enrolment stage T2. Spoofing of credentials / bypass authentication 5
V11 Lack of adequate controls in biometrics' enrolment stage T3. Large-scale and/or inappropriate data mining and/or surveillance 4
V11 Lack of adequate controls in biometrics' enrolment stage T11. Procedures / instructions not followed 3
V11 Lack of adequate controls in biometrics' enrolment stage T12. Non-compliance with data protection legislation 4
V11 Lack of adequate controls in biometrics' enrolment stage T14. Unauthorized check-in and boarding / identity theft 4
V11 Lack of adequate controls in biometrics' enrolment stage T30. Low acceptance of devices / equipment / procedures 4
V12 Lack of harmonisation and interoperability of procedures T9. Loss or misuse [of cards, devices etc] 3
V12 Lack of harmonisation and interoperability of procedures T10. Use erroneous and/or unreliable data 4
V12 Lack of harmonisation and interoperability of procedures T11. Procedures / instructions not followed 3
V12 Lack of harmonisation and interoperability of procedures T12. Non-compliance with data protection legislation 4
V12 Lack of harmonisation and interoperability of procedures T30. Low acceptance of devices / equipment / procedures 4
V12 Lack of harmonisation and interoperability of procedures T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V13 Lack of or inappropriate protection of RFID tags T1. Denial of service attack / Flood / Buffer overflow 3
V13 Lack of or inappropriate protection of RFID tags T2. Spoofing of credentials / bypass authentication 5
V13 Lack of or inappropriate protection of RFID tags T4. Traffic analysis / scan / probe 3
V13 Lack of or inappropriate protection of RFID tags T5. Man-in-the-middle attack 3
V13 Lack of or inappropriate protection of RFID tags T15. Cloning of credentials and tags (RFID related) 3
V13 Lack of or inappropriate protection of RFID tags T17. Side channel attack 2
V13 Lack of or inappropriate protection of RFID tags T18. Blocking 2
V13 Lack of or inappropriate protection of RFID tags T19. Jamming 2
V13 Lack of or inappropriate protection of RFID tags T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag 3
V13 Lack of or inappropriate protection of RFID tags T21. Physical RFID tag destruction 4
V13 Lack of or inappropriate protection of RFID tags T22. Malfunctioning/breakdown of systems /devices / equipment 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T2. Spoofing of credentials / bypass authentication 5
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T3. Large-scale and/or inappropriate data mining and/or surveillance 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T5. Man-in-the-middle attack 3
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T6. Social engineering attack 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T9. Loss or misuse [of cards, devices etc] 3
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T7. Theft [of cards, devices etc] 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T10. Use erroneous and/or unreliable data 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T11. Procedures / instructions not followed 3
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T12. Non-compliance with data protection legislation 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T14. Unauthorized check-in and boarding / identity theft 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T16. Unauthorised access to other restricted areas (apart from boarding e.g. Control room, personnel's' offices) 3
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T22. Malfunctioning/breakdown of systems /devices / equipment 4
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T23. E-visa not accepted at check in 3
V14 Lack of sufficiently skilled and/or trained personnel [airport, airline] T27. Trade union/labour strikes 3
V15 Insufficient equipment T11. Procedures / instructions not followed 3
V15 Insufficient equipment T30. Low acceptance of devices / equipment / procedures 4
V16 Inappropriate expansion of the trust perimeter T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V16 Inappropriate expansion of the trust perimeter T14. Unauthorized check-in and boarding / identity theft 4
V16 Inappropriate expansion of the trust perimeter T6. Social engineering attack 4
V17 Lack of dependable sensors, GPS T22. Malfunctioning/breakdown of systems /devices / equipment 4
V17 Lack of dependable sensors, GPS T4. Traffic analysis / scan / probe 3
V18 Lack of respect to the data minimisation and proportionality principles T3. Large-scale and/or inappropriate data mining and/or surveillance 4
V18 Lack of respect to the data minimisation and proportionality principles T12. Non-compliance with data protection legislation 4
V18 Lack of respect to the data minimisation and proportionality principles T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V18 Lack of respect to the data minimisation and proportionality principles T26. State surveillance on citizens 5
V18 Lack of respect to the data minimisation and proportionality principles T30. Low acceptance of devices / equipment / procedures 4
V18 Lack of respect to the data minimisation and proportionality principles T31. Data linkability 4
V18 Lack of respect to the data minimisation and proportionality principles T32. Profiling 4
V18 Lack of respect to the data minimisation and proportionality principles T33. Exclusion of the data subject from the data processing process 4
V19 Lack of respect to the purpose limitation (finality principle) T2. Spoofing of credentials / bypass authentication 5
V19 Lack of respect to the purpose limitation (finality principle) T3. Large-scale and/or inappropriate data mining and/or surveillance 4
V19 Lack of respect to the purpose limitation (finality principle) T6. Social engineering attack 4
V19 Lack of respect to the purpose limitation (finality principle) T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V19 Lack of respect to the purpose limitation (finality principle) T12. Non-compliance with data protection legislation 4
V19 Lack of respect to the purpose limitation (finality principle) T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V19 Lack of respect to the purpose limitation (finality principle) T26. State surveillance on citizens 5
V19 Lack of respect to the purpose restriction principle (purpose limitation principle) T32. Profiling 4
V19 Lack of respect to the purpose restriction principle (purpose limitation principle) T33. Exclusion of the data subject from the data processing process 4
V20 Lack of respect to the transparency principle T3. Large-scale and/or inappropriate data mining and/or surveillance 4
V20 Lack of respect to the transparency principle T11. Procedures / instructions not followed 3
V20 Lack of respect to the transparency principle T12. Non-compliance with data protection legislation 4
V20 Lack of respect to the transparency principle T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V20 Lack of respect to the transparency principle T26. State surveillance on citizens 5
V20 Lack of respect to the transparency principle T30. Low acceptance of devices / equipment / procedures 4
V20 Lack of respect to the transparency principle T31. Data linkability 4
V20 Lack of respect to the transparency principle T32. Profiling 4
V20 Lack of respect to the transparency principle T33. Exclusion of the data subject from the data processing process 4
V21 Inappropriate / inadequate identity management T2. Spoofing of credentials / bypass authentication 5
V21 Inappropriate / inadequate identity management T5. Man-in-the-middle attack 3
V21 Inappropriate / inadequate identity management T6. Social engineering attack 4
V21 Inappropriate / inadequate identity management T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V21 Inappropriate / inadequate identity management T14. Unauthorized check-in and boarding / identity theft 4
V21 Inappropriate / inadequate identity management T33. Exclusion of the data subject from the data processing process 4
V21 Inappropriate / inadequate identity management T34. Trivialisation of unique identifiers 4
V22 Inadequacy of RF traffic regulations T18. Blocking 2
V22 Inadequacy of RF traffic regulations T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V23 Over dependency on biometrics T3. Large-scale and/or inappropriate data mining and/or surveillance 4
V23 Over dependency on biometrics T11. Procedures / instructions not followed 3
V23 Over dependency on biometrics T12. Non-compliance with data protection legislation 4
V23 Over dependency on biometrics T14. Unauthorized check-in and boarding / identity theft 4
V23 Over dependency on biometrics T30. Low acceptance of devices / equipment / procedures 4
V24 0 T2. Spoofing of credentials / bypass authentication 5
V24 0 T6. Social engineering attack 4
V24 0 T7. Theft [of cards, devices etc] 4
V24 0 T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V24 0 T9. Loss or misuse [of cards, devices etc] 3
V24 0 T14. Unauthorized check-in and boarding / identity theft 4
V24 0 T15. Cloning of credentials and tags (RFID related) 3
V24 0 T16. Unauthorised access to other restricted areas (apart from boarding e.g. Control room, personnel's' offices) 3
V24 0 T21. Physical RFID tag destruction 4
V25 Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (especially for RFID tags) T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V25 Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (especially for RFID tags) T5. Man-in-the-middle attack 3
V25 Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (especially for RFID tags) T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag 3
V26 Actual RFID range longer than standard T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag 3
V27 RFID tags do not have a turn-off option T15. Cloning of credentials and tags (RFID related) 3
V27 RFID tags do not have a turn-off option T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag 3
V28 Insufficient protection against reverse engineering T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V28 Insufficient protection against reverse engineering T12. Non-compliance with data protection legislation 4
V29 Inadequate security measures of data storage (e.g. inadequate encryption measures) T9. Loss or misuse [of cards, devices etc] 3
V29 Inadequate security measures of data storage (e.g. inadequate encryption measures) T11. Procedures / instructions not followed 3
V29 Inadequate security measures of data storage (e.g. inadequate encryption measures) T30. Low acceptance of devices / equipment / procedures 4
V30 Over-sensitivity of devices (generating many false alarms) T22. Malfunctioning/breakdown of systems /devices / equipment 4
V31 Sensitivity to magnetic fields T4. Traffic analysis / scan / probe 3
V31 Sensitivity to magnetic fields T5. Man-in-the-middle attack 3
V31 Sensitivity to magnetic fields T6. Social engineering attack 4
V31 Sensitivity to magnetic fields T7. Theft [of cards, devices etc] 4
V31 Sensitivity to magnetic fields T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V31 Sensitivity to magnetic fields T10. Use erroneous and/or unreliable data 4
V31 Sensitivity to magnetic fields T15. Cloning of credentials and tags (RFID related) 3
V31 Sensitivity to magnetic fields T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag 3
V31 Sensitivity to magnetic fields T24. Worms, viruses & malicious code 3
V32 Devices & equipment used in unprotected environments T9. Loss or misuse [of cards, devices etc] 3
V32 Devices & equipment used in unprotected environments T22. Malfunctioning/breakdown of systems /devices / equipment 4
V32 Devices & equipment used in unprotected environments T30. Low acceptance of devices / equipment / procedures 4
V33 High error rates of biometric identification (esp. face-based recognition) T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V33 High error rates of biometric identification (esp. face-based recognition) T14. Unauthorized check-in and boarding / identity theft 4
V33 High error rates of biometric identification (esp. face-based recognition) T11. Procedures / instructions not followed 3
V33 High error rates of biometric identification (esp. face-based recognition) T30. Low acceptance of devices / equipment / procedures 4
V34 Communication of data over unprotected or publicly accessible channels T1. Denial of service attack / Flood / Buffer overflow 3
V34 Communication of data over unprotected or publicly accessible channels T4. Traffic analysis / scan / probe 3
V34 Communication of data over unprotected or publicly accessible channels T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V34 Communication of data over unprotected or publicly accessible channels T10. Use erroneous and/or unreliable data 4
V34 Communication of data over unprotected or publicly accessible channels T12. Non-compliance with data protection legislation 4
V34 Communication of data over unprotected or publicly accessible channels T19. Jamming 2
V34 Communication of data over unprotected or publicly accessible channels T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag 3
V34 Communication of data over unprotected or publicly accessible channels T24. Worms, viruses & malicious code 3
V35 Data linkability T3. Large-scale and/or inappropriate data mining and/or surveillance 4
V35 Data linkability T12. Non-compliance with data protection legislation 4
V35 Data linkability T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V35 Data linkability T26. State surveillance on citizens 5
V35 Data linkability T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V36 Lack of data correction mechanisms (as normally data subjects do not have access to the databases) T10. Use erroneous and/or unreliable data 4
V36 Lack of data correction mechanisms (as normally data subjects do not have access to the databases) T12. Non-compliance with data protection legislation 4
V36 Lack of data correction mechanisms (as normally data subjects do not have access to the databases) T23. E-visa not accepted at check in 3
V36 Lack of data correction mechanisms (as normally data subjects do not have access to the databases) T30. Low acceptance of devices / equipment / procedures 4
V37 Failure of biometrics sensors T2. Spoofing of credentials / bypass authentication 5
V37 Failure of biometrics sensors T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V37 Failure of biometrics sensors T10. Use erroneous and/or unreliable data 4
V37 Failure of biometrics sensors T14. Unauthorized check-in and boarding / identity theft 4
V38 Lack of common or harmonised legislation in EU Member States T10. Use erroneous and/or unreliable data 4
V38 Lack of common or harmonised legislation in EU Member States T11. Procedures / instructions not followed 3
V38 Lack of common or harmonised legislation in EU Member States T12. Non-compliance with data protection legislation 4
V38 Lack of common or harmonised legislation in EU Member States T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V38 Lack of common or harmonised legislation in EU Member States T30. Low acceptance of devices / equipment / procedures 4
V38 Lack of common or harmonised legislation in EU Member States T32. Profiling 4
V38 Lack of common or harmonised legislation in EU Member States T34. Trivialisation of unique identifiers 4
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T1. Denial of service attack / Flood / Buffer overflow 3
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T4. Traffic analysis / scan / probe 3
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T8. Unauthorised access to / deletion / modification of devices / data etc. 4
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T10. Use erroneous and/or unreliable data 4
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T12. Non-compliance with data protection legislation 4
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T19. Jamming 2
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag 3
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T24. Worms, viruses & malicious code 3
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T29. Ad hoc network routing attack 2
V39 Insufficient protection of wireless networks and communication (weak or no encryption etc.) T2. Spoofing of credentials / bypass authentication 5
V40 Lack of respect to the legitimacy of data processing, e.g. consent T12. Non-compliance with data protection legislation 4
V40 Lack of respect to the legitimacy of data processing, e.g. consent T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V40 Lack of respect to the legitimacy of data processing, e.g. consent T31. Data linkability 4
V40 Lack of respect to the legitimacy of data processing, e.g. consent T32. Profiling 4
V40 Lack of respect to the legitimacy of data processing, e.g. consent T33. Exclusion of the data subject from the data processing process 4
V41 Lack of respect to the data conservation principle T12. Non-compliance with data protection legislation 4
V41 Lack of respect to the data conservation principle T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V41 Lack of respect to the data conservation principle T32. Profiling 4
V41 Lack of respect to the data conservation principle T33. Exclusion of the data subject from the data processing process 4
V42 Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). T12. Non-compliance with data protection legislation 4
V42 Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). T13. Function creep (data used for other purposes than the ones for which they were originally collected) 4
V42 Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). T31. Data linkability 4
V42 Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). T32. Profiling 4
V42 Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). T33. Exclusion of the data subject from the data processing process 4
V42 Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). T34. Trivialisation of unique identifiers 4

Risk Assessment

Identification & Assessment of Risks (Asset-Threat-Vulnerability)
Asset ID Asset Description Asset Value Vulnerability Description V code V-ID A/V-ID A/V Value Threats T code T-ID Threat Value A/V/T ID Risk Value Risk Value (Final)
A1 Automated reservation, check-in and boarding procedure 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A1V1 3 T6. Social engineering attack T6. T6 4 A1.V1.T6 8 8
A1 Automated reservation, check-in and boarding procedure 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A1V1 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V1.T8 8 8
A1 Automated reservation, check-in and boarding procedure 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A1V1 3 T11. Procedures / instructions not followed T11 T11 3 A1.V1.T11 7 7
A1 Automated reservation, check-in and boarding procedure 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A1V1 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V1.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A1V1 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A1.V1.T13 9 9
A1 Automated reservation, check-in and boarding procedure 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A1V1 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V1.T14 9 9
A1 Automated reservation, check-in and boarding procedure 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A1V1 3 T27. Trade union/labor strikes T27 T27 3 A1.V1.T27 8 8
A1 Automated reservation, check-in and boarding procedure 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A1V10 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A1.V10.T1 8 8
A1 Automated reservation, check-in and boarding procedure 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A1V10 3 T11. Procedures / instructions not followed T11 T11 3 A1.V10.T11 7 7
A1 Automated reservation, check-in and boarding procedure 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A1V10 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V10.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A1V10 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A1.V10.T22 9 9
A1 Automated reservation, check-in and boarding procedure 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A1V10 3 T25. Malicious power failure attack T25 T25 3 A1.V10.T25 8 8
A1 Automated reservation, check-in and boarding procedure 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A1V10 3 T28. Adverse weather condition or other disaster T28 T28 4 A1.V10.T28 9 9
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A1.V12.T9 7 7
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V12.T10 8 8
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T11. Procedures / instructions not followed T11 T11 3 A1.V12.T11 7 7
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V12.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V12.T30 8 8
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A1.V12.T9 7 7
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V12.T10 8 8
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T11. Procedures / instructions not followed T11 T11 3 A1.V12.T11 7 7
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V12.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V12.T30 8 8
A1 Automated reservation, check-in and boarding procedure 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A1V12 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A1.V12.T13 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A1.V14.T2 10 10
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A1.V14.T3 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T5. Man in the middle attack T5. T5 3 A1.V14.T5 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T6. Social engineering attack T6. T6 4 A1.V14.T6 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V14.T8 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A1.V14.T9 8 8
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T7. Theft [of cards, devices etc] T7. T7 4 A1.V14.T7 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V14.T10 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T11. Procedures / instructions not followed T11 T11 3 A1.V14.T11 8 8
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T12. Non-compliance with data protection legislation T12 T12 4 A1.V14.T12 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V14.T14 10 10
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A1.V14.T16 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A1.V14.T22 10 10
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T23. e-visa not accepted at check in T23 T23 3 A1.V14.T23 9 9
A1 Automated reservation, check-in and boarding procedure 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A1V14 4 T27. Trade union/labor strikes T27 T27 3 A1.V14.T27 9 9
A1 Automated reservation, check-in and boarding procedure 4 V15. Insufficient equipment V15 V15 A1V15 2 T11. Procedures / instructions not followed T11 T11 3 A1.V15.T11 6 6
A1 Automated reservation, check-in and boarding procedure 4 V15. Insufficient equipment V15 V15 A1V15 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V15.T30 7 7
A1 Automated reservation, check-in and boarding procedure 4 V16. Inappropriate expansion of the trust perimeter V16 V16 A1V16 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V16.T8 9 9
A1 Automated reservation, check-in and boarding procedure 4 V16. Inappropriate expansion of the trust perimeter V16 V16 A1V16 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V16.T14 10 10
A1 Automated reservation, check-in and boarding procedure 4 V16. Inappropriate expansion of the trust perimeter V16 V16 A1V16 4 T6. Social engineering attack T6. T6 4 A1.V16.T6 9 9
A1 Automated reservation, check-in and boarding procedure 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A1V18 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A1.V18.T3 9 9
A1 Automated reservation, check-in and boarding procedure 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A1V18 4 T12. Non-compliance with data protection legislation T12 T12 4 A1.V18.T12 9 9
A1 Automated reservation, check-in and boarding procedure 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A1V18 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A1.V18.T13 10 10
A1 Automated reservation, check-in and boarding procedure 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A1V18 4 T26. State surveillance on citizens T26 T26 5 A1.V18.T26 10 10
A1 Automated reservation, check-in and boarding procedure 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A1V18 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V18.T30 9 9
A1 Automated reservation, check-in and boarding procedure 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A1V19 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A1.V19.T2 10 10
A1 Automated reservation, check-in and boarding procedure 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A1V19 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A1.V19.T3 9 9
A1 Automated reservation, check-in and boarding procedure 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A1V19 4 T6. Social engineering attack T6. T6 4 A1.V19.T6 9 9
A1 Automated reservation, check-in and boarding procedure 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A1V19 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V19.T8 9 9
A1 Automated reservation, check-in and boarding procedure 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A1V19 4 T12. Non-compliance with data protection legislation T12 T12 4 A1.V19.T12 9 9
A1 Automated reservation, check-in and boarding procedure 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A1V19 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A1.V19.T13 10 10
A1 Automated reservation, check-in and boarding procedure 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A1V19 4 T26. State surveillance on citizens T26 T26 5 A1.V19.T26 10 10
A1 Automated reservation, check-in and boarding procedure 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A1V2 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A1.V2.T1 8 8
A1 Automated reservation, check-in and boarding procedure 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A1V2 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A1.V2.T2 9 9
A1 Automated reservation, check-in and boarding procedure 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A1V2 3 T5. Man in the middle attack T5. T5 3 A1.V2.T5 8 8
A1 Automated reservation, check-in and boarding procedure 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A1V2 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A1.V2.T22 9 9
A1 Automated reservation, check-in and boarding procedure 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A1V2 3 T24. Worms, viruses & malicious code T24 T24 3 A1.V2.T24 8 8
A1 Automated reservation, check-in and boarding procedure 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A1V2 3 T25. Malicious power failure attack T25 T25 3 A1.V2.T25 8 8
A1 Automated reservation, check-in and boarding procedure 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A1V2 3 T28. Adverse weather condition or other disaster T28 T28 4 A1.V2.T28 9 9
A1 Automated reservation, check-in and boarding procedure 4 V20. Lack of respect to the transparency principle V20 V20 A1V20 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A1.V20.T3 8 8
A1 Automated reservation, check-in and boarding procedure 4 V20. Lack of respect to the transparency principle V20 V20 A1V20 3 T11. Procedures / instructions not followed T11 T11 3 A1.V20.T11 7 7
A1 Automated reservation, check-in and boarding procedure 4 V20. Lack of respect to the transparency principle V20 V20 A1V20 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V20.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V20. Lack of respect to the transparency principle V20 V20 A1V20 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A1.V20.T13 9 9
A1 Automated reservation, check-in and boarding procedure 4 V20. Lack of respect to the transparency principle V20 V20 A1V20 3 T26. State surveillance on citizens T26 T26 5 A1.V20.T26 9 9
A1 Automated reservation, check-in and boarding procedure 4 V20. Lack of respect to the transparency principle V20 V20 A1V20 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V20.T30 8 8
A1 Automated reservation, check-in and boarding procedure 4 V21. Inappropriate / inadequate identity management V21 V21 A1V21 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A1.V21.T2 9 9
A1 Automated reservation, check-in and boarding procedure 4 V21. Inappropriate / inadequate identity management V21 V21 A1V21 3 T5. Man in the middle attack T5. T5 3 A1.V21.T5 8 8
A1 Automated reservation, check-in and boarding procedure 4 V21. Inappropriate / inadequate identity management V21 V21 A1V21 3 T6. Social engineering attack T6. T6 4 A1.V21.T6 8 8
A1 Automated reservation, check-in and boarding procedure 4 V21. Inappropriate / inadequate identity management V21 V21 A1V21 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V21.T8 8 8
A1 Automated reservation, check-in and boarding procedure 4 V21. Inappropriate / inadequate identity management V21 V21 A1V21 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V21.T14 9 9
A1 Automated reservation, check-in and boarding procedure 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A1V28 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V28.T8 8 8
A1 Automated reservation, check-in and boarding procedure 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A1V28 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V28.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V3. Lack of back-up / failover procedures V3. V3 A1V3 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A1.V3.T1 9 9
A1 Automated reservation, check-in and boarding procedure 4 V3. Lack of back-up / failover procedures V3. V3 A1V3 4 T6. Social engineering attack T6. T6 4 A1.V3.T6 9 9
A1 Automated reservation, check-in and boarding procedure 4 V3. Lack of back-up / failover procedures V3. V3 A1V3 4 T7. Theft [of cards, devices etc] T7. T7 4 A1.V3.T7 9 9
A1 Automated reservation, check-in and boarding procedure 4 V3. Lack of back-up / failover procedures V3. V3 A1V3 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A1.V3.T9 8 8
A1 Automated reservation, check-in and boarding procedure 4 V3. Lack of back-up / failover procedures V3. V3 A1V3 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A1.V3.T22 10 10
A1 Automated reservation, check-in and boarding procedure 4 V3. Lack of back-up / failover procedures V3. V3 A1V3 4 T23. e-visa not accepted at check in T23 T23 3 A1.V3.T23 9 9
A1 Automated reservation, check-in and boarding procedure 4 V3. Lack of back-up / failover procedures V3. V3 A1V3 4 T25. Malicious power failure attack T25 T25 3 A1.V3.T25 9 9
A1 Automated reservation, check-in and boarding procedure 4 V3. Lack of back-up / failover procedures V3. V3 A1V3 4 T28. Adverse weather condition or other disaster T28 T28 4 A1.V3.T28 10 10
A1 Automated reservation, check-in and boarding procedure 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A1V36 3 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V36.T10 8 8
A1 Automated reservation, check-in and boarding procedure 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A1V36 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V36.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A1V36 3 T23. e-visa not accepted at check in T23 T23 3 A1.V36.T23 8 8
A1 Automated reservation, check-in and boarding procedure 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A1V36 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V36.T30 8 8
A1 Automated reservation, check-in and boarding procedure 4 V37. Failure of biometrics sensors V37 V37 A1V37 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A1.V37.T2 9 9
A1 Automated reservation, check-in and boarding procedure 4 V37. Failure of biometrics sensors V37 V37 A1V37 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V37.T8 8 8
A1 Automated reservation, check-in and boarding procedure 4 V37. Failure of biometrics sensors V37 V37 A1V37 3 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V37.T10 8 8
A1 Automated reservation, check-in and boarding procedure 4 V37. Failure of biometrics sensors V37 V37 A1V37 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V37.T14 9 9
A1 Automated reservation, check-in and boarding procedure 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A1V38 4 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V38.T10 9 9
A1 Automated reservation, check-in and boarding procedure 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A1V38 4 T11. Procedures / instructions not followed T11 T11 3 A1.V38.T11 8 8
A1 Automated reservation, check-in and boarding procedure 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A1V38 4 T12. Non-compliance with data protection legislation T12 T12 4 A1.V38.T12 9 9
A1 Automated reservation, check-in and boarding procedure 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A1V38 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A1.V38.T13 10 10
A1 Automated reservation, check-in and boarding procedure 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A1V38 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V38.T30 9 9
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A1.V4.T2 10 10
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T6. Social engineering attack T6. T6 4 A1.V4.T6 9 9
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T7. Theft [of cards, devices etc] T7. T7 4 A1.V4.T7 9 9
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V4.T8 9 9
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A1.V4.T9 8 8
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V4.T10 9 9
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T11. Procedures / instructions not followed T11 T11 3 A1.V4.T11 8 8
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T12. Non-compliance with data protection legislation T12 T12 4 A1.V4.T12 9 9
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A1.V4.T13 10 10
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V4.T14 10 10
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A1.V4.T16 9 9
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A1.V4.T22 10 10
A1 Automated reservation, check-in and boarding procedure 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A1V4 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V4.T30 9 9
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A1.V39.T1 7 7
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T4. Traffic analysis / scan / probe T4. T4 3 A1.V39.T4 6 6
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V39.T8 7 7
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V39.T10 7 7
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T12. Non-compliance with data protection legislation T12 T12 4 A1.V39.T12 7 7
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T19. Jamming T19 T19 2 A1.V39.T19 5 5
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A1.V39.T20 7 7
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T24. Worms, viruses & malicious code T24 T24 3 A1.V39.T24 7 7
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T29. MANET/Adhoc network routing attack T29 T29 2 A1.V39.T29 5 5
A1 Automated reservation, check-in and boarding procedure 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A1V39 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A1.V39.T2 8 8
A1 Automated reservation, check-in and boarding procedure 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A1V5 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V5.T8 9 9
A1 Automated reservation, check-in and boarding procedure 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A1V5 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A1.V5.T9 8 8
A1 Automated reservation, check-in and boarding procedure 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A1V5 4 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V5.T10 9 9
A1 Automated reservation, check-in and boarding procedure 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A1V5 4 T11. Procedures / instructions not followed T11 T11 3 A1.V5.T11 8 8
A1 Automated reservation, check-in and boarding procedure 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A1V5 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V5.T14 10 10
A1 Automated reservation, check-in and boarding procedure 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A1V5 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V5.T30 9 9
A1 Automated reservation, check-in and boarding procedure 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A1V6 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A1.V6.T9 7 7
A1 Automated reservation, check-in and boarding procedure 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A1V6 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A1.V6.T22 9 9
A1 Automated reservation, check-in and boarding procedure 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A1V6 3 T11. Procedures / instructions not followed T11 T11 3 A1.V6.T11 7 7
A1 Automated reservation, check-in and boarding procedure 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A1V6 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V6.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A1V6 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A1.V6.T30 8 8
A1 Automated reservation, check-in and boarding procedure 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A1V7 3 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V7.T10 8 8
A1 Automated reservation, check-in and boarding procedure 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A1V7 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V7.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A1V7 3 T11. Procedures / instructions not followed T11 T11 3 A1.V7.T11 7 7
A1 Automated reservation, check-in and boarding procedure 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A1V7 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V7.T14 9 9
A1 Automated reservation, check-in and boarding procedure 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A1V7 3 T23. e-visa not accepted at check in T23 T23 3 A1.V7.T23 8 8
A1 Automated reservation, check-in and boarding procedure 4 V8. Dependency on power systems V8. V8 A1V8 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A1.V8.T1 9 9
A1 Automated reservation, check-in and boarding procedure 4 V8. Dependency on power systems V8. V8 A1V8 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A1.V8.T22 10 10
A1 Automated reservation, check-in and boarding procedure 4 V8. Dependency on power systems V8. V8 A1V8 4 T25. Malicious power failure attack T25 T25 3 A1.V8.T25 9 9
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A1.V9.T2 9 9
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A1.V9.T3 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T5. Man in the middle attack T5. T5 3 A1.V9.T5 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T6. Social engineering attack T6. T6 4 A1.V9.T6 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T7. Theft [of cards, devices etc] T7. T7 4 A1.V9.T7 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A1.V9.T8 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A1.V9.T9 7 7
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T10. Use erroneous and/or unreliable data T10 T10 4 A1.V9.T10 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A1.V9.T14 9 9
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A1.V9.T15 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T17. Side channel attack T17 T17 2 A1.V9.T17 7 7
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T18. Blocking T18 T18 2 A1.V9.T18 7 7
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T19. Jamming T19 T19 2 A1.V9.T19 6 6
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A1.V9.T20 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T21. Physical RFID tag destruction T21 T21 4 A1.V9.T21 9 9
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T24. Worms, viruses & malicious code T24 T24 3 A1.V9.T24 8 8
A1 Automated reservation, check-in and boarding procedure 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A1V9 3 T29. MANET/Adhoc network routing attack T29 T29 2 A1.V9.T29 6 6
A1 Automated reservation, check-in and boarding procedure 4 V20. Lack of respect to the transparency principle V20 V20 A1V20 3 T31. Data linkability T31 T31 4 A1.V20.T31 8 8
A1 Automated reservation, check-in and boarding procedure 4 V21. Inappropriate / inadequate identity management V21 V21 A1V21 3 T33. Exclusion of the data subject from the data processing process T33 T33 4 A1.V21.T33 8 8
A1 Automated reservation, check-in and boarding procedure 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A1V38 4 T32. Profiling T32 T32 4 A1.V38.T32 9 9
A1 Automated reservation, check-in and boarding procedure 4 V41. Lack of respect to the data conservation principle V41 V41 A1V41 3 T12. Non-compliance with data protection legislation T12 T12 4 A1.V41.T12 8 8
A1 Automated reservation, check-in and boarding procedure 4 V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). V42 V42 A1V42 4 T12. Non-compliance with data protection legislation T12 T12 4 A1.V42.T12 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A10.V21.T1 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A10.V21.T2 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T4. Traffic analysis / scan / probe T4. T4 3 A10.V21.T4 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T5. Man in the middle attack T5. T5 3 A10.V21.T5 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A10.V21.T15 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T17. Side channel attack T17 T17 2 A10.V21.T17 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T18. Blocking T18 T18 2 A10.V21.T18 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T19. Jamming T19 T19 2 A10.V21.T19 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A10.V21.T20 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T21. Physical RFID tag destruction T21 T21 4 A10.V21.T21 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A10.V21.T1 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A10.V21.T2 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T4. Traffic analysis / scan / probe T4. T4 3 A10.V21.T4 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T5. Man in the middle attack T5. T5 3 A10.V21.T5 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A10.V21.T15 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T17. Side channel attack T17 T17 2 A10.V21.T17 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T18. Blocking T18 T18 2 A10.V21.T18 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T19. Jamming T19 T19 2 A10.V21.T19 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A10.V21.T20 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T21. Physical RFID tag destruction T21 T21 4 A10.V21.T21 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A10.V21.T22 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A10.V24.T2 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T6. Social engineering attack T6. T6 4 A10.V24.T6 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T7. Theft [of cards, devices etc] T7. T7 4 A10.V24.T7 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A10.V24.T8 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A10.V24.T9 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T10. Use erroneous and/or unreliable data T10 T10 4 A10.V24.T10 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T11. Procedures / instructions not followed T11 T11 3 A10.V24.T11 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T12. Non-compliance with data protection legislation T12 T12 4 A10.V24.T12 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A10.V24.T13 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A10V24 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A10.V24.T14 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A10V6 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A10.V6.T9 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A10V6 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A10.V6.T22 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A10V6 3 T11. Procedures / instructions not followed T11 T11 3 A10.V6.T11 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A10V6 3 T12. Non-compliance with data protection legislation T12 T12 4 A10.V6.T12 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A10V6 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A10.V6.T30 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A10.V31.T2 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A10.V31.T3 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T5. Man in the middle attack T5. T5 3 A10.V31.T5 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T6. Social engineering attack T6. T6 4 A10.V31.T6 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T7. Theft [of cards, devices etc] T7. T7 4 A10.V31.T7 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A10.V31.T8 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A10.V31.T9 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T10. Use erroneous and/or unreliable data T10 T10 4 A10.V31.T10 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A10.V31.T14 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A10.V31.T15 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T17. Side channel attack T17 T17 2 A10.V31.T17 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T18. Blocking T18 T18 2 A10.V31.T18 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T19. Jamming T19 T19 2 A10.V31.T19 6 6
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A10.V31.T20 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T21. Physical RFID tag destruction T21 T21 4 A10.V31.T21 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T24. Worms, viruses & malicious code T24 T24 3 A10.V31.T24 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T29. MANET/Adhoc network routing attack T29 T29 2 A10.V31.T29 6 6
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A10.V31.T20 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V31. Devices & equipment used in unprotected environments V31 V31 A10V31 3 T24. Worms, viruses & malicious code T24 T24 3 A10.V31.T24 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A10.V13.T1 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A10.V13.T2 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T4. Traffic analysis / scan / probe T4. T4 3 A10.V13.T4 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T5. Man in the middle attack T5. T5 3 A10.V13.T5 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A10.V13.T15 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T17. Side channel attack T17 T17 2 A10.V13.T17 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T18. Blocking T18 T18 2 A10.V13.T18 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T19. Jamming T19 T19 2 A10.V13.T19 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A10.V13.T20 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T21. Physical RFID tag destruction T21 T21 4 A10.V13.T21 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A10V13 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A10.V13.T22 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A10.V12.T9 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T10. Use erroneous and/or unreliable data T10 T10 4 A10.V12.T10 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T11. Procedures / instructions not followed T11 T11 3 A10.V12.T11 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A10.V12.T12 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A10.V12.T30 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A10.V12.T9 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T10. Use erroneous and/or unreliable data T10 T10 4 A10.V12.T10 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T11. Procedures / instructions not followed T11 T11 3 A10.V12.T11 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A10.V12.T12 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A10.V12.T30 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A10V12 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A10.V12.T13 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A10V18 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A10.V18.T30 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A10.V21.T2 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T5. Man in the middle attack T5. T5 3 A10.V21.T5 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T6. Social engineering attack T6. T6 4 A10.V21.T6 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A10.V21.T8 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V21. Inappropriate / inadequate identity management V21 V21 A10V21 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A10.V21.T14 10 10
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V22. Collision of tag traffic / Radio-frequency interference V22 V22 A10V22 2 T18. Blocking T18 T18 2 A10.V22.T18 6 6
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V22. Collision of tag traffic / Radio-frequency interference V22 V22 A10V22 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A10.V22.T13 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A10V38 3 T10. Use erroneous and/or unreliable data T10 T10 4 A10.V38.T10 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A10V38 3 T11. Procedures / instructions not followed T11 T11 3 A10.V38.T11 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A10V38 3 T12. Non-compliance with data protection legislation T12 T12 4 A10.V38.T12 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A10V38 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A10.V38.T13 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A10V38 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A10.V38.T30 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A10.V39.T1 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T4. Traffic analysis / scan / probe T4. T4 3 A10.V39.T4 8 8
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A10.V39.T8 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T10. Use erroneous and/or unreliable data T10 T10 4 A10.V39.T10 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T12. Non-compliance with data protection legislation T12 T12 4 A10.V39.T12 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T19. Jamming T19 T19 2 A10.V39.T19 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A10.V39.T20 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T24. Worms, viruses & malicious code T24 T24 3 A10.V39.T24 9 9
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T29. MANET/Adhoc network routing attack T29 T29 2 A10.V39.T29 7 7
A10 Credit Cards/Debit card/Payment cards/'e-wallet' 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A10V39 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A10.V39.T2 10 10
A11 Other RFID cards 3 V21. Inappropriate / inadequate identity management V21 V21 A11V21 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A11.V21.T1 8 8
A11 Other RFID cards 3 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A11V4 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A11.V4.T13 8 8
A11 Other RFID cards 3 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A11V4 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A11.V4.T14 8 8
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A11.V24.T2 8 8
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T6. Social engineering attack T6. T6 4 A11.V24.T6 7 7
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T7. Theft [of cards, devices etc] T7. T7 4 A11.V24.T7 7 7
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A11.V24.T8 7 7
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A11.V24.T9 6 6
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A11.V24.T14 8 8
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A11.V24.T15 7 7
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A11.V24.T16 7 7
A11 Other RFID cards 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A11V24 3 T21. Physical RFID tag destruction T21 T21 4 A11.V24.T21 8 8
A11 Other RFID cards 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A11V6 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A11.V6.T9 6 6
A11 Other RFID cards 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A11V6 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A11.V6.T22 8 8
A11 Other RFID cards 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A11V6 3 T11. Procedures / instructions not followed T11 T11 3 A11.V6.T11 6 6
A11 Other RFID cards 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A11V6 3 T12. Non-compliance with data protection legislation T12 T12 4 A11.V6.T12 7 7
A11 Other RFID cards 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A11V6 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A11.V6.T30 7 7
A11 Other RFID cards 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A11V9 2 T24. Worms, viruses & malicious code T24 T24 3 A11.V9.T24 6 6
A11 Other RFID cards 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A11V9 2 T29. MANET/Adhoc network routing attack T29 T29 2 A11.V9.T29 4 4
A11 Other RFID cards 3 V25. Actual RFID range longer than standard V25 V25 A11V25 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A11.V25.T8 8 8
A11 Other RFID cards 3 V25. Actual RFID range longer than standard V25 V25 A11V25 4 T5. Man in the middle attack T5. T5 3 A11.V25.T5 8 8
A11 Other RFID cards 3 V25. Actual RFID range longer than standard V25 V25 A11V25 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A11.V25.T20 8 8
A11 Other RFID cards 3 V26. RFID tags do not have a turn-off option V26 V26 A11V26 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A11.V26.T20 7 7
A11 Other RFID cards 3 V27. Insufficient protection against reverse engineering V27 V27 A11V27 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A11.V27.T15 7 7
A11 Other RFID cards 3 V27. Insufficient protection against reverse engineering V27 V27 A11V27 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A11.V27.T20 7 7
A11 Other RFID cards 3 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A11V28 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A11.V28.T8 8 8
A11 Other RFID cards 3 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A11V28 4 T12. Non-compliance with data protection legislation T12 T12 4 A11.V28.T12 8 8
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T4. Traffic analysis / scan / probe T4. T4 3 A11.V31.T4 6 6
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T5. Man in the middle attack T5. T5 3 A11.V31.T5 7 7
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T6. Social engineering attack T6. T6 4 A11.V31.T6 7 7
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T7. Theft [of cards, devices etc] T7. T7 4 A11.V31.T7 7 7
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A11.V31.T8 7 7
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T10. Use erroneous and/or unreliable data T10 T10 4 A11.V31.T10 7 7
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A11.V31.T15 7 7
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A11.V31.T20 7 7
A11 Other RFID cards 3 V31. Devices & equipment used in unprotected environments V31 V31 A11V31 3 T24. Worms, viruses & malicious code T24 T24 3 A11.V31.T24 7 7
A11 Other RFID cards 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A11V12 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A11.V12.T9 6 6
A11 Other RFID cards 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A11V12 3 T10. Use erroneous and/or unreliable data T10 T10 4 A11.V12.T10 7 7
A11 Other RFID cards 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A11V12 3 T11. Procedures / instructions not followed T11 T11 3 A11.V12.T11 6 6
A11 Other RFID cards 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A11V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A11.V12.T12 7 7
A11 Other RFID cards 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A11V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A11.V12.T30 7 7
A11 Other RFID cards 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A11V12 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A11.V12.T13 8 8
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A11.V38.T3 7 7
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T12. Non-compliance with data protection legislation T12 T12 4 A11.V38.T12 7 7
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A11.V38.T13 8 8
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T26. State surveillance on citizens T26 T26 5 A11.V38.T26 8 8
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T10. Use erroneous and/or unreliable data T10 T10 4 A11.V38.T10 7 7
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T11. Procedures / instructions not followed T11 T11 3 A11.V38.T11 6 6
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T12. Non-compliance with data protection legislation T12 T12 4 A11.V38.T12 7 7
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A11.V38.T13 8 8
A11 Other RFID cards 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A11V38 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A11.V38.T30 7 7
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A11.V39.T1 7 7
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T4. Traffic analysis / scan / probe T4. T4 3 A11.V39.T4 6 6
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A11.V39.T8 7 7
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T10. Use erroneous and/or unreliable data T10 T10 4 A11.V39.T10 7 7
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T12. Non-compliance with data protection legislation T12 T12 4 A11.V39.T12 7 7
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T19. Jamming T19 T19 2 A11.V39.T19 5 5
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A11.V39.T20 7 7
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T24. Worms, viruses & malicious code T24 T24 3 A11.V39.T24 7 7
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T29. MANET/Adhoc network routing attack T29 T29 2 A11.V39.T29 5 5
A11 Other RFID cards 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A11V39 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A11.V39.T2 8 8
A12 Scanners & detectors 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A12V1 2 T6. Social engineering attack T6. T6 4 A12.V1.T6 6 6
A12 Scanners & detectors 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A12V1 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A12.V1.T8 6 6
A12 Scanners & detectors 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A12V1 2 T11. Procedures / instructions not followed T11 T11 3 A12.V1.T11 5 5
A12 Scanners & detectors 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A12V1 2 T12. Non-compliance with data protection legislation T12 T12 4 A12.V1.T12 6 6
A12 Scanners & detectors 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A12V1 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A12.V1.T13 7 7
A12 Scanners & detectors 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A12V1 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A12.V1.T14 7 7
A12 Scanners & detectors 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A12V1 2 T27. Trade union/labor strikes T27 T27 3 A12.V1.T27 6 6
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A12.V11.T1 8 8
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A12.V11.T2 9 9
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T5. Man in the middle attack T5. T5 3 A12.V11.T5 8 8
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A12.V11.T22 9 9
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T24. Worms, viruses & malicious code T24 T24 3 A12.V11.T24 8 8
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T25. Malicious power failure attack T25 T25 3 A12.V11.T25 8 8
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T28. Adverse weather condition or other disaster T28 T28 4 A12.V11.T28 9 9
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T12. Non-compliance with data protection legislation T12 T12 4 A12.V11.T12 8 8
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A12.V11.T14 9 9
A12 Scanners & detectors 3 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A12V11 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A12.V11.T30 8 8
A12 Scanners & detectors 3 V37. Failure of biometrics sensors V37 V37 A12V37 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A12.V37.T2 8 8
A12 Scanners & detectors 3 V37. Failure of biometrics sensors V37 V37 A12V37 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A12.V37.T8 7 7
A12 Scanners & detectors 3 V37. Failure of biometrics sensors V37 V37 A12V37 3 T10. Use erroneous and/or unreliable data T10 T10 4 A12.V37.T10 7 7
A12 Scanners & detectors 3 V37. Failure of biometrics sensors V37 V37 A12V37 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A12.V37.T14 8 8
A12 Scanners & detectors 3 V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] V32 V32 A12V32 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A12.V32.T9 7 7
A12 Scanners & detectors 3 V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] V32 V32 A12V32 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A12.V32.T22 9 9
A12 Scanners & detectors 3 V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] V32 V32 A12V32 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A12.V32.T30 8 8
A12 Scanners & detectors 3 V33. High error rates of biometric identification (esp. face-based recognition) V33 V33 A12V33 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A12.V33.T8 7 7
A12 Scanners & detectors 3 V33. High error rates of biometric identification (esp. face-based recognition) V33 V33 A12V33 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A12.V33.T14 8 8
A12 Scanners & detectors 3 V33. High error rates of biometric identification (esp. face-based recognition) V33 V33 A12V33 3 T11. Procedures / instructions not followed T11 T11 3 A12.V33.T11 6 6
A12 Scanners & detectors 3 V33. High error rates of biometric identification (esp. face-based recognition) V33 V33 A12V33 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A12.V33.T30 7 7
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A12.V29.T2 8 8
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T6. Social engineering attack T6. T6 4 A12.V29.T6 7 7
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T7. Theft [of cards, devices etc] T7. T7 4 A12.V29.T7 7 7
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A12.V29.T8 7 7
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A12.V29.T9 6 6
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T10. Use erroneous and/or unreliable data T10 T10 4 A12.V29.T10 7 7
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T11. Procedures / instructions not followed T11 T11 3 A12.V29.T11 6 6
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T12. Non-compliance with data protection legislation T12 T12 4 A12.V29.T12 7 7
A12 Scanners & detectors 3 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A12V29 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A12.V29.T13 8 8
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A12.V39.T14 8 8
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A12.V39.T16 7 7
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A12.V39.T22 8 8
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A12.V39.T30 7 7
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T12. Non-compliance with data protection legislation T12 T12 4 A12.V39.T12 7 7
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T19. Jamming T19 T19 2 A12.V39.T19 5 5
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A12.V39.T20 7 7
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T24. Worms, viruses & malicious code T24 T24 3 A12.V39.T24 7 7
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T29. MANET/Adhoc network routing attack T29 T29 2 A12.V39.T29 5 5
A12 Scanners & detectors 3 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A12V39 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A12.V39.T2 8 8
A12 Scanners & detectors 3 V22. Collision of tag traffic / Radio-frequency interference V22 V22 A12V22 3 T18. Blocking T18 T18 2 A12.V22.T18 6 6
A12 Scanners & detectors 3 V22. Collision of tag traffic / Radio-frequency interference V22 V22 A12V22 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A12.V22.T13 8 8
A12 Scanners & detectors 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A12V38 2 T10. Use erroneous and/or unreliable data T10 T10 4 A12.V38.T10 6 6
A12 Scanners & detectors 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A12V38 2 T11. Procedures / instructions not followed T11 T11 3 A12.V38.T11 5 5
A12 Scanners & detectors 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A12V38 2 T12. Non-compliance with data protection legislation T12 T12 4 A12.V38.T12 6 6
A12 Scanners & detectors 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A12V38 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A12.V38.T13 7 7
A12 Scanners & detectors 3 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A12V38 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A12.V38.T30 6 6
A12 Scanners & detectors 3 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A12V18 4 T31. Data linkability T31 T31 4 A12.V18.T31 8 8
A12 Scanners & detectors 3 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A12V18 4 T32. Profiling T32 T32 4 A12.V18.T32 8 8
A12 Scanners & detectors 3 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A12V18 4 T33. Exclusion of the data subject from the data processing process T33 T33 4 A12.V18.T33 8 8
A13 Networks 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A13V1 3 T6. Social engineering attack T6. T6 4 A13.V1.T6 8 8
A13 Networks 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A13V1 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A13.V1.T8 8 8
A13 Networks 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A13V1 3 T11. Procedures / instructions not followed T11 T11 3 A13.V1.T11 7 7
A13 Networks 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A13V1 3 T12. Non-compliance with data protection legislation T12 T12 4 A13.V1.T12 8 8
A13 Networks 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A13V1 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A13.V1.T13 9 9
A13 Networks 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A13V1 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A13.V1.T14 9 9
A13 Networks 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A13V1 3 T27. Trade union/labor strikes T27 T27 3 A13.V1.T27 8 8
A13 Networks 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A13V2 4 T28. Adverse weather condition or other disaster T28 T28 4 A13.V2.T28 10 10
A13 Networks 4 V3. Lack of back-up / failover procedures V3. V3 A13V3 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A13.V3.T1 8 8
A13 Networks 4 V3. Lack of back-up / failover procedures V3. V3 A13V3 3 T6. Social engineering attack T6. T6 4 A13.V3.T6 8 8
A13 Networks 4 V3. Lack of back-up / failover procedures V3. V3 A13V3 3 T7. Theft [of cards, devices etc] T7. T7 4 A13.V3.T7 8 8
A13 Networks 4 V3. Lack of back-up / failover procedures V3. V3 A13V3 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A13.V3.T9 7 7
A13 Networks 4 V3. Lack of back-up / failover procedures V3. V3 A13V3 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A13.V3.T22 9 9
A13 Networks 4 V3. Lack of back-up / failover procedures V3. V3 A13V3 3 T23. e-visa not accepted at check in T23 T23 3 A13.V3.T23 8 8
A13 Networks 4 V3. Lack of back-up / failover procedures V3. V3 A13V3 3 T25. Malicious power failure attack T25 T25 3 A13.V3.T25 8 8
A13 Networks 4 V3. Lack of back-up / failover procedures V3. V3 A13V3 3 T28. Adverse weather condition or other disaster T28 T28 4 A13.V3.T28 9 9
A13 Networks 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A13V4 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A13.V4.T13 10 10
A13 Networks 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A13V4 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A13.V4.T14 10 10
A13 Networks 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A13V5 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A13.V5.T8 9 9
A13 Networks 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A13V5 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A13.V5.T9 8 8
A13 Networks 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A13V5 4 T10. Use erroneous and/or unreliable data T10 T10 4 A13.V5.T10 9 9
A13 Networks 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A13V5 4 T11. Procedures / instructions not followed T11 T11 3 A13.V5.T11 8 8
A13 Networks 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A13V5 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A13.V5.T14 10 10
A13 Networks 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A13V5 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A13.V5.T30 9 9
A13 Networks 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A13V6 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A13.V6.T9 7 7
A13 Networks 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A13V6 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A13.V6.T22 9 9
A13 Networks 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A13V6 3 T11. Procedures / instructions not followed T11 T11 3 A13.V6.T11 7 7
A13 Networks 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A13V6 3 T12. Non-compliance with data protection legislation T12 T12 4 A13.V6.T12 8 8
A13 Networks 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A13V6 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A13.V6.T30 8 8
A13 Networks 4 V8. Dependency on power systems V8. V8 A13V8 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A13.V8.T1 8 8
A13 Networks 4 V8. Dependency on power systems V8. V8 A13V8 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A13.V8.T22 9 9
A13 Networks 4 V8. Dependency on power systems V8. V8 A13V8 3 T25. Malicious power failure attack T25 T25 3 A13.V8.T25 8 8
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A13.V21.T2 10 10
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A13.V21.T3 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T5. Man in the middle attack T5. T5 3 A13.V21.T5 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T6. Social engineering attack T6. T6 4 A13.V21.T6 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T7. Theft [of cards, devices etc] T7. T7 4 A13.V21.T7 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A13.V21.T8 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A13.V21.T9 8 8
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T10. Use erroneous and/or unreliable data T10 T10 4 A13.V21.T10 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A13.V21.T14 10 10
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A13.V21.T15 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T17. Side channel attack T17 T17 2 A13.V21.T17 8 8
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T18. Blocking T18 T18 2 A13.V21.T18 8 8
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T19. Jamming T19 T19 2 A13.V21.T19 7 7
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A13.V21.T20 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T21. Physical RFID tag destruction T21 T21 4 A13.V21.T21 10 10
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T24. Worms, viruses & malicious code T24 T24 3 A13.V21.T24 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T29. MANET/Adhoc network routing attack T29 T29 2 A13.V21.T29 7 7
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T5. Man in the middle attack T5. T5 3 A13.V21.T5 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T6. Social engineering attack T6. T6 4 A13.V21.T6 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A13.V21.T8 9 9
A13 Networks 4 V21. Inappropriate / inadequate identity management V21 V21 A13V21 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A13.V21.T14 10 10
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A13.V39.T1 9 9
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T4. Traffic analysis / scan / probe T4. T4 3 A13.V39.T4 8 8
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A13.V39.T8 9 9
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T10. Use erroneous and/or unreliable data T10 T10 4 A13.V39.T10 9 9
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T12. Non-compliance with data protection legislation T12 T12 4 A13.V39.T12 9 9
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T19. Jamming T19 T19 2 A13.V39.T19 7 7
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A13.V39.T20 9 9
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T24. Worms, viruses & malicious code T24 T24 3 A13.V39.T24 9 9
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T29. MANET/Adhoc network routing attack T29 T29 2 A13.V39.T29 7 7
A13 Networks 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A13V39 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A13.V39.T2 10 10
A14 State databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A14V1 3 T6. Social engineering attack T6. T6 4 A14.V1.T6 8 8
A14 State databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A14V1 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A14.V1.T8 8 8
A14 State databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A14V1 3 T11. Procedures / instructions not followed T11 T11 3 A14.V1.T11 7 7
A14 State databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A14V1 3 T12. Non-compliance with data protection legislation T12 T12 4 A14.V1.T12 8 8
A14 State databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A14V1 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A14.V1.T13 9 9
A14 State databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A14V1 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A14.V1.T14 9 9
A14 State databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A14V1 3 T27. Trade union/labor strikes T27 T27 3 A14.V1.T27 8 8
A14 State databases 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A14V9 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A14.V9.T1 9 9
A14 State databases 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A14V9 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A14.V9.T2 10 10
A14 State databases 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A14V9 4 T5. Man in the middle attack T5. T5 3 A14.V9.T5 9 9
A14 State databases 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A14V9 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A14.V9.T22 10 10
A14 State databases 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A14V9 4 T24. Worms, viruses & malicious code T24 T24 3 A14.V9.T24 9 9
A14 State databases 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A14V9 4 T25. Malicious power failure attack T25 T25 3 A14.V9.T25 9 9
A14 State databases 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A14V9 4 T29. MANET/Adhoc network routing attack T29 T29 2 A14.V9.T29 7 7
A14 State databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A14V10 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A14.V10.T1 8 8
A14 State databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A14V10 3 T11. Procedures / instructions not followed T11 T11 3 A14.V10.T11 7 7
A14 State databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A14V10 3 T12. Non-compliance with data protection legislation T12 T12 4 A14.V10.T12 8 8
A14 State databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A14V10 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A14.V10.T22 9 9
A14 State databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A14V10 3 T25. Malicious power failure attack T25 T25 3 A14.V10.T25 8 8
A14 State databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A14V10 3 T28. Adverse weather condition or other disaster T28 T28 4 A14.V10.T28 9 9
A14 State databases 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A14V18 5 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A14.V18.T30 10 10
A14 State databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A14V19 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A14.V19.T2 10 10
A14 State databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A14V19 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A14.V19.T3 9 9
A14 State databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A14V19 4 T6. Social engineering attack T6. T6 4 A14.V19.T6 9 9
A14 State databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A14V19 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A14.V19.T8 9 9
A14 State databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A14V19 4 T12. Non-compliance with data protection legislation T12 T12 4 A14.V19.T12 9 9
A14 State databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A14V19 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A14.V19.T13 10 10
A14 State databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A14V19 4 T26. State surveillance on citizens T26 T26 5 A14.V19.T26 10 10
A14 State databases 4 V20. Lack of respect to the transparency principle V20 V20 A14V20 5 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A14.V20.T3 10 10
A14 State databases 4 V20. Lack of respect to the transparency principle V20 V20 A14V20 5 T11. Procedures / instructions not followed T11 T11 3 A14.V20.T11 9 9
A14 State databases 4 V20. Lack of respect to the transparency principle V20 V20 A14V20 5 T12. Non-compliance with data protection legislation T12 T12 4 A14.V20.T12 10 10
A14 State databases 4 V20. Lack of respect to the transparency principle V20 V20 A14V20 5 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A14.V20.T13 11 11
A14 State databases 4 V20. Lack of respect to the transparency principle V20 V20 A14V20 5 T26. State surveillance on citizens T26 T26 5 A14.V20.T26 11 11
A14 State databases 4 V20. Lack of respect to the transparency principle V20 V20 A14V20 5 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A14.V20.T30 10 10
A14 State databases 4 V20. Lack of respect to the transparency principle V20 V20 A14V20 5 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A14.V20.T8 10 10
A14 State databases 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A14V28 2 T12. Non-compliance with data protection legislation T12 T12 4 A14.V28.T12 7 7
A14 State databases 4 V35. High data linkability V35 V35 A14V35 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A14.V35.T3 9 9
A14 State databases 4 V35. High data linkability V35 V35 A14V35 4 T12. Non-compliance with data protection legislation T12 T12 4 A14.V35.T12 9 9
A14 State databases 4 V35. High data linkability V35 V35 A14V35 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A14.V35.T13 10 10
A14 State databases 4 V35. High data linkability V35 V35 A14V35 4 T26. State surveillance on citizens T26 T26 5 A14.V35.T26 10 10
A14 State databases 4 V35. High data linkability V35 V35 A14V35 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A14.V35.T8 9 9
A14 State databases 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A14V36 4 T10. Use erroneous and/or unreliable data T10 T10 4 A14.V36.T10 9 9
A14 State databases 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A14V36 4 T12. Non-compliance with data protection legislation T12 T12 4 A14.V36.T12 9 9
A14 State databases 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A14V36 4 T23. e-visa not accepted at check in T23 T23 3 A14.V36.T23 9 9
A14 State databases 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A14V36 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A14.V36.T30 9 9
A14 State databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A14V38 4 T10. Use erroneous and/or unreliable data T10 T10 4 A14.V38.T10 9 9
A14 State databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A14V38 4 T11. Procedures / instructions not followed T11 T11 3 A14.V38.T11 8 8
A14 State databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A14V38 4 T12. Non-compliance with data protection legislation T12 T12 4 A14.V38.T12 9 9
A14 State databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A14V38 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A14.V38.T13 10 10
A14 State databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A14V38 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A14.V38.T30 9 9
A15 Commercial and other databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A15V1 3 T6. Social engineering attack T6. T6 4 A15.V1.T6 8 8
A15 Commercial and other databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A15V1 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A15.V1.T8 8 8
A15 Commercial and other databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A15V1 3 T11. Procedures / instructions not followed T11 T11 3 A15.V1.T11 7 7
A15 Commercial and other databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A15V1 3 T12. Non-compliance with data protection legislation T12 T12 4 A15.V1.T12 8 8
A15 Commercial and other databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A15V1 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A15.V1.T13 9 9
A15 Commercial and other databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A15V1 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A15.V1.T14 9 9
A15 Commercial and other databases 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A15V1 3 T27. Trade union/labor strikes T27 T27 3 A15.V1.T27 8 8
A15 Commercial and other databases 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A15V2 4 T28. Adverse weather condition or other disaster T28 T28 4 A15.V2.T28 10 10
A15 Commercial and other databases 4 V3. Lack of back-up / failover procedures V3. V3 A15V3 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A15.V3.T1 8 8
A15 Commercial and other databases 4 V3. Lack of back-up / failover procedures V3. V3 A15V3 3 T6. Social engineering attack T6. T6 4 A15.V3.T6 8 8
A15 Commercial and other databases 4 V3. Lack of back-up / failover procedures V3. V3 A15V3 3 T7. Theft [of cards, devices etc] T7. T7 4 A15.V3.T7 8 8
A15 Commercial and other databases 4 V3. Lack of back-up / failover procedures V3. V3 A15V3 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A15.V3.T9 7 7
A15 Commercial and other databases 4 V3. Lack of back-up / failover procedures V3. V3 A15V3 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A15.V3.T22 9 9
A15 Commercial and other databases 4 V3. Lack of back-up / failover procedures V3. V3 A15V3 3 T23. e-visa not accepted at check in T23 T23 3 A15.V3.T23 8 8
A15 Commercial and other databases 4 V3. Lack of back-up / failover procedures V3. V3 A15V3 3 T25. Malicious power failure attack T25 T25 3 A15.V3.T25 8 8
A15 Commercial and other databases 4 V3. Lack of back-up / failover procedures V3. V3 A15V3 3 T28. Adverse weather condition or other disaster T28 T28 4 A15.V3.T28 9 9
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A15.V10.T2 9 9
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T6. Social engineering attack T6. T6 4 A15.V10.T6 8 8
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T7. Theft [of cards, devices etc] T7. T7 4 A15.V10.T7 8 8
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A15.V10.T8 8 8
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A15.V10.T9 7 7
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T10. Use erroneous and/or unreliable data T10 T10 4 A15.V10.T10 8 8
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T11. Procedures / instructions not followed T11 T11 3 A15.V10.T11 7 7
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T12. Non-compliance with data protection legislation T12 T12 4 A15.V10.T12 8 8
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A15.V10.T13 9 9
A15 Commercial and other databases 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A15V10 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A15.V10.T14 9 9
A15 Commercial and other databases 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A15V18 5 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A15.V18.T16 10 10
A15 Commercial and other databases 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A15V18 5 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A15.V18.T22 11 11
A15 Commercial and other databases 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A15V18 5 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A15.V18.T30 10 10
A15 Commercial and other databases 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A15V18 5 T26. State surveillance on citizens T26 T26 5 A15.V18.T26 11 11
A15 Commercial and other databases 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A15V18 5 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A15.V18.T30 10 10
A15 Commercial and other databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A15V19 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A15.V19.T2 10 10
A15 Commercial and other databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A15V19 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A15.V19.T3 9 9
A15 Commercial and other databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A15V19 4 T6. Social engineering attack T6. T6 4 A15.V19.T6 9 9
A15 Commercial and other databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A15V19 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A15.V19.T8 9 9
A15 Commercial and other databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A15V19 4 T12. Non-compliance with data protection legislation T12 T12 4 A15.V19.T12 9 9
A15 Commercial and other databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A15V19 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A15.V19.T13 10 10
A15 Commercial and other databases 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A15V19 4 T26. State surveillance on citizens T26 T26 5 A15.V19.T26 10 10
A15 Commercial and other databases 4 V20. Lack of respect to the transparency principle V20 V20 A15V20 5 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A15.V20.T3 10 10
A15 Commercial and other databases 4 V20. Lack of respect to the transparency principle V20 V20 A15V20 5 T11. Procedures / instructions not followed T11 T11 3 A15.V20.T11 9 9
A15 Commercial and other databases 4 V20. Lack of respect to the transparency principle V20 V20 A15V20 5 T12. Non-compliance with data protection legislation T12 T12 4 A15.V20.T12 10 10
A15 Commercial and other databases 4 V20. Lack of respect to the transparency principle V20 V20 A15V20 5 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A15.V20.T13 11 11
A15 Commercial and other databases 4 V20. Lack of respect to the transparency principle V20 V20 A15V20 5 T26. State surveillance on citizens T26 T26 5 A15.V20.T26 11 11
A15 Commercial and other databases 4 V20. Lack of respect to the transparency principle V20 V20 A15V20 5 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A15.V20.T30 10 10
A15 Commercial and other databases 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A15V28 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A15.V28.T8 7 7
A15 Commercial and other databases 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A15V28 2 T12. Non-compliance with data protection legislation T12 T12 4 A15.V28.T12 7 7
A15 Commercial and other databases 4 V35. High data linkability V35 V35 A15V35 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A15.V35.T3 9 9
A15 Commercial and other databases 4 V35. High data linkability V35 V35 A15V35 4 T12. Non-compliance with data protection legislation T12 T12 4 A15.V35.T12 9 9
A15 Commercial and other databases 4 V35. High data linkability V35 V35 A15V35 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A15.V35.T13 10 10
A15 Commercial and other databases 4 V35. High data linkability V35 V35 A15V35 4 T26. State surveillance on citizens T26 T26 5 A15.V35.T26 10 10
A15 Commercial and other databases 4 V35. High data linkability V35 V35 A15V35 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A15.V35.T8 9 9
A15 Commercial and other databases 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A15V36 4 T10. Use erroneous and/or unreliable data T10 T10 4 A15.V36.T10 9 9
A15 Commercial and other databases 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A15V36 4 T12. Non-compliance with data protection legislation T12 T12 4 A15.V36.T12 9 9
A15 Commercial and other databases 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A15V36 4 T23. e-visa not accepted at check in T23 T23 3 A15.V36.T23 9 9
A15 Commercial and other databases 4 V36. Lack of data correction mechanisms (as normally data subjects do not have access to the databases) V36 V36 A15V36 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A15.V36.T30 9 9
A15 Commercial and other databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A15V38 4 T10. Use erroneous and/or unreliable data T10 T10 4 A15.V38.T10 9 9
A15 Commercial and other databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A15V38 4 T11. Procedures / instructions not followed T11 T11 3 A15.V38.T11 8 8
A15 Commercial and other databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A15V38 4 T12. Non-compliance with data protection legislation T12 T12 4 A15.V38.T12 9 9
A15 Commercial and other databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A15V38 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A15.V38.T13 10 10
A15 Commercial and other databases 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A15V38 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A15.V38.T30 9 9
A16 Temporary handset airport guides 2 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A16V4 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A16.V4.T13 8 8
A16 Temporary handset airport guides 2 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A16V4 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A16.V4.T14 8 8
A16 Temporary handset airport guides 2 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A16V5 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A16.V5.T8 5 5
A16 Temporary handset airport guides 2 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A16V5 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A16.V5.T9 4 4
A16 Temporary handset airport guides 2 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A16V5 2 T10. Use erroneous and/or unreliable data T10 T10 4 A16.V5.T10 5 5
A16 Temporary handset airport guides 2 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A16V5 2 T11. Procedures / instructions not followed T11 T11 3 A16.V5.T11 4 4
A16 Temporary handset airport guides 2 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A16V5 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A16.V5.T14 6 6
A16 Temporary handset airport guides 2 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A16V5 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A16.V5.T30 5 5
A16 Temporary handset airport guides 2 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A16V6 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A16.V6.T9 4 4
A16 Temporary handset airport guides 2 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A16V6 2 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A16.V6.T22 6 6
A16 Temporary handset airport guides 2 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A16V6 2 T11. Procedures / instructions not followed T11 T11 3 A16.V6.T11 4 4
A16 Temporary handset airport guides 2 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A16V6 2 T12. Non-compliance with data protection legislation T12 T12 4 A16.V6.T12 5 5
A16 Temporary handset airport guides 2 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A16V6 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A16.V6.T30 5 5
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A17.V13.T1 7 7
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A17.V13.T2 8 8
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T4. Traffic analysis / scan / probe T4. T4 3 A17.V13.T4 6 6
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T5. Man in the middle attack T5. T5 3 A17.V13.T5 7 7
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A17.V13.T15 7 7
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T17. Side channel attack T17 T17 2 A17.V13.T17 6 6
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T18. Blocking T18 T18 2 A17.V13.T18 6 6
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T19. Jamming T19 T19 2 A17.V13.T19 5 5
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A17.V13.T20 7 7
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A17.V13.T1 7 7
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A17.V13.T2 8 8
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T4. Traffic analysis / scan / probe T4. T4 3 A17.V13.T4 6 6
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T5. Man in the middle attack T5. T5 3 A17.V13.T5 7 7
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A17.V13.T15 7 7
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T17. Side channel attack T17 T17 2 A17.V13.T17 6 6
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T18. Blocking T18 T18 2 A17.V13.T18 6 6
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T19. Jamming T19 T19 2 A17.V13.T19 5 5
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A17.V13.T20 7 7
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T21. Physical RFID tag destruction T21 T21 4 A17.V13.T21 8 8
A17 Luggage and goods 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A17V13 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A17.V13.T22 8 8
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A18.V1.T2 8 8
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A18.V1.T3 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T5. Man in the middle attack T5. T5 3 A18.V1.T5 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T6. Social engineering attack T6. T6 4 A18.V1.T6 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A18.V1.T8 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A18.V1.T9 6 6
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T7. Theft [of cards, devices etc] T7. T7 4 A18.V1.T7 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T10. Use erroneous and/or unreliable data T10 T10 4 A18.V1.T10 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T11. Procedures / instructions not followed T11 T11 3 A18.V1.T11 6 6
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T12. Non-compliance with data protection legislation T12 T12 4 A18.V1.T12 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V1.T14 8 8
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A18.V1.T16 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A18.V1.T22 8 8
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T23. e-visa not accepted at check in T23 T23 3 A18.V1.T23 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T27. Trade union/labor strikes T27 T27 3 A18.V1.T27 7 7
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V1.T14 8 8
A18 Check-in infrastructure 3 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A18V1 3 T27. Trade union/labor strikes T27 T27 3 A18.V1.T27 7 7
A18 Check-in infrastructure 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A18V2 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A18.V2.T1 8 8
A18 Check-in infrastructure 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A18V2 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A18.V2.T2 9 9
A18 Check-in infrastructure 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A18V2 4 T5. Man in the middle attack T5. T5 3 A18.V2.T5 8 8
A18 Check-in infrastructure 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A18V2 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A18.V2.T22 9 9
A18 Check-in infrastructure 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A18V2 4 T24. Worms, viruses & malicious code T24 T24 3 A18.V2.T24 8 8
A18 Check-in infrastructure 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A18V2 4 T25. Malicious power failure attack T25 T25 3 A18.V2.T25 8 8
A18 Check-in infrastructure 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A18V2 4 T28. Adverse weather condition or other disaster T28 T28 4 A18.V2.T28 9 9
A18 Check-in infrastructure 3 V3. Lack of back-up / failover procedures V3. V3 A18V3 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A18.V3.T1 7 7
A18 Check-in infrastructure 3 V3. Lack of back-up / failover procedures V3. V3 A18V3 3 T6. Social engineering attack T6. T6 4 A18.V3.T6 7 7
A18 Check-in infrastructure 3 V3. Lack of back-up / failover procedures V3. V3 A18V3 3 T7. Theft [of cards, devices etc] T7. T7 4 A18.V3.T7 7 7
A18 Check-in infrastructure 3 V3. Lack of back-up / failover procedures V3. V3 A18V3 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A18.V3.T9 6 6
A18 Check-in infrastructure 3 V3. Lack of back-up / failover procedures V3. V3 A18V3 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A18.V3.T22 8 8
A18 Check-in infrastructure 3 V3. Lack of back-up / failover procedures V3. V3 A18V3 3 T23. e-visa not accepted at check in T23 T23 3 A18.V3.T23 7 7
A18 Check-in infrastructure 3 V3. Lack of back-up / failover procedures V3. V3 A18V3 3 T25. Malicious power failure attack T25 T25 3 A18.V3.T25 7 7
A18 Check-in infrastructure 3 V3. Lack of back-up / failover procedures V3. V3 A18V3 3 T28. Adverse weather condition or other disaster T28 T28 4 A18.V3.T28 8 8
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A18.V12.T2 7 7
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T6. Social engineering attack T6. T6 4 A18.V12.T6 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T7. Theft [of cards, devices etc] T7. T7 4 A18.V12.T7 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A18.V12.T8 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A18.V12.T9 5 5
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T10. Use erroneous and/or unreliable data T10 T10 4 A18.V12.T10 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T11. Procedures / instructions not followed T11 T11 3 A18.V12.T11 5 5
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T12. Non-compliance with data protection legislation T12 T12 4 A18.V12.T12 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A18.V12.T13 7 7
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V12.T14 7 7
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A18.V12.T16 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A18.V12.T22 7 7
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A18.V12.T30 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T11. Procedures / instructions not followed T11 T11 3 A18.V12.T11 5 5
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T12. Non-compliance with data protection legislation T12 T12 4 A18.V12.T12 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A18.V12.T30 6 6
A18 Check-in infrastructure 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A18V12 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A18.V12.T13 7 7
A18 Check-in infrastructure 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A18V14 4 T27. Trade union/labor strikes T27 T27 3 A18.V14.T27 8 8
A18 Check-in infrastructure 3 V23. Over dependency on biometrics V23 V23 A18V23 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A18.V23.T3 8 8
A18 Check-in infrastructure 3 V23. Over dependency on biometrics V23 V23 A18V23 4 T11. Procedures / instructions not followed T11 T11 3 A18.V23.T11 7 7
A18 Check-in infrastructure 3 V23. Over dependency on biometrics V23 V23 A18V23 4 T12. Non-compliance with data protection legislation T12 T12 4 A18.V23.T12 8 8
A18 Check-in infrastructure 3 V23. Over dependency on biometrics V23 V23 A18V23 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V23.T14 9 9
A18 Check-in infrastructure 3 V23. Over dependency on biometrics V23 V23 A18V23 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A18.V23.T30 8 8
A18 Check-in infrastructure 3 V33. High error rates of biometric identification (esp. face-based recognition) V33 V33 A18V33 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A18.V33.T8 7 7
A18 Check-in infrastructure 3 V33. High error rates of biometric identification (esp. face-based recognition) V33 V33 A18V33 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V33.T14 8 8
A18 Check-in infrastructure 3 V33. High error rates of biometric identification (esp. face-based recognition) V33 V33 A18V33 3 T11. Procedures / instructions not followed T11 T11 3 A18.V33.T11 6 6
A18 Check-in infrastructure 3 V33. High error rates of biometric identification (esp. face-based recognition) V33 V33 A18V33 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A18.V33.T30 7 7
A18 Check-in infrastructure 3 V37. Failure of biometrics sensors V37 V37 A18V37 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A18.V37.T2 8 8
A18 Check-in infrastructure 3 V37. Failure of biometrics sensors V37 V37 A18V37 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A18.V37.T8 7 7
A18 Check-in infrastructure 3 V37. Failure of biometrics sensors V37 V37 A18V37 3 T10. Use erroneous and/or unreliable data T10 T10 4 A18.V37.T10 7 7
A18 Check-in infrastructure 3 V37. Failure of biometrics sensors V37 V37 A18V37 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V37.T14 8 8
A18 Check-in infrastructure 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A18V6 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A18.V6.T9 6 6
A18 Check-in infrastructure 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A18V6 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A18.V6.T22 8 8
A18 Check-in infrastructure 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A18V6 3 T11. Procedures / instructions not followed T11 T11 3 A18.V6.T11 6 6
A18 Check-in infrastructure 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A18V6 3 T12. Non-compliance with data protection legislation T12 T12 4 A18.V6.T12 7 7
A18 Check-in infrastructure 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A18V6 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A18.V6.T30 7 7
A18 Check-in infrastructure 3 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A18V7 2 T10. Use erroneous and/or unreliable data T10 T10 4 A18.V7.T10 6 6
A18 Check-in infrastructure 3 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A18V7 2 T12. Non-compliance with data protection legislation T12 T12 4 A18.V7.T12 6 6
A18 Check-in infrastructure 3 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A18V7 2 T11. Procedures / instructions not followed T11 T11 3 A18.V7.T11 5 5
A18 Check-in infrastructure 3 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A18V7 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V7.T14 7 7
A18 Check-in infrastructure 3 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A18V7 2 T23. e-visa not accepted at check in T23 T23 3 A18.V7.T23 6 6
A18 Check-in infrastructure 3 V8. Dependency on power systems V8. V8 A18V8 2 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A18.V8.T1 6 6
A18 Check-in infrastructure 3 V8. Dependency on power systems V8. V8 A18V8 2 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A18.V8.T22 7 7
A18 Check-in infrastructure 3 V8. Dependency on power systems V8. V8 A18V8 2 T25. Malicious power failure attack T25 T25 3 A18.V8.T25 6 6
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A18.V9.T1 7 7
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A18.V9.T2 8 8
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T5. Man in the middle attack T5. T5 3 A18.V9.T5 7 7
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A18.V9.T22 8 8
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T24. Worms, viruses & malicious code T24 T24 3 A18.V9.T24 7 7
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T25. Malicious power failure attack T25 T25 3 A18.V9.T25 7 7
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T28. Adverse weather condition or other disaster T28 T28 4 A18.V9.T28 8 8
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A18.V9.T13 8 8
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V9.T14 8 8
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A18.V9.T8 7 7
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A18.V9.T9 6 6
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T10. Use erroneous and/or unreliable data T10 T10 4 A18.V9.T10 7 7
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T11. Procedures / instructions not followed T11 T11 3 A18.V9.T11 6 6
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A18.V9.T14 8 8
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A18.V9.T30 7 7
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A18.V9.T9 6 6
A18 Check-in infrastructure 3 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A18V9 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A18.V9.T22 8 8
A19 Airport facilities 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A19V2 3 T11. Procedures / instructions not followed T11 T11 3 A19.V2.T11 6 6
A19 Airport facilities 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A19V2 3 T12. Non-compliance with data protection legislation T12 T12 4 A19.V2.T12 7 7
A19 Airport facilities 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A19V2 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A19.V2.T30 7 7
A19 Airport facilities 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A19V2 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A19.V2.T1 7 7
A19 Airport facilities 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A19V2 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A19.V2.T22 8 8
A19 Airport facilities 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A19V2 3 T25. Malicious power failure attack T25 T25 3 A19.V2.T25 7 7
A19 Airport facilities 3 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A19V2 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A19.V2.T2 8 8
A19 Airport facilities 3 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A19V4 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A19.V4.T3 8 8
A19 Airport facilities 3 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A19V4 4 T5. Man in the middle attack T5. T5 3 A19.V4.T5 8 8
A19 Airport facilities 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A19V5 3 T6. Social engineering attack T6. T6 4 A19.V5.T6 7 7
A19 Airport facilities 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A19V5 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A19.V5.T8 7 7
A19 Airport facilities 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A19V5 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A19.V5.T9 6 6
A19 Airport facilities 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A19V5 3 T7. Theft [of cards, devices etc] T7. T7 4 A19.V5.T7 7 7
A19 Airport facilities 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A19V5 3 T10. Use erroneous and/or unreliable data T10 T10 4 A19.V5.T10 7 7
A19 Airport facilities 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A19V5 3 T11. Procedures / instructions not followed T11 T11 3 A19.V5.T11 6 6
A19 Airport facilities 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A19V6 3 T12. Non-compliance with data protection legislation T12 T12 4 A19.V6.T12 7 7
A19 Airport facilities 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A19V6 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A19.V6.T14 8 8
A19 Airport facilities 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A19V6 3 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A19.V6.T16 7 7
A19 Airport facilities 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A19V6 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A19.V6.T22 8 8
A19 Airport facilities 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A19V6 3 T23. e-visa not accepted at check in T23 T23 3 A19.V6.T23 7 7
A19 Airport facilities 3 V8. Dependency on power systems V8. V8 A19V8 3 T27. Trade union/labor strikes T27 T27 3 A19.V8.T27 7 7
A19 Airport facilities 3 V8. Dependency on power systems V8. V8 A19V8 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A19.V8.T8 7 7
A19 Airport facilities 3 V8. Dependency on power systems V8. V8 A19V8 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A19.V8.T14 8 8
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T6. Social engineering attack T6. T6 4 A19.V14.T6 8 8
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A19.V14.T3 8 8
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T11. Procedures / instructions not followed T11 T11 3 A19.V14.T11 7 7
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T12. Non-compliance with data protection legislation T12 T12 4 A19.V14.T12 8 8
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A19.V14.T13 9 9
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T26. State surveillance on citizens T26 T26 5 A19.V14.T26 9 9
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A19.V14.T30 8 8
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A19.V14.T9 7 7
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A19.V14.T22 9 9
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A19.V14.T30 8 8
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A19.V14.T1 8 8
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A19.V14.T2 9 9
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T5. Man in the middle attack T5. T5 3 A19.V14.T5 8 8
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A19.V14.T22 9 9
A19 Airport facilities 3 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A19V14 4 T24. Worms, viruses & malicious code T24 T24 3 A19.V14.T24 8 8
A19 Airport facilities 3 V16. Inappropriate expansion of the trust perimeter V16 V16 A19V16 4 T25. Malicious power failure attack T25 T25 3 A19.V16.T25 8 8
A19 Airport facilities 3 V16. Inappropriate expansion of the trust perimeter V16 V16 A19V16 4 T28. Adverse weather condition or other disaster T28 T28 4 A19.V16.T28 9 9
A19 Airport facilities 3 V16. Inappropriate expansion of the trust perimeter V16 V16 A19V16 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A19.V16.T2 9 9
A19 Airport facilities 3 V20. Lack of respect to the transparency principle V20 V20 A19V20 2 T6. Social engineering attack T6. T6 4 A19.V20.T6 6 6
A19 Airport facilities 3 V20. Lack of respect to the transparency principle V20 V20 A19V20 2 T7. Theft [of cards, devices etc] T7. T7 4 A19.V20.T7 6 6
A19 Airport facilities 3 V20. Lack of respect to the transparency principle V20 V20 A19V20 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A19.V20.T8 6 6
A19 Airport facilities 3 V20. Lack of respect to the transparency principle V20 V20 A19V20 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A19.V20.T9 5 5
A19 Airport facilities 3 V20. Lack of respect to the transparency principle V20 V20 A19V20 2 T10. Use erroneous and/or unreliable data T10 T10 4 A19.V20.T10 6 6
A19 Airport facilities 3 V20. Lack of respect to the transparency principle V20 V20 A19V20 2 T11. Procedures / instructions not followed T11 T11 3 A19.V20.T11 5 5
A19 Airport facilities 3 V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] V32 V32 A19V32 4 T12. Non-compliance with data protection legislation T12 T12 4 A19.V32.T12 8 8
A19 Airport facilities 3 V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] V32 V32 A19V32 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A19.V32.T13 9 9
A19 Airport facilities 3 V32. Used by a great number of people every day [health issues (e.g. infectious diseases spread by fingerprint scanners)] V32 V32 A19V32 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A19.V32.T14 9 9
A2 Electronic visa issuing process 4 V8. Dependency on power systems V8. V8 A2V8 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A2.V8.T1 8 8
A2 Electronic visa issuing process 4 V8. Dependency on power systems V8. V8 A2V8 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A2.V8.T22 9 9
A2 Electronic visa issuing process 4 V8. Dependency on power systems V8. V8 A2V8 3 T25. Malicious power failure attack T25 T25 3 A2.V8.T25 8 8
A2 Electronic visa issuing process 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A2V1 5 T6. Social engineering attack T6. T6 4 A2.V1.T6 10 10
A2 Electronic visa issuing process 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A2V1 5 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A2.V1.T8 10 10
A2 Electronic visa issuing process 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A2V1 5 T11. Procedures / instructions not followed T11 T11 3 A2.V1.T11 9 9
A2 Electronic visa issuing process 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A2V1 5 T12. Non-compliance with data protection legislation T12 T12 4 A2.V1.T12 10 10
A2 Electronic visa issuing process 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A2V1 5 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A2.V1.T13 11 11
A2 Electronic visa issuing process 4 V1. Inappropriate design of procedures - includes: lack of accountability, high complexity of procedures, assigning extensive responsibilities to end-users (in critical parts of the procedures) etc. V1. V1 A2V1 5 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A2.V1.T14 11 11
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A2.V12.T9 8 8
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T10. Use erroneous and/or unreliable data T10 T10 4 A2.V12.T10 9 9
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T11. Procedures / instructions not followed T11 T11 3 A2.V12.T11 8 8
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T12. Non-compliance with data protection legislation T12 T12 4 A2.V12.T12 9 9
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V12.T30 9 9
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A2.V12.T9 8 8
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T10. Use erroneous and/or unreliable data T10 T10 4 A2.V12.T10 9 9
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T11. Procedures / instructions not followed T11 T11 3 A2.V12.T11 8 8
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T12. Non-compliance with data protection legislation T12 T12 4 A2.V12.T12 9 9
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V12.T30 9 9
A2 Electronic visa issuing process 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A2V12 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A2.V12.T13 10 10
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A2.V14.T2 10 10
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A2.V14.T3 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T5. Man in the middle attack T5. T5 3 A2.V14.T5 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T6. Social engineering attack T6. T6 4 A2.V14.T6 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A2.V14.T8 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A2.V14.T9 8 8
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T7. Theft [of cards, devices etc] T7. T7 4 A2.V14.T7 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T10. Use erroneous and/or unreliable data T10 T10 4 A2.V14.T10 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T11. Procedures / instructions not followed T11 T11 3 A2.V14.T11 8 8
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T12. Non-compliance with data protection legislation T12 T12 4 A2.V14.T12 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A2.V14.T14 10 10
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A2.V14.T16 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A2.V14.T22 10 10
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T23. e-visa not accepted at check in T23 T23 3 A2.V14.T23 9 9
A2 Electronic visa issuing process 4 V14. Lack of sufficiently skilled and/or trained personnel [airport, ariline] V14 V14 A2V14 4 T27. Trade union/labor strikes T27 T27 3 A2.V14.T27 9 9
A2 Electronic visa issuing process 4 V3. Lack of back-up / failover procedures V3. V3 A2V3 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A2.V3.T1 9 9
A2 Electronic visa issuing process 4 V3. Lack of back-up / failover procedures V3. V3 A2V3 4 T6. Social engineering attack T6. T6 4 A2.V3.T6 9 9
A2 Electronic visa issuing process 4 V3. Lack of back-up / failover procedures V3. V3 A2V3 4 T7. Theft [of cards, devices etc] T7. T7 4 A2.V3.T7 9 9
A2 Electronic visa issuing process 4 V3. Lack of back-up / failover procedures V3. V3 A2V3 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A2.V3.T9 8 8
A2 Electronic visa issuing process 4 V3. Lack of back-up / failover procedures V3. V3 A2V3 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A2.V3.T22 10 10
A2 Electronic visa issuing process 4 V3. Lack of back-up / failover procedures V3. V3 A2V3 4 T23. e-visa not accepted at check in T23 T23 3 A2.V3.T23 9 9
A2 Electronic visa issuing process 4 V3. Lack of back-up / failover procedures V3. V3 A2V3 4 T25. Malicious power failure attack T25 T25 3 A2.V3.T25 9 9
A2 Electronic visa issuing process 4 V3. Lack of back-up / failover procedures V3. V3 A2V3 4 T28. Adverse weather condition or other disaster T28 T28 4 A2.V3.T28 10 10
A2 Electronic visa issuing process 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A2V7 3 T10. Use erroneous and/or unreliable data T10 T10 4 A2.V7.T10 8 8
A2 Electronic visa issuing process 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A2V7 3 T12. Non-compliance with data protection legislation T12 T12 4 A2.V7.T12 8 8
A2 Electronic visa issuing process 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A2V7 3 T11. Procedures / instructions not followed T11 T11 3 A2.V7.T11 7 7
A2 Electronic visa issuing process 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A2V7 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A2.V7.T14 9 9
A2 Electronic visa issuing process 4 V7. Collected data is insufficient or incorrect [lack of adequate controls at data entry] V7. V7 A2V7 3 T23. e-visa not accepted at check in T23 T23 3 A2.V7.T23 8 8
A2 Electronic visa issuing process 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A2V5 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A2.V5.T8 8 8
A2 Electronic visa issuing process 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A2V5 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A2.V5.T9 7 7
A2 Electronic visa issuing process 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A2V5 3 T10. Use erroneous and/or unreliable data T10 T10 4 A2.V5.T10 8 8
A2 Electronic visa issuing process 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A2V5 3 T11. Procedures / instructions not followed T11 T11 3 A2.V5.T11 7 7
A2 Electronic visa issuing process 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A2V5 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A2.V5.T14 9 9
A2 Electronic visa issuing process 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A2V5 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V5.T30 8 8
A2 Electronic visa issuing process 4 V23. Over dependency on biometrics V23 V23 A2V23 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A2.V23.T3 8 8
A2 Electronic visa issuing process 4 V23. Over dependency on biometrics V23 V23 A2V23 3 T11. Procedures / instructions not followed T11 T11 3 A2.V23.T11 7 7
A2 Electronic visa issuing process 4 V23. Over dependency on biometrics V23 V23 A2V23 3 T12. Non-compliance with data protection legislation T12 T12 4 A2.V23.T12 8 8
A2 Electronic visa issuing process 4 V23. Over dependency on biometrics V23 V23 A2V23 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A2.V23.T14 9 9
A2 Electronic visa issuing process 4 V23. Over dependency on biometrics V23 V23 A2V23 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V23.T30 8 8
A2 Electronic visa issuing process 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A2V6 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A2.V6.T9 8 8
A2 Electronic visa issuing process 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A2V6 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A2.V6.T22 10 10
A2 Electronic visa issuing process 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A2V6 4 T11. Procedures / instructions not followed T11 T11 3 A2.V6.T11 8 8
A2 Electronic visa issuing process 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A2V6 4 T12. Non-compliance with data protection legislation T12 T12 4 A2.V6.T12 9 9
A2 Electronic visa issuing process 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A2V6 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V6.T30 9 9
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A2.V38.T2 9 9
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A2.V38.T3 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T5. Man in the middle attack T5. T5 3 A2.V38.T5 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T6. Social engineering attack T6. T6 4 A2.V38.T6 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T7. Theft [of cards, devices etc] T7. T7 4 A2.V38.T7 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A2.V38.T8 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A2.V38.T9 7 7
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T10. Use erroneous and/or unreliable data T10 T10 4 A2.V38.T10 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A2.V38.T14 9 9
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A2.V38.T15 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T17. Side channel attack T17 T17 2 A2.V38.T17 7 7
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T18. Blocking T18 T18 2 A2.V38.T18 7 7
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T19. Jamming T19 T19 2 A2.V38.T19 6 6
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A2.V38.T20 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T21. Physical RFID tag destruction T21 T21 4 A2.V38.T21 9 9
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T24. Worms, viruses & malicious code T24 T24 3 A2.V38.T24 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T29. MANET/Adhoc network routing attack T29 T29 2 A2.V38.T29 6 6
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T10. Use erroneous and/or unreliable data T10 T10 4 A2.V38.T10 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T11. Procedures / instructions not followed T11 T11 3 A2.V38.T11 7 7
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T12. Non-compliance with data protection legislation T12 T12 4 A2.V38.T12 8 8
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A2.V38.T13 9 9
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V38.T30 8 8
A2 Electronic visa issuing process 4 V15. Insufficient equipment V15 V15 A2V15 2 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A2.V15.T3 7 7
A2 Electronic visa issuing process 4 V15. Insufficient equipment V15 V15 A2V15 2 T12. Non-compliance with data protection legislation T12 T12 4 A2.V15.T12 7 7
A2 Electronic visa issuing process 4 V15. Insufficient equipment V15 V15 A2V15 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A2.V15.T13 8 8
A2 Electronic visa issuing process 4 V15. Insufficient equipment V15 V15 A2V15 2 T26. State surveillance on citizens T26 T26 5 A2.V15.T26 8 8
A2 Electronic visa issuing process 4 V15. Insufficient equipment V15 V15 A2V15 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V15.T30 7 7
A2 Electronic visa issuing process 4 V15. Insufficient equipment V15 V15 A2V15 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V15.T30 7 7
A2 Electronic visa issuing process 4 V20. Lack of respect to the transparency principle V20 V20 A2V20 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A2.V20.T3 9 9
A2 Electronic visa issuing process 4 V20. Lack of respect to the transparency principle V20 V20 A2V20 4 T11. Procedures / instructions not followed T11 T11 3 A2.V20.T11 8 8
A2 Electronic visa issuing process 4 V20. Lack of respect to the transparency principle V20 V20 A2V20 4 T12. Non-compliance with data protection legislation T12 T12 4 A2.V20.T12 9 9
A2 Electronic visa issuing process 4 V20. Lack of respect to the transparency principle V20 V20 A2V20 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A2.V20.T13 10 10
A2 Electronic visa issuing process 4 V20. Lack of respect to the transparency principle V20 V20 A2V20 4 T26. State surveillance on citizens T26 T26 5 A2.V20.T26 10 10
A2 Electronic visa issuing process 4 V20. Lack of respect to the transparency principle V20 V20 A2V20 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A2.V20.T30 9 9
A2 Electronic visa issuing process 4 V20. Lack of respect to the transparency principle V20 V20 A2V20 4 T32. Profiling T32 T32 4 A2.V20.T32 9 9
A2 Electronic visa issuing process 4 V21. Inappropriate / inadequate identity management V21 V21 A2V21 0 T34. Trivialisation of unique identifiers T34 T34 4 A2.V21.T34 5 5
A2 Electronic visa issuing process 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A2V38 3 T34. Trivialisation of unique identifiers T34 T34 4 A2.V38.T34 8 8
A2 Electronic visa issuing process 4 V40. Lack of respect to the legitimacy of data processing, e.g. consent V40 V40 A2V40 4 T12. Non-compliance with data protection legislation T12 T12 4 A2.V40.T12 9 9
A2 Electronic visa issuing process 4 V41. Lack of respect to the data conservation principle V41 V41 A2V41 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A2.V41.T13 10 10
A2 Electronic visa issuing process 4 V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). V42 V42 A2V42 5 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A2.V42.T13 11 11
A20 Cars / vehicles 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A20V2 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A20.V2.T9 7 7
A20 Cars / vehicles 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A20V2 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A20.V2.T22 9 9
A20 Cars / vehicles 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A20V2 3 T11. Procedures / instructions not followed T11 T11 3 A20.V2.T11 7 7
A20 Cars / vehicles 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A20V2 3 T12. Non-compliance with data protection legislation T12 T12 4 A20.V2.T12 8 8
A20 Cars / vehicles 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A20V2 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A20.V2.T30 8 8
A20 Cars / vehicles 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A20V2 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A20.V2.T1 8 8
A20 Cars / vehicles 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A20V2 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A20.V2.T22 9 9
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T25. Malicious power failure attack T25 T25 3 A20.V4.T25 9 9
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A20.V4.T2 10 10
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A20.V4.T3 9 9
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T5. Man in the middle attack T5. T5 3 A20.V4.T5 9 9
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T6. Social engineering attack T6. T6 4 A20.V4.T6 9 9
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T7. Theft [of cards, devices etc] T7. T7 4 A20.V4.T7 9 9
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A20.V4.T8 9 9
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A20.V4.T9 8 8
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T10. Use erroneous and/or unreliable data T10 T10 4 A20.V4.T10 9 9
A20 Cars / vehicles 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A20V4 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A20.V4.T14 10 10
A20 Cars / vehicles 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A20V6 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A20.V6.T15 8 8
A20 Cars / vehicles 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A20V6 3 T17. Side channel attack T17 T17 2 A20.V6.T17 7 7
A20 Cars / vehicles 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A20V6 3 T18. Blocking T18 T18 2 A20.V6.T18 7 7
A20 Cars / vehicles 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A20V6 3 T19. Jamming T19 T19 2 A20.V6.T19 6 6
A20 Cars / vehicles 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A20V6 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A20.V6.T20 8 8
A20 Cars / vehicles 4 V8. Dependency on power systems V8. V8 A20V8 4 T21. Physical RFID tag destruction T21 T21 4 A20.V8.T21 10 10
A20 Cars / vehicles 4 V8. Dependency on power systems V8. V8 A20V8 4 T24. Worms, viruses & malicious code T24 T24 3 A20.V8.T24 9 9
A20 Cars / vehicles 4 V8. Dependency on power systems V8. V8 A20V8 4 T29. MANET/Adhoc network routing attack T29 T29 2 A20.V8.T29 7 7
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A20.V9.T1 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T11. Procedures / instructions not followed T11 T11 3 A20.V9.T11 7 7
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T12. Non-compliance with data protection legislation T12 T12 4 A20.V9.T12 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A20.V9.T22 9 9
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T25. Malicious power failure attack T25 T25 3 A20.V9.T25 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T28. Adverse weather condition or other disaster T28 T28 4 A20.V9.T28 9 9
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A20.V9.T9 7 7
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T10. Use erroneous and/or unreliable data T10 T10 4 A20.V9.T10 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T11. Procedures / instructions not followed T11 T11 3 A20.V9.T11 7 7
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T12. Non-compliance with data protection legislation T12 T12 4 A20.V9.T12 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A20.V9.T30 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A20.V9.T9 7 7
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T10. Use erroneous and/or unreliable data T10 T10 4 A20.V9.T10 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T11. Procedures / instructions not followed T11 T11 3 A20.V9.T11 7 7
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T12. Non-compliance with data protection legislation T12 T12 4 A20.V9.T12 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A20.V9.T30 8 8
A20 Cars / vehicles 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A20V9 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A20.V9.T13 9 9
A20 Cars / vehicles 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A20V10 2 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A20.V10.T22 8 8
A20 Cars / vehicles 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A20V10 2 T4. Traffic analysis / scan / probe T4. T4 3 A20.V10.T4 6 6
A20 Cars / vehicles 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A20V10 2 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A20.V10.T3 7 7
A20 Cars / vehicles 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A20V10 2 T12. Non-compliance with data protection legislation T12 T12 4 A20.V10.T12 7 7
A20 Cars / vehicles 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A20V10 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A20.V10.T13 8 8
A20 Cars / vehicles 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A20V10 2 T26. State surveillance on citizens T26 T26 5 A20.V10.T26 8 8
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A20.V12.T30 7 7
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A20.V12.T2 8 8
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A20.V12.T3 7 7
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T6. Social engineering attack T6. T6 4 A20.V12.T6 7 7
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A20.V12.T8 7 7
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T12. Non-compliance with data protection legislation T12 T12 4 A20.V12.T12 7 7
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A20.V12.T13 8 8
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T26. State surveillance on citizens T26 T26 5 A20.V12.T26 8 8
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A20.V12.T3 7 7
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T11. Procedures / instructions not followed T11 T11 3 A20.V12.T11 6 6
A20 Cars / vehicles 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A20V12 2 T12. Non-compliance with data protection legislation T12 T12 4 A20.V12.T12 7 7
A20 Cars / vehicles 4 V17. Lack of dependable sensors, GPS V17 V17 A20V17 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A20.V17.T13 9 9
A20 Cars / vehicles 4 V17. Lack of dependable sensors, GPS V17 V17 A20V17 3 T26. State surveillance on citizens T26 T26 5 A20.V17.T26 9 9
A20 Cars / vehicles 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A20V18 1 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A20.V18.T30 6 6
A20 Cars / vehicles 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A20V18 1 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A20.V18.T8 6 6
A20 Cars / vehicles 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A20V18 1 T12. Non-compliance with data protection legislation T12 T12 4 A20.V18.T12 6 6
A20 Cars / vehicles 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A20V18 1 T10. Use erroneous and/or unreliable data T10 T10 4 A20.V18.T10 6 6
A20 Cars / vehicles 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A20V18 1 T11. Procedures / instructions not followed T11 T11 3 A20.V18.T11 5 5
A20 Cars / vehicles 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A20V19 4 T12. Non-compliance with data protection legislation T12 T12 4 A20.V19.T12 9 9
A20 Cars / vehicles 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A20V19 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A20.V19.T13 10 10
A20 Cars / vehicles 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A20V19 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A20.V19.T30 9 9
A20 Cars / vehicles 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A20V19 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A20.V19.T1 9 9
A20 Cars / vehicles 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A20V19 4 T4. Traffic analysis / scan / probe T4. T4 3 A20.V19.T4 8 8
A20 Cars / vehicles 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A20V19 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A20.V19.T8 9 9
A20 Cars / vehicles 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A20V19 4 T10. Use erroneous and/or unreliable data T10 T10 4 A20.V19.T10 9 9
A20 Cars / vehicles 4 V20. Lack of respect to the transparency principle V20 V20 A20V20 3 T12. Non-compliance with data protection legislation T12 T12 4 A20.V20.T12 8 8
A20 Cars / vehicles 4 V20. Lack of respect to the transparency principle V20 V20 A20V20 3 T19. Jamming T19 T19 2 A20.V20.T19 6 6
A20 Cars / vehicles 4 V20. Lack of respect to the transparency principle V20 V20 A20V20 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A20.V20.T20 8 8
A20 Cars / vehicles 4 V20. Lack of respect to the transparency principle V20 V20 A20V20 3 T24. Worms, viruses & malicious code T24 T24 3 A20.V20.T24 8 8
A20 Cars / vehicles 4 V20. Lack of respect to the transparency principle V20 V20 A20V20 3 T29. MANET/Adhoc network routing attack T29 T29 2 A20.V20.T29 6 6
A20 Cars / vehicles 4 V20. Lack of respect to the transparency principle V20 V20 A20V20 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A20.V20.T2 9 9
A20 Cars / vehicles 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A20V28 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A20.V28.T2 9 9
A20 Cars / vehicles 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A20V28 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A20.V28.T3 8 8
A20 Cars / vehicles 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A20V38 4 T5. Man in the middle attack T5. T5 3 A20.V38.T5 9 9
A20 Cars / vehicles 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A20V38 4 T6. Social engineering attack T6. T6 4 A20.V38.T6 9 9
A20 Cars / vehicles 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A20V38 4 T7. Theft [of cards, devices etc] T7. T7 4 A20.V38.T7 9 9
A20 Cars / vehicles 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A20V38 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A20.V38.T8 9 9
A20 Cars / vehicles 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A20V38 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A20.V38.T9 8 8
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T10. Use erroneous and/or unreliable data T10 T10 4 A20.V39.T10 9 9
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A20.V39.T14 10 10
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A20.V39.T15 9 9
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T17. Side channel attack T17 T17 2 A20.V39.T17 8 8
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T18. Blocking T18 T18 2 A20.V39.T18 8 8
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T19. Jamming T19 T19 2 A20.V39.T19 7 7
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A20.V39.T20 9 9
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T21. Physical RFID tag destruction T21 T21 4 A20.V39.T21 10 10
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T24. Worms, viruses & malicious code T24 T24 3 A20.V39.T24 9 9
A20 Cars / vehicles 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A20V39 4 T29. MANET/Adhoc network routing attack T29 T29 2 A20.V39.T29 7 7
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A3.V13.T1 6 6
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A3.V13.T2 7 7
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T4. Traffic analysis / scan / probe T4. T4 3 A3.V13.T4 5 5
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T5. Man in the middle attack T5. T5 3 A3.V13.T5 6 6
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A3.V13.T15 6 6
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T17. Side channel attack T17 T17 2 A3.V13.T17 5 5
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T18. Blocking T18 T18 2 A3.V13.T18 5 5
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T19. Jamming T19 T19 2 A3.V13.T19 4 4
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A3.V13.T20 6 6
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T21. Physical RFID tag destruction T21 T21 4 A3.V13.T21 7 7
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A3.V13.T1 6 6
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A3.V13.T2 7 7
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T4. Traffic analysis / scan / probe T4. T4 3 A3.V13.T4 5 5
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T5. Man in the middle attack T5. T5 3 A3.V13.T5 6 6
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A3.V13.T15 6 6
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T17. Side channel attack T17 T17 2 A3.V13.T17 5 5
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T18. Blocking T18 T18 2 A3.V13.T18 5 5
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T19. Jamming T19 T19 2 A3.V13.T19 4 4
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A3.V13.T20 6 6
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T21. Physical RFID tag destruction T21 T21 4 A3.V13.T21 7 7
A3 Luggage and goods handling 3 V13. Lack of or inappropriate protection of RFID tags V13 V13 A3V13 2 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A3.V13.T22 7 7
A3 Luggage and goods handling 3 V25. Actual RFID range longer than standard V25 V25 A3V25 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A3.V25.T8 6 6
A3 Luggage and goods handling 3 V25. Actual RFID range longer than standard V25 V25 A3V25 2 T5. Man in the middle attack T5. T5 3 A3.V25.T5 6 6
A3 Luggage and goods handling 3 V25. Actual RFID range longer than standard V25 V25 A3V25 2 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A3.V25.T20 6 6
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A3.V12.T1 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A3.V12.T2 8 8
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T5. Man in the middle attack T5. T5 3 A3.V12.T5 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A3.V12.T22 8 8
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T24. Worms, viruses & malicious code T24 T24 3 A3.V12.T24 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T25. Malicious power failure attack T25 T25 3 A3.V12.T25 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T28. Adverse weather condition or other disaster T28 T28 4 A3.V12.T28 8 8
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A3.V12.T12 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A3.V12.T30 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A3.V12.T9 6 6
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T10. Use erroneous and/or unreliable data T10 T10 4 A3.V12.T10 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T11. Procedures / instructions not followed T11 T11 3 A3.V12.T11 6 6
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A3.V12.T12 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A3.V12.T30 7 7
A3 Luggage and goods handling 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A3V12 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A3.V12.T13 8 8
A3 Luggage and goods handling 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A3V5 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A3.V5.T8 6 6
A3 Luggage and goods handling 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A3V5 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A3.V5.T9 5 5
A3 Luggage and goods handling 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A3V5 2 T10. Use erroneous and/or unreliable data T10 T10 4 A3.V5.T10 6 6
A3 Luggage and goods handling 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A3V5 2 T11. Procedures / instructions not followed T11 T11 3 A3.V5.T11 5 5
A3 Luggage and goods handling 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A3V5 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A3.V5.T14 7 7
A3 Luggage and goods handling 3 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A3V5 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A3.V5.T30 6 6
A3 Luggage and goods handling 3 V15. Insufficient equipment V15 V15 A3V15 4 T11. Procedures / instructions not followed T11 T11 3 A3.V15.T11 7 7
A3 Luggage and goods handling 3 V15. Insufficient equipment V15 V15 A3V15 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A3.V15.T30 8 8
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A3.V24.T2 7 7
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T6. Social engineering attack T6. T6 4 A3.V24.T6 6 6
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T7. Theft [of cards, devices etc] T7. T7 4 A3.V24.T7 6 6
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A3.V24.T8 6 6
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A3.V24.T9 5 5
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A3.V24.T14 7 7
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A3.V24.T15 6 6
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A3.V24.T16 6 6
A3 Luggage and goods handling 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A3V24 2 T21. Physical RFID tag destruction T21 T21 4 A3.V24.T21 7 7
A3 Luggage and goods handling 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A3V6 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A3.V6.T9 7 7
A3 Luggage and goods handling 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A3V6 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A3.V6.T22 9 9
A3 Luggage and goods handling 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A3V6 4 T11. Procedures / instructions not followed T11 T11 3 A3.V6.T11 7 7
A3 Luggage and goods handling 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A3V6 4 T12. Non-compliance with data protection legislation T12 T12 4 A3.V6.T12 8 8
A3 Luggage and goods handling 3 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A3V6 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A3.V6.T30 8 8
A4 Automated traffic management 4 V17. Lack of dependable sensors, GPS V17 V17 A4V17 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A4.V17.T22 9 9
A4 Automated traffic management 4 V17. Lack of dependable sensors, GPS V17 V17 A4V17 3 T4. Traffic analysis / scan / probe T4. T4 3 A4.V17.T4 7 7
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A4.V39.T1 9 9
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T4. Traffic analysis / scan / probe T4. T4 3 A4.V39.T4 8 8
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A4.V39.T8 9 9
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T10. Use erroneous and/or unreliable data T10 T10 4 A4.V39.T10 9 9
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T12. Non-compliance with data protection legislation T12 T12 4 A4.V39.T12 9 9
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T19. Jamming T19 T19 2 A4.V39.T19 7 7
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A4.V39.T20 9 9
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T24. Worms, viruses & malicious code T24 T24 3 A4.V39.T24 9 9
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T29. MANET/Adhoc network routing attack T29 T29 2 A4.V39.T29 7 7
A4 Automated traffic management 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A4V39 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A4.V39.T2 10 10
A4 Automated traffic management 4 V20. Lack of respect to the transparency principle V20 V20 A4V20 3 T33. Exclusion of the data subject from the data processing process T33 T33 4 A4.V20.T33 8 8
A4 Automated traffic management 4 V40. Lack of respect to the legitimacy of data processing, e.g. consent V40 V40 A4V40 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A4.V40.T13 9 9
A4 Automated traffic management 4 V41. Lack of respect to the data conservation principle V41 V41 A4V41 3 T32. Profiling T32 T32 4 A4.V41.T32 8 8
A4 Automated traffic management 4 V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). V42 V42 A4V42 3 T31. Data linkability T31 T31 4 A4.V42.T31 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A5.V11.T2 9 9
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A5.V11.T3 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T5. Man in the middle attack T5. T5 3 A5.V11.T5 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T6. Social engineering attack T6. T6 4 A5.V11.T6 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A5.V11.T8 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A5.V11.T9 7 7
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T7. Theft [of cards, devices etc] T7. T7 4 A5.V11.T7 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T10. Use erroneous and/or unreliable data T10 T10 4 A5.V11.T10 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T11. Procedures / instructions not followed T11 T11 3 A5.V11.T11 7 7
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T12. Non-compliance with data protection legislation T12 T12 4 A5.V11.T12 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A5.V11.T14 9 9
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A5.V11.T16 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A5.V11.T22 9 9
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T23. e-visa not accepted at check in T23 T23 3 A5.V11.T23 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T27. Trade union/labor strikes T27 T27 3 A5.V11.T27 8 8
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A5.V11.T14 9 9
A5 Passports and National ID cards 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A5V11 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A5.V11.T30 8 8
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A5.V4.T2 9 9
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T6. Social engineering attack T6. T6 4 A5.V4.T6 8 8
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T7. Theft [of cards, devices etc] T7. T7 4 A5.V4.T7 8 8
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A5.V4.T8 8 8
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A5.V4.T9 7 7
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T10. Use erroneous and/or unreliable data T10 T10 4 A5.V4.T10 8 8
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T11. Procedures / instructions not followed T11 T11 3 A5.V4.T11 7 7
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T12. Non-compliance with data protection legislation T12 T12 4 A5.V4.T12 8 8
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A5.V4.T13 9 9
A5 Passports and National ID cards 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A5V4 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A5.V4.T14 9 9
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A5.V24.T16 7 7
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A5.V24.T22 8 8
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A5.V24.T30 7 7
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A5.V24.T8 7 7
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A5.V24.T9 6 6
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A5.V24.T14 8 8
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A5.V24.T15 7 7
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A5.V24.T16 7 7
A5 Passports and National ID cards 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A5V24 2 T21. Physical RFID tag destruction T21 T21 4 A5.V24.T21 8 8
A5 Passports and National ID cards 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A5V6 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A5.V6.T9 7 7
A5 Passports and National ID cards 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A5V6 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A5.V6.T22 9 9
A5 Passports and National ID cards 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A5V6 3 T11. Procedures / instructions not followed T11 T11 3 A5.V6.T11 7 7
A5 Passports and National ID cards 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A5V6 3 T12. Non-compliance with data protection legislation T12 T12 4 A5.V6.T12 8 8
A5 Passports and National ID cards 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A5V6 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A5.V6.T30 8 8
A5 Passports and National ID cards 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A5V9 2 T24. Worms, viruses & malicious code T24 T24 3 A5.V9.T24 7 7
A5 Passports and National ID cards 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A5V9 2 T29. MANET/Adhoc network routing attack T29 T29 2 A5.V9.T29 5 5
A5 Passports and National ID cards 4 V25. Actual RFID range longer than standard V25 V25 A5V25 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A5.V25.T8 9 9
A5 Passports and National ID cards 4 V25. Actual RFID range longer than standard V25 V25 A5V25 4 T5. Man in the middle attack T5. T5 3 A5.V25.T5 9 9
A5 Passports and National ID cards 4 V25. Actual RFID range longer than standard V25 V25 A5V25 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A5.V25.T20 9 9
A5 Passports and National ID cards 4 V26. RFID tags do not have a turn-off option V26 V26 A5V26 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A5.V26.T20 8 8
A5 Passports and National ID cards 4 V27. Insufficient protection against reverse engineering V27 V27 A5V27 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A5.V27.T15 8 8
A5 Passports and National ID cards 4 V27. Insufficient protection against reverse engineering V27 V27 A5V27 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A5.V27.T20 8 8
A5 Passports and National ID cards 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A5V28 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A5.V28.T8 9 9
A5 Passports and National ID cards 4 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A5V28 4 T12. Non-compliance with data protection legislation T12 T12 4 A5.V28.T12 9 9
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A5.V12.T1 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A5.V12.T2 9 9
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T4. Traffic analysis / scan / probe T4. T4 3 A5.V12.T4 7 7
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T5. Man in the middle attack T5. T5 3 A5.V12.T5 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A5.V12.T15 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T17. Side channel attack T17 T17 2 A5.V12.T17 7 7
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T18. Blocking T18 T18 2 A5.V12.T18 7 7
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T19. Jamming T19 T19 2 A5.V12.T19 6 6
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A5.V12.T20 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T21. Physical RFID tag destruction T21 T21 4 A5.V12.T21 9 9
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A5.V12.T1 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A5.V12.T2 9 9
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T4. Traffic analysis / scan / probe T4. T4 3 A5.V12.T4 7 7
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T5. Man in the middle attack T5. T5 3 A5.V12.T5 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A5.V12.T15 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T17. Side channel attack T17 T17 2 A5.V12.T17 7 7
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T18. Blocking T18 T18 2 A5.V12.T18 7 7
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T19. Jamming T19 T19 2 A5.V12.T19 6 6
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A5.V12.T20 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T21. Physical RFID tag destruction T21 T21 4 A5.V12.T21 9 9
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A5.V12.T22 9 9
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A5.V12.T12 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A5.V12.T30 8 8
A5 Passports and National ID cards 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A5V12 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A5.V12.T13 9 9
A5 Passports and National ID cards 4 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A5V18 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A5.V18.T30 9 9
A5 Passports and National ID cards 4 V21. Inappropriate / inadequate identity management V21 V21 A5V21 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A5.V21.T2 9 9
A5 Passports and National ID cards 4 V21. Inappropriate / inadequate identity management V21 V21 A5V21 3 T5. Man in the middle attack T5. T5 3 A5.V21.T5 8 8
A5 Passports and National ID cards 4 V21. Inappropriate / inadequate identity management V21 V21 A5V21 3 T6. Social engineering attack T6. T6 4 A5.V21.T6 8 8
A5 Passports and National ID cards 4 V21. Inappropriate / inadequate identity management V21 V21 A5V21 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A5.V21.T8 8 8
A5 Passports and National ID cards 4 V21. Inappropriate / inadequate identity management V21 V21 A5V21 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A5.V21.T14 9 9
A5 Passports and National ID cards 4 V22. Collision of tag traffic / Radio-frequency interference V22 V22 A5V22 2 T18. Blocking T18 T18 2 A5.V22.T18 6 6
A5 Passports and National ID cards 4 V22. Collision of tag traffic / Radio-frequency interference V22 V22 A5V22 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A5.V22.T13 8 8
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T4. Traffic analysis / scan / probe T4. T4 3 A5.V31.T4 7 7
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T5. Man in the middle attack T5. T5 3 A5.V31.T5 8 8
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T6. Social engineering attack T6. T6 4 A5.V31.T6 8 8
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T7. Theft [of cards, devices etc] T7. T7 4 A5.V31.T7 8 8
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A5.V31.T8 8 8
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T10. Use erroneous and/or unreliable data T10 T10 4 A5.V31.T10 8 8
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A5.V31.T15 8 8
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A5.V31.T20 8 8
A5 Passports and National ID cards 4 V31. Devices & equipment used in unprotected environments V31 V31 A5V31 3 T24. Worms, viruses & malicious code T24 T24 3 A5.V31.T24 8 8
A5 Passports and National ID cards 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A5V38 3 T10. Use erroneous and/or unreliable data T10 T10 4 A5.V38.T10 8 8
A5 Passports and National ID cards 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A5V38 3 T11. Procedures / instructions not followed T11 T11 3 A5.V38.T11 7 7
A5 Passports and National ID cards 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A5V38 3 T12. Non-compliance with data protection legislation T12 T12 4 A5.V38.T12 8 8
A5 Passports and National ID cards 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A5V38 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A5.V38.T13 9 9
A5 Passports and National ID cards 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A5V38 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A5.V38.T30 8 8
A5 Passports and National ID cards 4 V41. Lack of respect to the data conservation principle V41 V41 A5V41 4 T33. Exclusion of the data subject from the data processing process T33 T33 4 A5.V41.T33 9 9
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T6. Social engineering attack T6. T6 4 A6.V21.T6 9 9
A6 Mobile ‘smart’ devices 4 V23. Over dependency on biometrics V23 V23 A6V23 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A6.V23.T3 9 9
A6 Mobile ‘smart’ devices 4 V23. Over dependency on biometrics V23 V23 A6V23 4 T11. Procedures / instructions not followed T11 T11 3 A6.V23.T11 8 8
A6 Mobile ‘smart’ devices 4 V23. Over dependency on biometrics V23 V23 A6V23 4 T12. Non-compliance with data protection legislation T12 T12 4 A6.V23.T12 9 9
A6 Mobile ‘smart’ devices 4 V23. Over dependency on biometrics V23 V23 A6V23 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A6.V23.T14 10 10
A6 Mobile ‘smart’ devices 4 V23. Over dependency on biometrics V23 V23 A6V23 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A6.V23.T30 9 9
A6 Mobile ‘smart’ devices 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A6V11 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A6.V11.T2 9 9
A6 Mobile ‘smart’ devices 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A6V11 3 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A6.V11.T3 8 8
A6 Mobile ‘smart’ devices 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A6V11 3 T11. Procedures / instructions not followed T11 T11 3 A6.V11.T11 7 7
A6 Mobile ‘smart’ devices 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A6V11 3 T12. Non-compliance with data protection legislation T12 T12 4 A6.V11.T12 8 8
A6 Mobile ‘smart’ devices 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A6V11 3 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A6.V11.T14 9 9
A6 Mobile ‘smart’ devices 4 V11. Lack of adequate controls in biometrics' enrollment stage V11 V11 A6V11 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A6.V11.T30 8 8
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A6.V24.T2 8 8
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T6. Social engineering attack T6. T6 4 A6.V24.T6 7 7
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T7. Theft [of cards, devices etc] T7. T7 4 A6.V24.T7 7 7
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A6.V24.T8 7 7
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A6.V24.T9 6 6
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T10. Use erroneous and/or unreliable data T10 T10 4 A6.V24.T10 7 7
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T11. Procedures / instructions not followed T11 T11 3 A6.V24.T11 6 6
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T12. Non-compliance with data protection legislation T12 T12 4 A6.V24.T12 7 7
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A6.V24.T13 8 8
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A6.V24.T14 8 8
A6 Mobile ‘smart’ devices 4 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A6V24 2 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A6.V24.T16 7 7
A6 Mobile ‘smart’ devices 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A6V6 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A6.V6.T9 7 7
A6 Mobile ‘smart’ devices 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A6V6 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A6.V6.T22 9 9
A6 Mobile ‘smart’ devices 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A6V6 3 T11. Procedures / instructions not followed T11 T11 3 A6.V6.T11 7 7
A6 Mobile ‘smart’ devices 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A6V6 3 T12. Non-compliance with data protection legislation T12 T12 4 A6.V6.T12 8 8
A6 Mobile ‘smart’ devices 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A6V6 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A6.V6.T30 8 8
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A6.V13.T2 10 10
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A6.V13.T3 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T5. Man in the middle attack T5. T5 3 A6.V13.T5 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T6. Social engineering attack T6. T6 4 A6.V13.T6 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T7. Theft [of cards, devices etc] T7. T7 4 A6.V13.T7 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A6.V13.T8 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A6.V13.T9 8 8
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T10. Use erroneous and/or unreliable data T10 T10 4 A6.V13.T10 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A6.V13.T14 10 10
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A6.V13.T15 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T17. Side channel attack T17 T17 2 A6.V13.T17 8 8
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T18. Blocking T18 T18 2 A6.V13.T18 8 8
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T19. Jamming T19 T19 2 A6.V13.T19 7 7
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A6.V13.T20 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T21. Physical RFID tag destruction T21 T21 4 A6.V13.T21 10 10
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T24. Worms, viruses & malicious code T24 T24 3 A6.V13.T24 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T29. MANET/Adhoc network routing attack T29 T29 2 A6.V13.T29 7 7
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T19. Jamming T19 T19 2 A6.V13.T19 7 7
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A6.V13.T20 9 9
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T21. Physical RFID tag destruction T21 T21 4 A6.V13.T21 10 10
A6 Mobile ‘smart’ devices 4 V13. Lack of or inappropriate protection of RFID tags V13 V13 A6V13 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A6.V13.T22 10 10
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A6.V12.T9 7 7
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T10. Use erroneous and/or unreliable data T10 T10 4 A6.V12.T10 8 8
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T11. Procedures / instructions not followed T11 T11 3 A6.V12.T11 7 7
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A6.V12.T12 8 8
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A6.V12.T30 8 8
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A6.V12.T9 7 7
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T10. Use erroneous and/or unreliable data T10 T10 4 A6.V12.T10 8 8
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T11. Procedures / instructions not followed T11 T11 3 A6.V12.T11 7 7
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T12. Non-compliance with data protection legislation T12 T12 4 A6.V12.T12 8 8
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A6.V12.T30 8 8
A6 Mobile ‘smart’ devices 4 V12. Lack of harmonisation and interoperability of procedures V12 V12 A6V12 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A6.V12.T13 9 9
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T3. Large-scale and/or inappropriate data mining / surveillance / profiling T3. T3 4 A6.V21.T3 9 9
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T12. Non-compliance with data protection legislation T12 T12 4 A6.V21.T12 9 9
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A6.V21.T13 10 10
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T26. State surveillance on citizens T26 T26 5 A6.V21.T26 10 10
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A6.V21.T2 10 10
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T5. Man in the middle attack T5. T5 3 A6.V21.T5 9 9
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T6. Social engineering attack T6. T6 4 A6.V21.T6 9 9
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A6.V21.T8 9 9
A6 Mobile ‘smart’ devices 4 V21. Inappropriate / inadequate identity management V21 V21 A6V21 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A6.V21.T14 10 10
A6 Mobile ‘smart’ devices 4 V22. Collision of tag traffic / Radio-frequency interference V22 V22 A6V22 2 T18. Blocking T18 T18 2 A6.V22.T18 6 6
A6 Mobile ‘smart’ devices 4 V22. Collision of tag traffic / Radio-frequency interference V22 V22 A6V22 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A6.V22.T13 8 8
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T4. Traffic analysis / scan / probe T4. T4 3 A6.V31.T4 7 7
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T5. Man in the middle attack T5. T5 3 A6.V31.T5 8 8
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T6. Social engineering attack T6. T6 4 A6.V31.T6 8 8
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T7. Theft [of cards, devices etc] T7. T7 4 A6.V31.T7 8 8
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A6.V31.T8 8 8
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T10. Use erroneous and/or unreliable data T10 T10 4 A6.V31.T10 8 8
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A6.V31.T15 8 8
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A6.V31.T20 8 8
A6 Mobile ‘smart’ devices 4 V31. Devices & equipment used in unprotected environments V31 V31 A6V31 3 T24. Worms, viruses & malicious code T24 T24 3 A6.V31.T24 8 8
A6 Mobile ‘smart’ devices 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A6V38 3 T10. Use erroneous and/or unreliable data T10 T10 4 A6.V38.T10 8 8
A6 Mobile ‘smart’ devices 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A6V38 3 T11. Procedures / instructions not followed T11 T11 3 A6.V38.T11 7 7
A6 Mobile ‘smart’ devices 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A6V38 3 T12. Non-compliance with data protection legislation T12 T12 4 A6.V38.T12 8 8
A6 Mobile ‘smart’ devices 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A6V38 3 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A6.V38.T13 9 9
A6 Mobile ‘smart’ devices 4 V38. Lack of common or harmonised legislation in EU Member States V38 V38 A6V38 3 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A6.V38.T30 8 8
A6 Mobile ‘smart’ devices 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A6V10 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A6.V10.T1 8 8
A6 Mobile ‘smart’ devices 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A6V10 3 T11. Procedures / instructions not followed T11 T11 3 A6.V10.T11 7 7
A6 Mobile ‘smart’ devices 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A6V10 3 T12. Non-compliance with data protection legislation T12 T12 4 A6.V10.T12 8 8
A6 Mobile ‘smart’ devices 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A6V10 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A6.V10.T22 9 9
A6 Mobile ‘smart’ devices 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A6V10 3 T25. Malicious power failure attack T25 T25 3 A6.V10.T25 8 8
A6 Mobile ‘smart’ devices 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A6V10 3 T28. Adverse weather condition or other disaster T28 T28 4 A6.V10.T28 9 9
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A6.V39.T1 8 8
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T4. Traffic analysis / scan / probe T4. T4 3 A6.V39.T4 7 7
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A6.V39.T8 8 8
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T10. Use erroneous and/or unreliable data T10 T10 4 A6.V39.T10 8 8
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T12. Non-compliance with data protection legislation T12 T12 4 A6.V39.T12 8 8
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T19. Jamming T19 T19 2 A6.V39.T19 6 6
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A6.V39.T20 8 8
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T24. Worms, viruses & malicious code T24 T24 3 A6.V39.T24 8 8
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T29. MANET/Adhoc network routing attack T29 T29 2 A6.V39.T29 6 6
A6 Mobile ‘smart’ devices 4 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A6V39 3 T2. Spoofing of credentials / bypass authentication T2. T2 5 A6.V39.T2 9 9
A6 Mobile ‘smart’ devices 4 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A6V34 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A6.V34.T1 9 9
A6 Mobile ‘smart’ devices 4 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A6V34 4 T4. Traffic analysis / scan / probe T4. T4 3 A6.V34.T4 8 8
A6 Mobile ‘smart’ devices 4 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A6V34 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A6.V34.T8 9 9
A6 Mobile ‘smart’ devices 4 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A6V34 4 T10. Use erroneous and/or unreliable data T10 T10 4 A6.V34.T10 9 9
A6 Mobile ‘smart’ devices 4 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A6V34 4 T12. Non-compliance with data protection legislation T12 T12 4 A6.V34.T12 9 9
A6 Mobile ‘smart’ devices 4 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A6V34 4 T19. Jamming T19 T19 2 A6.V34.T19 7 7
A6 Mobile ‘smart’ devices 4 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A6V34 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A6.V34.T20 9 9
A6 Mobile ‘smart’ devices 4 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A6V34 4 T24. Worms, viruses & malicious code T24 T24 3 A6.V34.T24 9 9
A6 Mobile ‘smart’ devices 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A6V19 4 T32. Profiling T32 T32 4 A6.V19.T32 9 9
A6 Mobile ‘smart’ devices 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A6V19 4 T33. Exclusion of the data subject from the data processing process T33 T33 4 A6.V19.T33 9 9
A6 Mobile ‘smart’ devices 4 V40. Lack of respect to the legitimacy of data processing, e.g. consent V40 V40 A6V40 4 T31. Data linkability T31 T31 4 A6.V40.T31 9 9
A6 Mobile ‘smart’ devices 4 V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). V42 V42 A6V42 4 T32. Profiling T32 T32 4 A6.V42.T32 9 9
A7 Health monitoring devices 5 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A7V4 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A7.V4.T14 11 11
A7 Health monitoring devices 5 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A7V5 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A7.V5.T8 10 10
A7 Health monitoring devices 5 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A7V5 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A7.V5.T9 9 9
A7 Health monitoring devices 5 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A7V5 4 T10. Use erroneous and/or unreliable data T10 T10 4 A7.V5.T10 10 10
A7 Health monitoring devices 5 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A7V5 4 T11. Procedures / instructions not followed T11 T11 3 A7.V5.T11 9 9
A7 Health monitoring devices 5 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A7V5 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A7.V5.T14 11 11
A7 Health monitoring devices 5 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A7V5 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A7.V5.T30 10 10
A7 Health monitoring devices 5 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A7V6 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A7.V6.T9 9 9
A7 Health monitoring devices 5 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A7V6 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A7.V6.T22 11 11
A7 Health monitoring devices 5 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A7V6 4 T11. Procedures / instructions not followed T11 T11 3 A7.V6.T11 9 9
A7 Health monitoring devices 5 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A7V6 4 T12. Non-compliance with data protection legislation T12 T12 4 A7.V6.T12 10 10
A7 Health monitoring devices 5 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A7V6 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A7.V6.T30 10 10
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A7.V24.T2 9 9
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T6. Social engineering attack T6. T6 4 A7.V24.T6 8 8
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T7. Theft [of cards, devices etc] T7. T7 4 A7.V24.T7 8 8
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A7.V24.T8 8 8
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A7.V24.T9 7 7
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A7.V24.T14 9 9
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A7.V24.T15 8 8
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A7.V24.T16 8 8
A7 Health monitoring devices 5 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A7V24 2 T21. Physical RFID tag destruction T21 T21 4 A7.V24.T21 9 9
A7 Health monitoring devices 5 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A7V28 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A7.V28.T8 9 9
A7 Health monitoring devices 5 V28. Inadequate security measures of data storage (e.g. inadequate encryption measures) V28 V28 A7V28 3 T12. Non-compliance with data protection legislation T12 T12 4 A7.V28.T12 9 9
A7 Health monitoring devices 5 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A7V29 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A7.V29.T9 9 9
A7 Health monitoring devices 5 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A7V29 4 T11. Procedures / instructions not followed T11 T11 3 A7.V29.T11 9 9
A7 Health monitoring devices 5 V29. Over-sensitivity of devices (give many false alarms) V29 V29 A7V29 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A7.V29.T30 10 10
A7 Health monitoring devices 5 V30. Sensitivity to magnetic fields V30 V30 A7V30 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A7.V30.T22 11 11
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T4. Traffic analysis / scan / probe T4. T4 3 A7.V31.T4 8 8
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T5. Man in the middle attack T5. T5 3 A7.V31.T5 9 9
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T6. Social engineering attack T6. T6 4 A7.V31.T6 9 9
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T7. Theft [of cards, devices etc] T7. T7 4 A7.V31.T7 9 9
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A7.V31.T8 9 9
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T10. Use erroneous and/or unreliable data T10 T10 4 A7.V31.T10 9 9
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A7.V31.T15 9 9
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A7.V31.T20 9 9
A7 Health monitoring devices 5 V31. Devices & equipment used in unprotected environments V31 V31 A7V31 3 T24. Worms, viruses & malicious code T24 T24 3 A7.V31.T24 9 9
A7 Health monitoring devices 5 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A7V34 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A7.V34.T1 10 10
A7 Health monitoring devices 5 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A7V34 4 T4. Traffic analysis / scan / probe T4. T4 3 A7.V34.T4 9 9
A7 Health monitoring devices 5 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A7V34 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A7.V34.T8 10 10
A7 Health monitoring devices 5 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A7V34 4 T10. Use erroneous and/or unreliable data T10 T10 4 A7.V34.T10 10 10
A7 Health monitoring devices 5 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A7V34 4 T12. Non-compliance with data protection legislation T12 T12 4 A7.V34.T12 10 10
A7 Health monitoring devices 5 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A7V34 4 T19. Jamming T19 T19 2 A7.V34.T19 8 8
A7 Health monitoring devices 5 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A7V34 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A7.V34.T20 10 10
A7 Health monitoring devices 5 V34. Communication of data over unprotected or publicly accessible channels V34 V34 A7V34 4 T24. Worms, viruses & malicious code T24 T24 3 A7.V34.T24 10 10
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A7.V39.T1 10 10
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T4. Traffic analysis / scan / probe T4. T4 3 A7.V39.T4 9 9
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A7.V39.T8 10 10
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T10. Use erroneous and/or unreliable data T10 T10 4 A7.V39.T10 10 10
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T12. Non-compliance with data protection legislation T12 T12 4 A7.V39.T12 10 10
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T19. Jamming T19 T19 2 A7.V39.T19 8 8
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T20. Fake / rogue RFID readers / scanning of RFID reader and /or tag T20 T20 3 A7.V39.T20 10 10
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T24. Worms, viruses & malicious code T24 T24 3 A7.V39.T24 10 10
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T29. MANET/Adhoc network routing attack T29 T29 2 A7.V39.T29 8 8
A7 Health monitoring devices 5 V39. Insufficient protection of wireless networks and communication (weak or no encryption etc.) V39 V39 A7V39 4 T2. Spoofing of credentials / bypass authentication T2. T2 5 A7.V39.T2 11 11
A7 Health monitoring devices 5 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A7V18 4 T31. Data linkability T31 T31 4 A7.V18.T31 10 10
A7 Health monitoring devices 5 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A7V18 4 T32. Profiling T32 T32 4 A7.V18.T32 10 10
A7 Health monitoring devices 5 V18. Lack of respect to the data minimisation and proportionality principles V18 V18 A7V18 4 T33. Exclusion of the data subject from the data processing process T33 T33 4 A7.V18.T33 10 10
A7 Health monitoring devices 5 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A7V19 4 T32. Profiling T32 T32 4 A7.V19.T32 10 10
A7 Health monitoring devices 5 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A7V19 4 T33. Exclusion of the data subject from the data processing process T33 T33 4 A7.V19.T33 10 10
A7 Health monitoring devices 5 V40. Lack of respect to the legitimacy of data processing, e.g. consent V40 V40 A7V40 3 T32. Profiling T32 T32 4 A7.V40.T32 9 9
A7 Health monitoring devices 5 V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). V42 V42 A7V42 5 T33. Exclusion of the data subject from the data processing process T33 T33 4 A7.V42.T33 11 11
A8 Travel documents (paper) 3 V3. Lack of back-up / failover procedures V3. V3 A8V3 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A8.V3.T1 8 8
A8 Travel documents (paper) 3 V3. Lack of back-up / failover procedures V3. V3 A8V3 4 T6. Social engineering attack T6. T6 4 A8.V3.T6 8 8
A8 Travel documents (paper) 3 V3. Lack of back-up / failover procedures V3. V3 A8V3 4 T7. Theft [of cards, devices etc] T7. T7 4 A8.V3.T7 8 8
A8 Travel documents (paper) 3 V3. Lack of back-up / failover procedures V3. V3 A8V3 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A8.V3.T9 7 7
A8 Travel documents (paper) 3 V3. Lack of back-up / failover procedures V3. V3 A8V3 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A8.V3.T22 9 9
A8 Travel documents (paper) 3 V3. Lack of back-up / failover procedures V3. V3 A8V3 4 T23. e-visa not accepted at check in T23 T23 3 A8.V3.T23 8 8
A8 Travel documents (paper) 3 V3. Lack of back-up / failover procedures V3. V3 A8V3 4 T25. Malicious power failure attack T25 T25 3 A8.V3.T25 8 8
A8 Travel documents (paper) 3 V3. Lack of back-up / failover procedures V3. V3 A8V3 4 T28. Adverse weather condition or other disaster T28 T28 4 A8.V3.T28 9 9
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T2. Spoofing of credentials / bypass authentication T2. T2 5 A8.V12.T2 7 7
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T6. Social engineering attack T6. T6 4 A8.V12.T6 6 6
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T7. Theft [of cards, devices etc] T7. T7 4 A8.V12.T7 6 6
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A8.V12.T8 6 6
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A8.V12.T9 5 5
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T10. Use erroneous and/or unreliable data T10 T10 4 A8.V12.T10 6 6
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T11. Procedures / instructions not followed T11 T11 3 A8.V12.T11 5 5
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T12. Non-compliance with data protection legislation T12 T12 4 A8.V12.T12 6 6
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A8.V12.T13 7 7
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A8.V12.T14 7 7
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A8.V12.T16 6 6
A8 Travel documents (paper) 3 V12. Lack of harmonisation and interoperability of procedures V12 V12 A8V12 2 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A8.V12.T22 7 7
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A8.V24.T30 8 8
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T6. Social engineering attack T6. T6 4 A8.V24.T6 8 8
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T7. Theft [of cards, devices etc] T7. T7 4 A8.V24.T7 8 8
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A8.V24.T8 8 8
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A8.V24.T9 7 7
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A8.V24.T14 9 9
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T15. Cloning of credentials and tags (RFID related) T15 T15 3 A8.V24.T15 8 8
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T16. Unauthorised access to other restricted areas (apart from boarding e.g. control room, personnels' offices) T16 T16 3 A8.V24.T16 8 8
A8 Travel documents (paper) 3 V24. Inherent features (size, material etc.): easy to lose, to be stolen and/or copied (expecially for RFID tags) V24 V24 A8V24 4 T21. Physical RFID tag destruction T21 T21 4 A8.V24.T21 9 9
A9 RFID & barcode readers 4 V2. Excessive dependency on IT systems, network and external infrastructure V2. V2 A9V2 3 T28. Adverse weather condition or other disaster T28 T28 4 A9.V2.T28 9 9
A9 RFID & barcode readers 4 V3. Lack of back-up / failover procedures V3. V3 A9V3 3 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A9.V3.T1 8 8
A9 RFID & barcode readers 4 V3. Lack of back-up / failover procedures V3. V3 A9V3 3 T6. Social engineering attack T6. T6 4 A9.V3.T6 8 8
A9 RFID & barcode readers 4 V3. Lack of back-up / failover procedures V3. V3 A9V3 3 T7. Theft [of cards, devices etc] T7. T7 4 A9.V3.T7 8 8
A9 RFID & barcode readers 4 V3. Lack of back-up / failover procedures V3. V3 A9V3 3 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A9.V3.T9 7 7
A9 RFID & barcode readers 4 V3. Lack of back-up / failover procedures V3. V3 A9V3 3 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A9.V3.T22 9 9
A9 RFID & barcode readers 4 V3. Lack of back-up / failover procedures V3. V3 A9V3 3 T23. e-visa not accepted at check in T23 T23 3 A9.V3.T23 8 8
A9 RFID & barcode readers 4 V3. Lack of back-up / failover procedures V3. V3 A9V3 3 T25. Malicious power failure attack T25 T25 3 A9.V3.T25 8 8
A9 RFID & barcode readers 4 V3. Lack of back-up / failover procedures V3. V3 A9V3 3 T28. Adverse weather condition or other disaster T28 T28 4 A9.V3.T28 9 9
A9 RFID & barcode readers 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A9V4 4 T13. Function creep (data used for other purposes that the ones for which they were originally collected) T13 T13 4 A9.V4.T13 10 10
A9 RFID & barcode readers 4 V4. Lack of or low user awareness and/or training in procedures, use of devices, security aspects etc V4. V4 A9V4 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A9.V4.T14 10 10
A9 RFID & barcode readers 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A9V5 4 T8. Unauthorised access to / deletion / modification of devices / data etc. T8. T8 4 A9.V5.T8 9 9
A9 RFID & barcode readers 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A9V5 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A9.V5.T9 8 8
A9 RFID & barcode readers 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A9V5 4 T10. Use erroneous and/or unreliable data T10 T10 4 A9.V5.T10 9 9
A9 RFID & barcode readers 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A9V5 4 T11. Procedures / instructions not followed T11 T11 3 A9.V5.T11 8 8
A9 RFID & barcode readers 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A9V5 4 T14. Unauthorized check-in and boarding / identity theft T14 T14 4 A9.V5.T14 10 10
A9 RFID & barcode readers 4 V5. Lack of usability / unfriendly user interface(s) of device(s) V5. V5 A9V5 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A9.V5.T30 9 9
A9 RFID & barcode readers 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A9V6 4 T9. Loss or misuse [of cards, devices etc] T9. T9 3 A9.V6.T9 8 8
A9 RFID & barcode readers 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A9V6 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A9.V6.T22 10 10
A9 RFID & barcode readers 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A9V6 4 T11. Procedures / instructions not followed T11 T11 3 A9.V6.T11 8 8
A9 RFID & barcode readers 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A9V6 4 T12. Non-compliance with data protection legislation T12 T12 4 A9.V6.T12 9 9
A9 RFID & barcode readers 4 V6. Lack of interoperability between devices and/or technologies and/or systems V6. V6 A9V6 4 T30. Low acceptance of devices / equipment / procedures T30 T30 4 A9.V6.T30 9 9
A9 RFID & barcode readers 4 V9. Lack of or inadequate identification, authentication and authorisation controls V9. V9 A9V9 3 T29. MANET/Adhoc network routing attack T29 T29 2 A9.V9.T29 6 6
A9 RFID & barcode readers 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A9V10 4 T1. Denial of service attack / Flood / Buffer overflow T1. T1 3 A9.V10.T1 9 9
A9 RFID & barcode readers 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A9V10 4 T11. Procedures / instructions not followed T11 T11 3 A9.V10.T11 8 8
A9 RFID & barcode readers 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A9V10 4 T12. Non-compliance with data protection legislation T12 T12 4 A9.V10.T12 9 9
A9 RFID & barcode readers 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A9V10 4 T22. Malfunctioning/breakdown of systems /devices / equipment T22 T22 4 A9.V10.T22 10 10
A9 RFID & barcode readers 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A9V10 4 T25. Malicious power failure attack T25 T25 3 A9.V10.T25 9 9
A9 RFID & barcode readers 4 V10. Flawed/insufficient design and/or capacity of devices and systems V10 V10 A9V10 4 T28. Adverse weather condition or other disaster T28 T28 4 A9.V10.T28 10 10
A9 RFID & barcode readers 4 V19. Lack of respect to the purpose restriction principle (purpose limitation principle) V19 V19 A9V19 3 T32. Profiling T32 T32 4 A9.V19.T32 8 8
A9 RFID & barcode readers 4 V40. Lack of respect to the legitimacy of data processing, e.g. consent V40 V40 A9V40 3 T33. Exclusion of the data subject from the data processing process T33 T33 4 A9.V40.T33 8 8
A9 RFID & barcode readers 4 V42. Lack of respect to the rights of the data subject (such as the right for rectification, blocking or deletion of data). V42 V42 A9V42 4 T34. Trivialisation of unique identifiers T34 T34 4 A9.V42.T34 9 9