
Cars are becoming more and more connected, and therefore vulnerable to increasing cyber-attacks from the outside. This could severely threaten the safety of passengers and the public. However, the existing standards do not address the unique cybersecurity challenges in automotive engineering, e.g. safety, long life cycle and use of embedded controllers. Thus, a uniform guidelines and standards for automotive security need to be established.
Why ISO/SAE 21434?
ISO/SAE 21434 “Road vehicles – Cybersecurity engineering” is the future automotive security standard. It is important for the automotive product development and all related processes.
The ISO/SAE 21434 will define common terminologies across the global automotive supply chain and drive industry consensus on key cybersecurity issues. It sets minimum criteria for vehicle cybersecurity engineering and provides a governance reference to point to for engineering quality.
Scope of ISO/SAE 21434
The new ISO/SAE 21434 safeguards the entire development process and lifecycle of a road vehicle and promotes “security by design”. Following the V-model, it includes requirements engineering, design, specification, implementation, test and operation.
The ISO/SAE 21434 is therefore a process-oriented standard and helps define a structured process to ensure cybersecurity along the lifecycle. It will not prescribe specific cybersecurity technology, solutions or remediation methods.
Cybersecurity Processes
We support establishing a state-of-the-art cybersecurity process where we perform the following activities:


Our Solutions
- Vector SecurityCheck with threat and risk analysis (TARA), security concept, prioritized proposals and initial methodical instructions
- Methodology and tool support for security-oriented tests and resilience
- Process assessments for your suppliers
- Awareness training on cybersecurity and ISO/SAE 21434 for managers and developers
- Training and coaching for managers and developers for the effective implementation of ISO/SAE 21434 across the life cycle
- Interim Safety and Security Manager
Vector SecurityCheck
End-to-End Security Safeguards Analysis
Security analyses and security concept for end-to-end safeguards
Threat Scenario-Based Security Requirements Specification
Development and specification of security requirements based on threat scenarios and Automotive Common Criteria
Asset and Threat Classification Analysis
Assets are agreed, and each asset is analyzed with respect to potential attacks, the effect of the attack and the resulting threat. Each threat is classified according to a security level. The first step in this work package is to analyze the security items in scope of the security engineering process.
Cybersecurity Incident Concept Development
Develop concepts and solutions around related Cybersecurity incidents reported in industry and research organizations.
ECU Security Weakness Analysis and Risk Prevention
Analyze ECUs, find potential security weakness and report back to find new requirements, testing or processes which can be updated to avoid future risk. Storyboards, use cases, proof-of-concept demonstrations, specifications and requirements development experience
Security Concept and Attack Scheme Review
Analyze security concept and attack schemes
Security Goal Derivation for High-Level Threats
For each threat with high security level security goals are derived. Security goals can be summarized as high-level security requirements.
Functional and Technical Security Requirements Refinement
Each security goal is then further refined into functional and technical security requirements which help to achieve the security goal. This step answers to the questions of “How?” and provides concrete answers for the implementation.
Preliminary Security Requirements Gap Analysis
Additional to that, if already the initial concept documents are available, a preliminary gap analysis can be performed where it is assessed if the system requirements specification covers the related security aspects based on the security requirements or not.
Hands-on Tutorials

