The Cybersecurity Extension for ASPICE - A View from ASPICE Assessors

被引:2
|
作者
Schlager, Christian [1 ]
Macher, Georg [1 ]
机构
[1] Graz Univ Technol, Graz, Austria
来源
SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2021 | 2021年 / 1442卷
关键词
ASPICE; Cybersecurity; Assessment;
D O I
10.1007/978-3-030-85521-5_27
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
ASPICE has been introduced to development of embedded systems at automotive suppliers to assess the capability of processes. ASPICE covers processes for software, system, quality assurance, configuration management, problem resolution, change management, project management and supplier monitoring. It defines a scheme for determining the capability of the process based on the underlying PAM. HW Spice is also taken into consideration, because it is also necessary for Cybersecurity, but not mechanical Spice. Based on ASPICE VDA defined processes for Cybersecurity Engineering, Cybersecurity Risk Management and Supplier Request and Selection. This means additional effort for the assessors and also the engineering team when the ASPICE assessment is extended by processes of Cybersecurity to satisfy the requirements of standard ISO/SAE 21434. This paper investigates for the method of mapping the base practices (BP) of cybersecurity process defined by VDA to BP of ASPICE process(es) to reduce the time of an assessment by merging the Base Practices of Processes from Cybersecurity with the Base Practices of Processes from ASPICE.
引用
收藏
页码:409 / 422
页数:14
相关论文
共 50 条
  • [1] 'Aspice domini'.
    Di Grazia, DM
    NOTES, 2005, 61 (03) : 858 - 866
  • [2] Review: Aspice hunc opus mirum
    Kranjec, Ivor
    Krleza, Palmira
    ARS ADRIATICA, 2020, 10 (01) : 287 - 294
  • [3] Agile Software Development Projects Compliance to ASPICE
    Ibrahim, Ahmed
    Badr, Khaled
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2024, PT II, 2024, 2180 : 294 - 308
  • [4] ASPICE: an interface system for independent life
    Aloise, F.
    Cincotti, F.
    Babiloni, F.
    Marciani, M. G.
    Morelli, D.
    Paolucci, S.
    Oriolo, G.
    Cherubini, A.
    Sciarra, F.
    Mangiola, F.
    Melpignano, A.
    Davide, F.
    Mattia, D.
    SMART HOMES AND BEYOND, 2006, 19 : 343 - 346
  • [5] Paving the Road Towards Cybersecurity Compliance: Navigating ISO 21434 and ASPICE from Organizational- to Project-Level Compliance
    Barmayoun, Darius
    Kemeter, Martin
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2024, PT I, 2024, 2179 : 353 - 362
  • [6] Brain-operated assistive devices: the ASPICE project
    Cincotti, F.
    Aloise, F.
    Babiloni, F.
    Marciani, M. G.
    Morelli, D.
    Paolucci, S.
    Oriolo, G.
    Cherubini, A.
    Bruscino, S.
    Sciarra, F.
    Mangiola, F.
    Melpignano, A.
    Davide, F.
    Mattia, D.
    2006 1ST IEEE RAS-EMBS INTERNATIONAL CONFERENCE ON BIOMEDICAL ROBOTICS AND BIOMECHATRONICS, VOLS 1-3, 2006, : 830 - +
  • [7] 基于Aspice的汽车软件开发流程实践
    周晓翠
    崔长军
    钟涛
    雍建军
    汽车实用技术, 2020, (01) : 109 - 110+125
  • [8] Integrating Agile Development with Process Standards Like ASPICE and ISO 26262
    Karlsson, Even-Andre
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT (PROFES 2016), 2016, 10027 : 763 - 764
  • [9] 基于Aspice的汽车软件开发流程研究
    严舰
    电脑知识与技术, 2021, 17 (24) : 90 - 91+94
  • [10] Implementing Process Increments in Sprints: A Way of Working for Improved ASPICE Compliance
    Bhat, Sudeesh
    Mounir, Mourad
    Badr, Khaled
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2024, PT I, 2024, 2179 : 405 - 412