CANape_Kernel_PressRelease_202601_Graphic2.jpg

Cybersecurity

Cybersecurity Analysis and Risk Assessment with ISO/SAE 21434

Cars are becoming more and more connected, and therefore vulnerable to increasing cyber-attacks from the outside. This could severely threaten the safety of passengers and the public. However, the existing standards do not address the unique cybersecurity challenges in automotive engineering, e.g. safety, long life cycle and use of embedded controllers. Thus, a uniform guidelines and standards for automotive security need to be established.

Why ISO/SAE 21434?

ISO/SAE 21434 “Road vehicles – Cybersecurity engineering” is the future automotive security standard.  It is important for the automotive product development and all related processes.

The ISO/SAE 21434 will define common terminologies across the global automotive supply chain and drive industry consensus on key cybersecurity issues. It sets minimum criteria for vehicle cybersecurity engineering and provides a governance reference to point to for engineering quality.

Scope of ISO/SAE 21434

The new ISO/SAE 21434 safeguards the entire development process and lifecycle of a road vehicle and promotes “security by design”. Following the V-model, it includes requirements engineering, design, specification, implementation, test and operation.

The ISO/SAE 21434 is therefore a process-oriented standard and helps define a structured process to ensure cybersecurity along the lifecycle. It will not prescribe specific cybersecurity technology, solutions or remediation methods.

Cybersecurity Processes

We support establishing a state-of-the-art cybersecurity process where we perform the following activities:

Cybersecurity Processes

Our Solutions

  • Vector SecurityCheck with threat and risk analysis (TARA), security concept, prioritized proposals and initial methodical instructions
  • Methodology and tool support for security-oriented tests and resilience
  • Process assessments for your suppliers
  • Awareness training on cybersecurity and ISO/SAE 21434 for managers and developers
  • Training and coaching for managers and developers for the effective implementation of ISO/SAE 21434 across the life cycle
  • Interim Safety and Security Manager
Technical Article Highlight
Practical Cybersecurity with ISO 21434 Published on ATZ Electronics, 03-04/2022 Business IT and embedded product IT are converging into multi-purpose systems. The ISO 21434 standard on automotive cybersecurity provides guidelines to mitigate security risks in product, project, and organization. This article by Vector introduces systematic security engineering following ISO 21434. It also provides practical examples from global projects for the efficient implementation of ISO 21434.

Vector SecurityCheck

End-to-End Security Safeguards Analysis

Security analyses and security concept for end-to-end safeguards

Threat Scenario-Based Security Requirements Specification

Development and specification of security requirements based on threat scenarios and Automotive Common Criteria

Asset and Threat Classification Analysis

Assets are agreed, and each asset is analyzed with respect to potential attacks, the effect of the attack and the resulting threat. Each threat is classified according to a security level. The first step in this work package is to analyze the security items in scope of the security engineering process.

Cybersecurity Incident Concept Development

Develop concepts and solutions around related Cybersecurity incidents reported in industry and research organizations.

ECU Security Weakness Analysis and Risk Prevention

Analyze ECUs, find potential security weakness and report back to find new requirements, testing or processes which can be updated to avoid future risk. Storyboards, use cases, proof-of-concept demonstrations, specifications and requirements development experience

Security Concept and Attack Scheme Review

Analyze security concept and attack schemes

Security Goal Derivation for High-Level Threats

For each threat with high security level security goals are derived. Security goals can be summarized as high-level security requirements.

Functional and Technical Security Requirements Refinement

Each security goal is then further refined into functional and technical security requirements which help to achieve the security goal. This step answers to the questions of “How?” and provides concrete answers for the implementation.

Preliminary Security Requirements Gap Analysis

Additional to that, if already the initial concept documents are available, a preliminary gap analysis can be performed where it is assessed if the system requirements specification covers the related security aspects based on the security requirements or not.

Hands-on Tutorials

Your Partner for Engineering Excellence
Vector Consulting Services
Team
Your Partner for Engineering Excellence
Let us build the ideal setup for your engineering challenges together. Reach out to our team to explore how our powerful coaching can seamlessly integrate into your existing workflows.