Standardization of Cybersecurity Concepts in Automotive Process Models: An Assessment Tool Proposal

被引:0
|
作者
Moselhy, Noha [1 ,2 ]
Mahmoud, Ahmed Adel [1 ,2 ]
机构
[1] CMMi V1 3 ATM, Giza, Egypt
[2] Valeo, Giza, Egypt
关键词
Automotive SPICE for cybersecurity; Automotive SPIC EPAM v3.1; CMMi v1.3; CMMi v2.0; SSE-CMM; ISO27001; SAE J3061; ISO26262; Automotive software; Improved implementation of process models; CMMi extension; SOC-CMM; A-SPICE;
D O I
10.1007/978-3-031-28073-3_44
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the world of high-tech and information communication domains, the usage of network communication and cloud services is an unavoidable need, which jeopardizes systems and software products to cyber-attacks, causing loss of money, vital information, or may be even causing safety hazards. Hence, cybersecurity is considered as an integral part of the development which grabbed a lot of focus in the late 20th century. This led some huge industries (e.g.: Automotive) and service providers to consider the release of specific standards and process models for Cybersecurity. In August 2021, the German Association for Automotive Industry "VDA" which holds the top car manufacturers worldwide as members to release a new process model appendix called: the Automotive SPICE for Cybersecurity, which focuses on Process Reference, Process Assessment Models for Cybersecurity Engineering, and on the Rating Guidelines of Process Performance for Cybersecurity Engineering. In this paper, a case study of the result of applying this new standard on a sample set of projects will be presented, showing the investigation of challenges and lessons learned by following the traditional methodology of process capability assessments in the new Cybersecurity process assessments, with an introduction of a few tool proposals to cope with the specific requirements and constraints of a Cybersecurity process model that can help practitioners in other domains (e.g.: SSE-CMM). The study also urges the VDA to officially consider those best practices into the newly released Cybersecurity process model of Automotive SPICE to ensure a secure product and threat-immune organizational infrastructure.
引用
收藏
页码:635 / 655
页数:21
相关论文
共 50 条
  • [41] An Advanced Assessment Tool and Process
    Burge, Legand L.
    Leach, Ronald J.
    SIGCSE 10: PROCEEDINGS OF THE 41ST ACM TECHNICAL SYMPOSIUM ON COMPUTER SCIENCE EDUCATION, 2010, : 451 - 454
  • [42] Process standardization to support service process assessment and re-engineering
    Curiazzi, Roberta
    Rondini, Alice
    Pirola, Fabiana
    Ouertani, Mohamed-Zied
    Pezzotta, Giuditta
    PRODUCT-SERVICE SYSTEMS ACROSS LIFE CYCLE, 2016, 47 : 347 - 352
  • [43] Proposal of an assessment tool to diagnose industrial symbiosis readiness
    Agudo, Fabiana Liar
    Bezerra, Barbara Stolte
    Bertolucci Paes, Luis Alberto
    Gobbo Junior, Jose Alcides
    SUSTAINABLE PRODUCTION AND CONSUMPTION, 2022, 30 : 916 - 929
  • [44] PROPOSAL OF A PRODUCT INDICATOR AS A TOOL FOR A COMPREHENSIVE ASSESSMENT OF WINDOWS
    Arranz, Beatriz
    Bedoya-Frutos, Cesar
    Vega-Sanchez, Sergio
    ARCHNET-IJAR INTERNATIONAL JOURNAL OF ARCHITECTURAL RESEARCH, 2018, 12 (01) : 266 - 279
  • [45] Customer Knowledge Management Models: Assessment and Proposal
    Buchnowska, Dorota
    RESEARCH IN SYSTEMS ANALYSIS AND DESIGN: MODELS AND METHODS, 2011, 93 : 25 - 38
  • [46] Guidelines for the Assessment Process (GAP):: A proposal for discussion
    Fernández-Ballesteros, R
    De Bruyn, EEJ
    Godoy, A
    Hornke, LF
    Ter Laak, J
    Vizcarro, C
    Westhoff, K
    Westmeyer, H
    Zaccagnini, JL
    EUROPEAN JOURNAL OF PSYCHOLOGICAL ASSESSMENT, 2001, 17 (03) : 187 - 200
  • [47] STANDARDIZATION OF THE ASSESSMENT PROCESS IN A DECENTRALIZED SERVICE DELIVERY SYSTEM
    ANDERSON, E
    GERONTOLOGIST, 1982, 22 : 63 - 63
  • [48] Automotive Cybersecurity Vulnerability Assessment Using the Common Vulnerability Scoring System and Bayesian Network Model
    Wang, Yinghui
    Yu, Bin
    Yu, Haiyang
    Xiao, Lingyun
    Ji, Haojie
    Zhao, Yanan
    IEEE SYSTEMS JOURNAL, 2023, 17 (02): : 2880 - 2891
  • [49] CyberROAD: A cybersecurity risk assessment ontology for automotive domain aligned with ISO/SAE 21434:2021
    Khalil, Karim
    Gehrmann, Christian
    Vogel, Guenther
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2025, 90
  • [50] Security Concepts as Add-On for Process Models
    Geisel, Jacob
    Hamid, Brahim
    Bruel, Jean-Michel
    2015 20TH INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS), 2015, : 190 - 193