Automotive Cybersecurity Engineering Standardization and Regulation: An Integrated Model
摘要
The automotive industry stands out with its innovative breakthroughs while facing new challenges to harmonize and enhance their cybersecurity engineering practices. In recent years there have been a release of multiple standards and regulations, especially within the area of vehicle engineering and product management. International organizations have been leading this effort. These standards are increasingly gaining traction within the automotive sector for both car manufacturers and parts suppliers. Moreover, regulations for vehicle certifications have highlighted the significance of meeting certain compliance criteria and played a significant role in driving industry interest on the adoption of standardized practices. There have been numerous attempts to adhere simultaneously to some essential automotive cybersecurity standards. However, in certain instances, these efforts have resulted in an increase of the “cost of quality” due to redundancy and overlapping. Additionally, inconsistencies and a lack of connectivity and correlation between standards have posed challenges for practitioners striving to ensure secure vehicle development. The primary contributions of this paper lie in the analysis of various key standards in a context different from those of which have already been individually applied in the industry by cross-referencing these standards while highlighting the common requirements and practices among those norms to develop an inte-grated and enhanced cybersecurity implementation model to the cybersecurity product engineering phase. Additionally, providing a simplified process flow that can be used by practitioners as a strategy. This paper also provides the resulting pros and challenges from applying this model through lessons learned of conducting an ISO/SAE 21434 audit and four Automotive Software Process Im-provement and Capability Determination (ASPICE) for cybersecurity assessments in an organization with four selected security related projects.