错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Proposal for ISO24089 Audit Methodology Before Type Approvals: Interface with Automotive SPICE® PAM4.0

  • Noha Moselhy,
  • Ahmed Seddik,
  • Doaa Badawy

摘要

Following the release of ISO21434 [1] which addressed the UNECE [2] regulation no. 155 for Vehicle Cybersecurity Management Systems (CSMS) and Development Projects in Aug, 2021; the release of ISO24089 [3] was anticipated to address regulation no. 156 which is focused on Software Updates Management Systems (SUMS) such that both standards together can cover all the needed rules for in-vehicle software cybersecurity before type approvals. ISO24089 release took place in Feb, 2023 and addressed quality management, functional safety management and cybersecurity management at organizations and projects involved in software update engineering activities for road vehicles, to provide them with requirements and work products needed to manage this activity in post-production phases for vehicles or vehicle systems. Moreover, many of the modern automotive industry Cybersecurity standards (e.g.: ISO21434) and manufacturers (e.g.: Chinese OEM’s) are now interested in software update management procedures even in post development pre-production phases. In this paper, we provide a verification proposal for different types of reviewers; quality engineers, cybersecurity auditors, and even A-SPICE [4] assessors, who will deal with software update engineering projects that complies with the new requirements of ISO24089, during all phases in order to optimize the audits and ensure effectiveness and efficiency.