NIST Cybersecurity Framework, ISO 27001, SOC 2, and OWASP
While ISO 21434 and ASPICE for Cybersecurity focus on the security processes for vehicle development, organizations must also consider security processes for the cloud and mobile app development related to automotive IoT applications.
Common security frameworks and approaches for such environments include the NIST Cybersecurity Framework, ISO 27001, SOC 2, and OWASP.
NIST Cybersecurity Framework
An overview of the NIST Cybersecurity Framework [3] is shown in Figure 6.6.
Figure 6.6 – Core functions in the NIST Cybersecurity Framework
There are five core functions organizations can follow to better manage their cybersecurity risks: identify, protect, detect, respond, and recover.
Identify
The identify function helps the organization to better understand the organization’s cybersecurity landscape and potential threats. This includes mapping out critical assets, data...