Standardization of Cybersecurity Concepts in Automotive Process Models: An Assessment Tool Proposal

被引:0
|
作者
Moselhy, Noha [1 ,2 ]
Mahmoud, Ahmed Adel [1 ,2 ]
机构
[1] CMMi V1 3 ATM, Giza, Egypt
[2] Valeo, Giza, Egypt
关键词
Automotive SPICE for cybersecurity; Automotive SPIC EPAM v3.1; CMMi v1.3; CMMi v2.0; SSE-CMM; ISO27001; SAE J3061; ISO26262; Automotive software; Improved implementation of process models; CMMi extension; SOC-CMM; A-SPICE;
D O I
10.1007/978-3-031-28073-3_44
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the world of high-tech and information communication domains, the usage of network communication and cloud services is an unavoidable need, which jeopardizes systems and software products to cyber-attacks, causing loss of money, vital information, or may be even causing safety hazards. Hence, cybersecurity is considered as an integral part of the development which grabbed a lot of focus in the late 20th century. This led some huge industries (e.g.: Automotive) and service providers to consider the release of specific standards and process models for Cybersecurity. In August 2021, the German Association for Automotive Industry "VDA" which holds the top car manufacturers worldwide as members to release a new process model appendix called: the Automotive SPICE for Cybersecurity, which focuses on Process Reference, Process Assessment Models for Cybersecurity Engineering, and on the Rating Guidelines of Process Performance for Cybersecurity Engineering. In this paper, a case study of the result of applying this new standard on a sample set of projects will be presented, showing the investigation of challenges and lessons learned by following the traditional methodology of process capability assessments in the new Cybersecurity process assessments, with an introduction of a few tool proposals to cope with the specific requirements and constraints of a Cybersecurity process model that can help practitioners in other domains (e.g.: SSE-CMM). The study also urges the VDA to officially consider those best practices into the newly released Cybersecurity process model of Automotive SPICE to ensure a secure product and threat-immune organizational infrastructure.
引用
收藏
页码:635 / 655
页数:21
相关论文
共 50 条
  • [1] Automotive Cybersecurity Engineering Standardization and Regulation: An Integrated Model
    Mohamed, Ahmed Adel
    Aslan, Heba
    Arafa, Tamer
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2024, PT I, 2024, 2179 : 429 - 445
  • [2] A Process to Facilitate Automated Automotive Cybersecurity Testing
    Marksteiner, Stefan
    Marko, Nadja
    Smulders, Andre
    Karagiannis, Stelios
    Stahl, Florian
    Hamazaryan, Hayk
    Schlick, Rupert
    Kraxberger, Stefan
    Vasenev, Alexandr
    2021 IEEE 93RD VEHICULAR TECHNOLOGY CONFERENCE (VTC2021-SPRING), 2021,
  • [3] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [4] A simulation framework for automotive cybersecurity risk assessment
    Jayaratne, Don Nalin Dharshana
    Kamtam, Suraj Harsha
    Shaikh, Siraj Ahmed
    Ramli, Muhamad Azfar
    Lu, Qian
    Mepparambath, Rakhi Manohar
    Nguyen, Hoang Nga
    Rakib, Abdur
    SIMULATION MODELLING PRACTICE AND THEORY, 2024, 136
  • [5] An Automotive Cybersecurity Maturity Level Assessment Programme
    Grumer, Patrick
    Brandao, Pedro
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS, DSN-W, 2023, : 84 - 91
  • [6] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Yunpeng Wang
    Yinghui Wang
    Hongmao Qin
    Haojie Ji
    Yanan Zhang
    Jian Wang
    Automotive Innovation, 2021, 4 : 253 - 261
  • [7] Automotive Data Management SPICE Assessment - Comparison of Process Assessment Models
    Portner, Lara
    Riel, Andreas
    Leclaire, Marcel
    Makkar, Samer Sameh
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2023, PT I, 2023, 1890 : 205 - 219
  • [8] PROPOSAL FOR THE STANDARDIZATION OF CARDIOCIRCULATORY PERFORMANCE ASSESSMENT
    HOLSCHER, U
    ZEITSCHRIFT FUR KLINISCHE MEDIZIN-ZKM, 1988, 43 (16): : 1393 - 1397
  • [9] Consistency of Cybersecurity Process and Product Assessments in the Automotive Domain
    Schlager, Christian
    Messnarz, Richard
    Ekert, Damjan
    Danmayr, Tobias
    Aschbacher, Laura
    Iriskic, Almin
    Macher, Georg
    Brenner, Eugen
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2023, PT I, 2023, 1890 : 343 - 355
  • [10] Research and Application of Risk Assessment Method for Automotive Cybersecurity
    Ji, Haojie
    Yu, Haiyang
    Wang, Yinghui
    Peng, Jing
    CICTP 2021: ADVANCED TRANSPORTATION, ENHANCED CONNECTION, 2021, : 1535 - 1544