RASIC, vendor security assessments, and CIADs
Different approaches can help with improving security in the software supply chain. First, it is crucial for the organization to define roles and responsibilities for the different cybersecurity activities during development and operations. One general approach that can be taken is establishing a responsible, accountable, support, inform, and consult (RASIC) chart.
Moreover, organizations in the automotive industry typically work with a multitude of suppliers. To improve security in the supply chain, it is imperative that organizations follow a systemic approach to evaluating the cybersecurity capabilities and cybersecurity posture of different suppliers. One such approach is to perform a vendor security assessment and use that information as one factor when selecting a vendor.
Furthermore, already common in the automotive industry is to define a development interface agreement (DIA) between the procurer and the supplier. The DIA...