Security Engineering for ISO 21434

12/30/2020
by   Yuri Gil Dantas, et al.
0

The ISO 21434 is a new standard that has been proposed to address the future challenges of automotive cybersecurity. This white paper takes a closer look at the ISO 21434 helping engineers to understand the ISO 21434 parts, the key activities to be carried out and the main artefacts that shall be produced. As any certification, obtaining the ISO 21434 certification can be daunting at first sight. Engineers have to deploy processes that include several security risk assessment methods to produce security arguments and evidence supporting item security claims. In this white paper, we propose a security engineering approach that can ease this process by relying on Rigorous Security Assessments and Incremental Assessment Maintenance methods supported by automation. We demonstrate by example that the proposed approach can greatly increase the quality of the produced artefacts, the efficiency to produce them, as well as enable continuous security assessment. Finally, we point out some key research directions that we are investigating to fully realize the proposed approach.

READ FULL TEXT
research
10/11/2018

Model-Based Safety and Security Engineering

By exploiting the increasing surface attack of systems, cyber-attacks ca...
research
08/14/2023

Understanding Hackers' Work: An Empirical Study of Offensive Security Practitioners

Offensive security-tests are a common way to pro-actively discover poten...
research
03/11/2019

CloudSafe: A Tool for an Automated Security Analysis for Cloud Computing

Cloud computing has been adopted widely, providing on-demand computing r...
research
05/30/2020

Cyber LOPA: A New Approach for CPS Safety Design in the Presence of Cyber Attacks

Safety risk assessment is an essential process to ensure a dependable Cy...
research
05/07/2021

A Multivariate Density Forecast Approach for Online Power System Security Assessment

A multivariate density forecast model based on deep learning is designed...
research
01/25/2022

Automating Safety and Security Co-Design through Semantically-Rich Architecture Patterns

During the design of safety-critical systems, safety and security engine...

Please sign up or login with your details

Forgot password? Click here to reset