Experiences with the automotive SPICE for cybersecurity assessment model and tools

被引:4
|
作者
Messnarz, Richard [1 ]
Ekert, Damjan [1 ]
Macher, Georg [2 ]
Much, Alexander [3 ]
Zehetner, Tobias [1 ]
Aschbacher, Laura [1 ]
机构
[1] ISCN GesmbH, Graz, Austria
[2] Graz Univ Technol, Graz, Austria
[3] Elektrobit AG, Erlangen, Germany
关键词
capability adviser tool based assessment; CSMS audit; cybersecurity ASPICE assessment; first experiences; IMPROVEMENT;
D O I
10.1002/smr.2519
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In August 2021 the ISO 21434:2021 standard for Road vehicles-Cybersecurity Engineering has been published. At the same time the blue book from VDA (Verein der Deutschen Automobilgesellschaft; German Automotive Association) for Automotive SPICE cybersecurity assessments has been released. In addition in the period September-December 2021 the training material for iNTACS (INTernational Assessor Certification Schema) certified Automotive SPICE for cybersecurity assessors has been developed. Since February 2022 the upgrade training of assessors worldwide has started. Beside the ASPICE (Automotive SPICE) for cybersecurity blue book also a red book from VDA has been published. The red book describes the questions to check in an ACSMS (Automotive CyberSecurity Management System) audit. This paper explains the main strategy and content for ASPICE for Cybersecurity assessments and how such assessments are integrated to the overall ACSMS strategy. Also, the paper outlines an example method and tool used in ASPICE for cybersecurity assessments and how such assessment results will look like.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] Standardization of Cybersecurity Concepts in Automotive Process Models: An Assessment Tool Proposal
    Moselhy, Noha
    Mahmoud, Ahmed Adel
    ADVANCES IN INFORMATION AND COMMUNICATION, FICC, VOL 2, 2023, 652 : 635 - 655
  • [22] ThreatSurf: A method for automated Threat Surface assessment in automotive cybersecurity engineering
    Zelle, Daniel
    Plappert, Christian
    Rieke, Roland
    Scheuermann, Dirk
    Krauss, Christoph
    MICROPROCESSORS AND MICROSYSTEMS, 2022, 90
  • [23] Self-assessment Model and Review Technique for SPICE: SMART SPICE
    Kar, Sharmistha
    Das, Satyabrata
    Rath, Amiya Kumar
    Kar, Subrata Kumar
    SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION, 2012, 290 : 222 - +
  • [24] Towards A Testbed for Automotive Cybersecurity
    Fowler, Daniel S.
    Cheah, Madeline
    Shaikh, Siraj Ahmed
    Bryans, Jeremy
    2017 10TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST), 2017, : 540 - 541
  • [25] A-SPICE for Cybersecurity: Analysis and Enriched Practices
    Magdy, Esraa
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2021, 2021, 1442 : 564 - 574
  • [26] Automotive Cybersecurity - Training the Future
    Schmittner, Christoph
    Shaaban, Abdelkader
    Stolfa, Svatopluk
    Stolfa, Jakub
    Plucar, Jan
    Spanyik, Marek
    Salamun, Alen
    Messnarz, Richard
    Ekert, Damjan
    Macher, Georg
    Much, Alexander
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2021, 2021, 1442 : 211 - 219
  • [27] Smart Grid Cybersecurity Risk Assessment Experiences with the SGIS Toolbox
    Langer, Lucie
    Smith, Paul
    Hutle, Martin
    2015 International Symposium on Smart Electric Distribution Systems and Technologies (EDST), 2015, : 475 - 482
  • [28] A Model-Driven Methodology for Automotive Cybersecurity Test Case Generation
    Marksteiner, Stefan
    Priller, Peter
    2021 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2021), 2021, : 129 - 135
  • [29] Automotive SPICE Draft PAM V4.0 in Action: BETA Assessment
    Moselhy, Noha
    Adel, Ahmed
    Seddik, Ahmed
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2023, PT II, 2023, 1891 : 96 - 112
  • [30] A Global Survey of Standardization and Industry Practices of Automotive Cybersecurity Validation and Verification Testing Processes and Tools
    Roberts, Andrew
    Marksteiner, Stefan
    Soyturk, Mujdat
    Yaman, Berkay
    Yang, Yi
    SAE INTERNATIONAL JOURNAL OF CONNECTED AND AUTOMATED VEHICLES, 2024, 7 (02):