Standardization of Cybersecurity Concepts in Automotive Process Models: An Assessment Tool Proposal

被引:0
|
作者
Moselhy, Noha [1 ,2 ]
Mahmoud, Ahmed Adel [1 ,2 ]
机构
[1] CMMi V1 3 ATM, Giza, Egypt
[2] Valeo, Giza, Egypt
关键词
Automotive SPICE for cybersecurity; Automotive SPIC EPAM v3.1; CMMi v1.3; CMMi v2.0; SSE-CMM; ISO27001; SAE J3061; ISO26262; Automotive software; Improved implementation of process models; CMMi extension; SOC-CMM; A-SPICE;
D O I
10.1007/978-3-031-28073-3_44
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the world of high-tech and information communication domains, the usage of network communication and cloud services is an unavoidable need, which jeopardizes systems and software products to cyber-attacks, causing loss of money, vital information, or may be even causing safety hazards. Hence, cybersecurity is considered as an integral part of the development which grabbed a lot of focus in the late 20th century. This led some huge industries (e.g.: Automotive) and service providers to consider the release of specific standards and process models for Cybersecurity. In August 2021, the German Association for Automotive Industry "VDA" which holds the top car manufacturers worldwide as members to release a new process model appendix called: the Automotive SPICE for Cybersecurity, which focuses on Process Reference, Process Assessment Models for Cybersecurity Engineering, and on the Rating Guidelines of Process Performance for Cybersecurity Engineering. In this paper, a case study of the result of applying this new standard on a sample set of projects will be presented, showing the investigation of challenges and lessons learned by following the traditional methodology of process capability assessments in the new Cybersecurity process assessments, with an introduction of a few tool proposals to cope with the specific requirements and constraints of a Cybersecurity process model that can help practitioners in other domains (e.g.: SSE-CMM). The study also urges the VDA to officially consider those best practices into the newly released Cybersecurity process model of Automotive SPICE to ensure a secure product and threat-immune organizational infrastructure.
引用
收藏
页码:635 / 655
页数:21
相关论文
共 50 条
  • [21] An Open Source Tool to Support the Quantitative Assessment of Cybersecurity
    Nagaraju, Vidhyashree
    Fiondella, Lance
    Wandji, Thierry
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2017), 2017, : 244 - 253
  • [22] ThreatSurf: A method for automated Threat Surface assessment in automotive cybersecurity engineering
    Zelle, Daniel
    Plappert, Christian
    Rieke, Roland
    Scheuermann, Dirk
    Krauss, Christoph
    MICROPROCESSORS AND MICROSYSTEMS, 2022, 90
  • [23] Proposal of Business process Visualization Tool
    Nagai, Akihiko
    Ito, Takayuki
    PROCEEDINGS OF THE 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON COMMERCE AND ENTERPRISE COMPUTING (CEC 2012), 2012, : 135 - 139
  • [24] Reconciling process flexibility and standardization: a case study in the automotive industry
    Assad Neto, Anis
    Sampaio, Jessyca
    Detro, Silvana Pereira
    Deschamps, Fernando
    Portela Santos, Eduardo Alves
    Rocha Loures, Eduardo de Freitas
    OPERATIONS MANAGEMENT RESEARCH, 2021, 14 (3-4) : 507 - 524
  • [25] Reconciling process flexibility and standardization: a case study in the automotive industry
    Anis Assad Neto
    Jessyca Sampaio
    Silvana Pereira Detro
    Fernando Deschamps
    Eduardo Alves Portela Santos
    Eduardo de Freitas Rocha Loures
    Operations Management Research, 2021, 14 : 507 - 524
  • [26] Process Assessment Standardization for Factory Control
    Lam, Michelle
    2014 36TH ELECTRICAL OVERSTRESS/ELECTROSTATIC DISCHARGE SYMPOSIUM (EOS/ESD), 2014,
  • [27] Proposal of Work Standardization to Improve a Metal-mechanical Process
    Casallo, L.
    Lucero, E.
    Maradiegue, F.
    Alvarez, J. C.
    2021 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEE IEEM21), 2021, : 668 - 672
  • [28] Development of a framework for the flexibility assessment of automotive production concepts
    Kampker, Achim
    Bergweiler, Georg
    Hollah, Ansgar
    Bickendorf, Philipp
    Hoffmann, Felix
    52ND CIRP CONFERENCE ON MANUFACTURING SYSTEMS (CMS), 2019, 81 : 34 - 39
  • [29] Software process assessment concepts
    Haase, VH
    JOURNAL OF SYSTEMS ARCHITECTURE, 1996, 42 (08) : 621 - 631
  • [30] Empirical evaluation of a threat modeling language as a cybersecurity assessment tool
    Katsikeas, Sotirios
    Ling, Engla Rencelj
    Johnsson, Pontus
    Ekstedt, Mathias
    COMPUTERS & SECURITY, 2024, 140