错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Paving the Road Towards Cybersecurity Compliance: Navigating ISO 21434 and ASPICE from Organizational- to Project-Level Compliance

  • Darius Barmayoun,
  • Martin Kemeter

摘要

This article explores the rigorous process of aligning internal development processes with the demanding requirements of ISO/SAE 21434 and ASPICE for Cybersecurity within the Automotive Industry. The necessity for urgent automotive cybersecurity compliance is highlighted by the evolving threats and regulatory expectations in the industry. Through a detailed gap analysis, this study pinpoints discrepancies between the supplier's existing practices and those mandated by the standards, with a particular focus on ISO 21434's Clause 10, Product Development. The analysis further led to the development of a separate ASPICE for Cybersecurity Compliance Matrix, following the resolution of gaps highlighted in the ISO/SAE 21434 matrix. This step illustrates the complexity and resource-intensiveness of attaining dual compliance, a task that enhances cybersecurity measures but demands considerable effort. In response to the challenges encountered, the article proposes an innovative approach for future research: developing a unified compliance matrix that directly maps ASPICE for Cybersecurity requirements to the ISO/SAE 21434 standard. This proposed methodology aims to simplify the compliance process, significantly reducing the resources required for conducting gap analyses and ensuring compliance. Conducted within a Tier 1 supplier context, this research makes a valuable contribution to the automotive industry by offering a practical roadmap towards achieving cybersecurity compliance in automotive development processes.