Managing dependencies in automotive cybersecurity through assumptions, cybersecurity claims and modular cybersecurity cases

  • The development of the electrical system in vehicles, in accordance with current guidelines and standards, involves the division of the vehicle into discrete subparts, referred to as "items." The concept of items has been made mandatory by the recently introduced automotive-specific standard, ISO/SAE 21434. This concept has been inherited from the more established functional safety standard, ISO 26262. An item is defined as a component or a set of components that perform a specific function at the vehicle level. This approach enables the representation of cybersecurity risks with fine granularity. However, this approach is not without its challenges. In practice, each item is dependent on other items for protection against cybersecurity threats. If these dependencies are not effectively managed, the value of the item-based and risk-driven approach may be undermined. ISO/SAE 21434 provides basic constructs, such as assumptions, cybersecurity claims, and cybersecurity cases, to manage these dependencies. However, the standard does not provide sufficient guidance on how to use these constructs effectively. This paper presents an approach that utilises assumptions, cybersecurity claims, and modular cybersecurity cases to manage the interdependencies between items, thereby providing an efficient means of managing cybersecurity risks over time.

Download full text files

Export metadata

Additional Services

Share in Twitter Search Google Scholar
Metadaten
Author:Jonas BorgORCiDGND, Alexander ÅströmORCiDGND
URN:urn:nbn:de:hbz:294-103906
DOI:https://doi.org/10.13154/294-10390
Parent Title (German):21th escar Europe : The World's Leading Automotive Cyber Security Conference (Hamburg, 15. - 16.11.2023)
Document Type:Part of a Book
Language:English
Date of Publication (online):2023/10/25
Date of first Publication:2023/10/25
Publishing Institution:Ruhr-Universität Bochum, Universitätsbibliothek
Tag:Assurance cases; Cybersecurity; Cybersecurity claims; ISO/SAE 21434
Pagenumber:15
Dewey Decimal Classification:Allgemeines, Informatik, Informationswissenschaft / Informatik
open_access (DINI-Set):open_access
Konferenz-/Sammelbände:21th escar Europe : The World's Leading Automotive Cyber Security Conference
Licence (German):License LogoKeine Creative Commons Lizenz - es gelten die Rechteeinräumung und das deutsche Urheberrecht