Project inventory
An organization can create and maintain a project inventory as part of the development process to better understand its security posture and manage the overall security activities for the different projects. The project inventory helps the organization provide a clear and structured way of knowing what type of projects they are developing and maintaining, the respective risk levels, and relevant security activities to perform.
Project information and risk level
First, to get started with a project inventory, some general information about each project is collected. Figure 7.5 shows an overview of an example project inventory.
Project name is the project name of the automotive IoT application. Exposure represents how accessible the automotive IoT application is. This can be divided into five categories and defined as shown in Table 7.1.
Level |
Network Accessibility |
... |