Security Assurance Cases for Road Vehicles: an Industry Perspective

03/31/2020
by   Mazen Mohamad, et al.
0

Assurance cases are structured arguments that are commonly used to reason about the safety of a product or service. Currently, there is an ongoing push towards using assurance cases for also cybersecurity, especially in safety-critical domains, like automotive. While the industry is faced with the challenge of defining a sound methodology to build security assurance cases, the state of the art is rather immature. Therefore, we have conducted a thorough investigation of the (external) constraints and (internal) needs that security assurance cases have to satisfy in the context of the automotive industry. This has been done in the context of two large automotive companies in Sweden. The end result is a set of recommendations that automotive companies can apply in order to define security assurance cases that are (i) aligned with the constraints imposed by the existing and upcoming standards and regulations and (ii)harmonized with the internal product development processes and organizational practices. We expect the results to be also of interest for product companies in other safety-critical domains, like healthcare, transportation, and so on

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/28/2019

Challenges of Scaled Agile for Safety-Critical Systems

Automotive companies increasingly adopt scaled agile methods to allow th...
research
03/31/2020

Security Assurance Cases – State of the Art of an Emerging Approach

Security Assurance Cases (SAC) are a form of structured argumentation us...
research
07/20/2018

Safety-Critical Systems and Agile Development: A Mapping Study

In the last decades, agile methods had a huge impact on how software is ...
research
06/01/2022

Sustaining Security and Safety in ICT: A Quest for Terminology, Objectives, and Limits

Security and safety are intertwined concepts in the world of computing. ...
research
04/24/2018

Communication channels in safety analysis: An industrial exploratory case study

Safety analysis is a predominant activity in developing safety-critical ...
research
02/23/2018

Lean Internal Startups for Software Product Innovation in Large Companies: Enablers and Inhibitors

To compete in this age of disruption, large companies cannot rely on cos...
research
05/07/2019

Model Based System Assurance Using the Structured Assurance Case Metamodel

Assurance cases are used to demonstrate confidence in system properties ...

Please sign up or login with your details

Forgot password? Click here to reset