Automotive industries use various standards to achieve the required level of security in vehicles. Widely used standards are ISO 21434 and UNECE R155. ISO 21434 provides a framework for managing cybersecurity risks throughout the entire lifecycle of road vehicles, from design and development to production, operation, maintenance, and decommissioning. UNECE R155 mandates that vehicle manufacturers implement a Cybersecurity Management System (CSMS) to ensure the security of vehicles throughout their lifecycle.
AVIN provides extensive services for development and management of CSMS and support customers in all phases of automotive lifecycle. The various cybersecurity services provided by AVIN are described below:
CSMS establishment Support
-
Development / upgrade various QMS artefacts to meet cybersecurity standards.
-
Gap Analysis between current QMS process and ISO 21434 and perform updates
-
Update QMS in conjunction with other quality and safety standards such as ASPICE and ISO26262.
-
Development of process for ISO21434 specific procedures such as TARA, Cybersecurity Risk Analysis etc.
CSMS Deployment Support
-
Development of Cybersecurity Plan for a specific project.
-
Support in performing Threat Analysis and Risk Assessment (TARA) and deriving Security Goals for various applications in adherence to ISO 21434.
-
Evaluation of various threat scenarios and attack paths applicable for an item.
-
Identify Cybersecurity Protection features to be implemented.
-
Incorporate such features in Requirements or Design as appropriate.
-
Development of Cybersecurity Case.
-
Support for Cybersecurity Assessment.
Cybersecurity Implementation Support
-
Configuration and Integration of AUTOSAR Classic Platform Crypto Stack, Key Manager and HSM Drivers according to Security features required by the System.
-
Development of HSM Drivers.
-
Development, Configuration and Integration of Crypto Functional Cluster in AUTOSAR Adaptive Platform.
-
Intrusion Detection System development according to standards / OEM needs. (IDSM & IDS).
-
Secured Bootloader Development with Crypto Stack and HSM Integration.
Cybersecurity Testing
AVIN provides Cybersecurity Testing services as part of product development or as independent services as below:
-
Functional Testing
-
Vulnerability Scanning
-
Penetration Testing
-
Fuzz Testing.
Cybersecurity Monitoring Services
AVIN provides the below Cybersecurity Monitoring services for OEMs and Tier1s after the vehicles are released to market:
-
Support in performing Cybersecurity Monitoring.
-
Vulnerability Analysis and Vulnerability Management.
-
Cybersecurity Incident Response.
-
Remedial Actions and plan for Software Updates.
-
Coordination of Software Updates.