没有合适的资源?快使用搜索试试~ 我知道了~
首页ISO SAE 21434.DIS 2020.02.12.pdf
ISO SAE 21434.DIS 2020.02.12.pdf
需积分: 50 776 浏览量
更新于2023-05-23
评论 1
收藏 16.21MB PDF 举报
ISO 21434扫描OCR文字版。 This document specifies requirements for cybersecurity risk management regarding engineering for concept, development, production, operation, maintenance, and decommissioning for road vehicle electrical and electronic (E/E) systems, including their components and interfaces.
资源详情
资源评论
资源推荐

cannot
be
utilized
for
any
conformance
or
compliance
purposes
.
SURFACE VEHICLE
ISO/SAE DIS 21434
INTERNATIONAL
STANDARD
Issued 2020-02-12
Road
Vehicles
-
Cybersecurity
Engineering
FOREWORD
ISO (the International Organization for Standardization) is a worldwide federation
of
national standards bodies (ISO
member bodies). The work
of
preparing International Standards is
no
rmally carried out through ISO technical
committees. Each member body interested
in
a subject for which a technical committee has been established has the
right
to
be represented on that committee. International organizations, governmental and non-governmental, in liaison
with ISO, also take part in the work. ISO collaborates closely with the International Electrotechnical Commission (IEC)
on all matters of electrotechnical standardization.
SAE International
is
a global association of more than 128,000 engineers and related technical experts in the aerospace,
automotive and commercial-vehicle industries. Standards from SAE International are used to advance mobility
engineering throughout the world. The SAE Technical Standards Development Program is among the organization's
primary provisions
to
those mobility industries
it
serves aerospace, automotive, and commercial vehicle. These works
are authorized, revised, and maintained
by
the volunteer efforts
of
more than 9,000 engineers, and other qualified
professionals from around the world. SAE subject matter experts act as individuals in the standards process, not as
representatives
of
their organizations. Thus, SAE standards represent optimal technical content developed in a
transparent, open, and collaborative process.
The procedures used to develop this document and those intended for its further maintenance are described in the
ISO/IEC Directives, Part 1 and the SAE Technical Standards Board Policy. In particular, the different approval criteria
needed for the different types
of
ISO documents should be noted. This document was drafted in accordance with the
editorial rules
of
the ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Attention is drawn to the possibility that some
of
the elements
of
this document may be the subject
of
patent rights. ISO
and SAE International shall not be held responsible for identifying any
or
all such patent rights. Details
of
any patent
rights identified during the development
of
the document will be in the Introduction and/or on the ISO list of patent
declarations received (see www.iso.org/patents
).
SAE Technical Standards Board Rules provide that: "This document is published to advance the state
of
technical and
engineering sciences. The use of this document is entirely voluntary, and its applicability and suitability for any particular
use, including any patent infringement arising
th
erefrom,
is
the sole responsibility
of
the user."
Any trade name used
in
this document is information given for the convenience of users and does not constitute an
endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions related
to
conformity assessment, as well as information about ISO's adherence
to
the World Trade Organization (WTO)
pr
inciples
in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
©
ISO
/SAE International 2020
All rights reseived. Unless otherwise specified,
or
required
in
the context of its Implementation, no part of this publication may be reproduced;
or
utilized otherwise in any form
or
by
any means, electronic
or
mechanical, including photocopying,
or
posting
on
the
in
ternet
or
an intranel, without
prior written permission. Permission can
be
requested from either
ISO
or
SAE
International
al
the respective address below
or
ISO's member body
in the country of the requester.
ISO
copyright office
CP
401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone:
+41
22
749
01
11
Fax: +
41
22 749 09
47
Email: oopyright@iso.org
Website:
www
.iso.org
Published in Switzerland and USA.
SAE
International
Tel
': 877-606-7323 (inside USA and Canada)
Tel
:
+1
724-776-4970 (outside USA)
Fax: 724-776-0790
Email: CustomerSeivice@sae.org
SAE
WEB ADDRESS: http
:/
/www.sae.org

ISO/SAE INTERNATIONAL ISO/SAE DIS 21434 Page 2
of
108
This document was jointly prepared
in
the ISO/SAE Cybersecurity Engineering Joint Working Group, with experts from
ISO Technical Committee 22 Road Vehicles, Subcommittee
32
Electrical and electronic components and general
system aspects and SAE Vehicle Cybersecurity Systems Engineering Committee.
This first edition cancels and supersedes the SAE J3061_201601 .
A list of all parts in the ISO/SAE 21434 series
can
be
found
on
the ISO and SAE websites.
Any
feedback
or
questions on this document should be directed to the user's national standards body. A complete listing
of these bodies
can
be found at www.iso.org/members.html. Alternatively, to provide feedback on this document, please
visit https://www .sae.orq/standards/contenVISO/SAE21434. D1.

ISO/SAE INTERNATIONAL ISO/SAE DIS 21434 Page 3
of
108
INTRODUCTION
Pu
rpose
of
this Document
This document addresses the cybersecurity perspective in engineering of electrical and electronic (E/E) systems within
road vehicles. By ensuring appropriate consideration
of
cybersecurity, this document aims to enable the engineering
of
E/E systems to keep up with changing technology and attack methods.
This document provides vocabulary, objectives, requirements and guidelines
as
a foundation for common understanding
throughout the supply chain. This enables organizations to:
- define cybersecurity policies and processes;
- manage cybersecurity risk; and
- foster a cybersecurity culture.
This document can be used to implement a cybersecurity management system including cybersecurity risk management
in accordance with ISO 31000. This document
is
intended to supersede SAE J3061 recommended practice.
Organization
of
this Document
An overview
of
the document structure is given in Figure 1.
The
elements
of
Figure 1 do not prescribe
an
execution
sequence of the individual topics.

I
SO
/SAE INTERNATIONAL ISO/SAE DIS 21434 Page 4
of
108
1
.Sc
ope
2. No
nn
a
ti
ve
refere
n
ces
3.
Terms
and
a
bb
reviations
4.
Ge
n
era
l
considerations
5.
Overall
cyb
ersecurity
man
agement
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6 5.4.7 5.4.8
Cybersecurity
Cybersecurity
Cybersecurity
Organizational
Information Management Tool Information
governance
culture
risk
cybersecurity
sharing
systems management
security
management
aud
it
management
6.
Pr
oj
ect
depen
de
nt cybersecurlty
ma
n
age
me
nt
6.4.1
6.4.2
6.4
.3
□
6.4.5 6.4.6 6.4.7 6.4.8 6.4.9
Cybersecurlty
Cybersecurity
Tailoring
of
Component
Off-the-shelf
Cybersecurity Cybersecurlty Release
fo
r
responsibili·
planning
the
cyber•
out
of
context component case asses
sme
nt
post-
ties & their security
e
development
assignment activities
7.
Continuo
us cybersec:urlty activities
7.3 7.4 7.5
7.6
Cybersecurity Cybersecurity Vulnerability Vulnerability
monitoring event
analysis
management
assessment
8.
RJs
k
assessment
meth
ods
8.3 8.4
8.5
8.6 8.1 8.8 8.9
Asset
Threat
Impact Attack Attack Risk Risk
ldentlncation scenario rating
path
analysis feasibility determination
treatment
ldentlflcadon rating decision
Co
n
ce
pt phase Produ
ct
d
eve
lopm
ent
p
hases
P
ost
-d
eve
lopment p
hases
9.
Co
n
ce
pt ph
ase
10.
Produ
ct
de
vel
op
m
ent
11.
Cy
bersecurity
I
12.Prod
uctlon
I
validation
I
9.3
I
10.4.1
13.
Operatio
ns an d m
aintenance
Item definition
Refinement
of
cybersecurlty
requirements
and
architectural design
13.3 13.4
I
Cyber- Updates
9.4
I I
10.4.2
I
security
Cybersecurity goals Integration
and
verification
incident
r
esponse
9.5
10.4.3
Cybersecurity concept
spec1nc requirements for
software development
I
1
4.
Deco
mm
issio
nin
g
I
1S.
Distribu
ted
cybersecurlty
activities
15.4.1
15
.4.2 15.4.3
Demonstration
Request for Alignment
of
and
evaluation
of
quotation responsibilities
supplier capability
Annexes A·J
(In
f
ormative)
Figure 1 - Overview
of
this document
Clauses 5 and 6 (Management of Cybersecurity) include the implementation
of
the organizational cybersecurity policy,
rules, and processes
fo
r overall cybersecurity management and for project dependent cybersecurity management.
Clause 7 (Continuous Cybersecurity Activities) defines activit
ies
that provide information
for
ongoing risk assessments
and vulnerability management
of
E/E systems until end of support.
Clause 8 (Risk Assessment Methods)
def
ines methods to determine the extent of cybersecurity risk.

ISO
/SA
E INTERNATIONAL ISO/SAE DIS 21434 Page 5
of
108
Clause 9 (Concept Phase) defines an item and the relevant assets, provides cybersecurity risk determination, and
defines the cybersecurity goals.
Clause 1 O (Product Development) defines the cybersecurity specification, implements and verifies cybersecurity
requirements specific
to
an item or component.
Clause
11
(Cybersecurity Validation) describes the cybersecurity validation of an item at the vehicle level.
Clause
12
(Production) specifies the cybersecurity related aspects
of
fabrication, assembly and/or calibration of an item
or
component.
Clause 13 (Operations and Maintenance) specifies activities related to cybersecurity incident response and updates to
an item
or
component.
Clause 14 (Decommissioning) includes cybersecurity considerations that relate
to
the decommissioning of an item
or
component.
Clause 15 (Distributed Act
iv
ities) includes requirements for supplier management.
剩余107页未读,继续阅读












安全验证
文档复制为VIP权益,开通VIP直接复制

评论0