ISO/SAE 21434 and ASPICE for Cybersecurity
To achieve a certain level of security assurance for automotive IoT products, it is imperative for automotive organizations to follow a standardized and rigorous development process.
In this section, we will review two standardized development processes, namely ISO/SAE 21434 [1]and ASPICE for Cybersecurity [2], and focus on the cybersecurity requirements.
ISO/SAE 21434 Overview
ISO/SAE 21434 was released in 2021 and gives a comprehensive set of cybersecurity engineering requirements for the development of automotive systems. The standard contains 15 clauses providing both organizational-level and project-level requirements. The first four clauses are more general in nature, defining the scope, normative references and terms, definitions and abbreviated terms, and general considerations, and therefore omitted from further discussion in this book.
An overview of the remaining clauses 5 through 15 is depicted in Figure 6.4.
...