Experiences with the automotive SPICE for cybersecurity assessment model and tools

被引:0
|
作者
Messnarz, Richard [1 ]
Ekert, Damjan [1 ]
Macher, Georg [2 ]
Much, Alexander [3 ]
Zehetner, Tobias [1 ]
Aschbacher, Laura [1 ]
机构
[1] ISCN GesmbH, Graz, Austria
[2] Graz Univ Technol, Graz, Austria
[3] Elektrobit AG, Erlangen, Germany
关键词
capability adviser tool based assessment; CSMS audit; cybersecurity ASPICE assessment; first experiences; IMPROVEMENT;
D O I
10.1002/smr.2519
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In August 2021 the ISO 21434:2021 standard for Road vehicles-Cybersecurity Engineering has been published. At the same time the blue book from VDA (Verein der Deutschen Automobilgesellschaft; German Automotive Association) for Automotive SPICE cybersecurity assessments has been released. In addition in the period September-December 2021 the training material for iNTACS (INTernational Assessor Certification Schema) certified Automotive SPICE for cybersecurity assessors has been developed. Since February 2022 the upgrade training of assessors worldwide has started. Beside the ASPICE (Automotive SPICE) for cybersecurity blue book also a red book from VDA has been published. The red book describes the questions to check in an ACSMS (Automotive CyberSecurity Management System) audit. This paper explains the main strategy and content for ASPICE for Cybersecurity assessments and how such assessments are integrated to the overall ACSMS strategy. Also, the paper outlines an example method and tool used in ASPICE for cybersecurity assessments and how such assessment results will look like.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] First Experiences with the Automotive SPICE for Cybersecurity Assessment Model
    Messnarz, Richard
    Norimatsu, So
    Dobaj, Juergen
    Ekert, Damjan
    Macher, Georg
    Zehetner, Tobias
    Aschbacher, Laura
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2021, 2021, 1442 : 531 - 547
  • [2] Experiences with ASPICE 3.1 and the VDA Automotive SPICE Guidelines - Using Advanced Assessment Systems
    Messnarz, Richard
    Ekert, Damjan
    Zehetner, Tobias
    Aschbacher, Laura
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT (EUROSPI 2019), 2019, 1060 : 549 - 562
  • [3] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [4] A simulation framework for automotive cybersecurity risk assessment
    Jayaratne, Don Nalin Dharshana
    Kamtam, Suraj Harsha
    Shaikh, Siraj Ahmed
    Ramli, Muhamad Azfar
    Lu, Qian
    Mepparambath, Rakhi Manohar
    Nguyen, Hoang Nga
    Rakib, Abdur
    SIMULATION MODELLING PRACTICE AND THEORY, 2024, 136
  • [5] An Automotive Cybersecurity Maturity Level Assessment Programme
    Grumer, Patrick
    Brandao, Pedro
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS, DSN-W, 2023, : 84 - 91
  • [6] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Yunpeng Wang
    Yinghui Wang
    Hongmao Qin
    Haojie Ji
    Yanan Zhang
    Jian Wang
    Automotive Innovation, 2021, 4 : 253 - 261
  • [7] Research and Application of Risk Assessment Method for Automotive Cybersecurity
    Ji, Haojie
    Yu, Haiyang
    Wang, Yinghui
    Peng, Jing
    CICTP 2021: ADVANCED TRANSPORTATION, ENHANCED CONNECTION, 2021, : 1535 - 1544
  • [8] Computing an Automotive Cybersecurity Maturity Level Assessment Programme
    Grumer, Patrick
    Brandao, Pedro
    7TH ACM COMPUTER SCIENCE IN CARS SYMPOSIUM, CSCS 2023, 2023,
  • [9] Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain
    Plappert, Christian
    Zelle, Daniel
    Gadacz, Henry
    Rieke, Roland
    Scheuermann, Dirk
    Kraus, Christoph
    2021 29TH EUROMICRO INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING (PDP 2021), 2021, : 266 - 275
  • [10] An Evaluation of Cybersecurity Assessment Tools on a SCADA Environment
    Hahn, Adam
    Govindarasu, Manimaran
    2011 IEEE POWER AND ENERGY SOCIETY GENERAL MEETING, 2011,