没有合适的资源?快使用搜索试试~ 我知道了~
资源推荐
资源详情
资源评论








© ISO SAE 21434 – All rights reserved
ISOSAE21434:2018(X)1
ISO TC 22/SC 32/WG 11 2
SAE 3
Secretariat: ISO SAE 4
Roadvehicles–Cybersecurityengineering5
6
CD stage 7
8
9
WarningforWDsandCDs10
This document is not an ISO International Standard. It is distributed for review and comment. It is subject to 11
change without notice and may not be referred to as an International Standard. 12
Recipients of this draft are invited to submit, with their comments, notification of any relevant patent rights of 13
which they are aware and to provide supporting documentation. 14
Tohelpyou,thisguideonwritingstandardswasproducedbytheISO/TMBandisavailableat15
https://www.iso.org/iso/how‐to‐write‐standards.pdf16
AmodelmanuscriptofadraftInternationalStandard(knownas“TheRiceModel”)isavailableat17
https://www.iso.org/iso/model_document‐rice_model.pdf18
19

ISOSAE21434:2018(X)
ii © ISO SAE 21434 – All rights reserved
© ISO SAE 2018 20
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this 21
publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, 22
including photocopying, or posting on the internet or an intranet, without prior written permission. Permission 23
can be requested from either ISO at the address below or ISO’s member body in the country of the requester. 24
ISO copyright office 25
CP 401 • Ch. de Blandonnet 8 26
CH-1214 Vernier, Geneva 27
Phone: +41 22 749 01 11 28
Fax: +41 22 749 09 47 29
Email: copyright@iso.org 30
Website: www.iso.org 31
Published in Switzerland 32

ISOSAE21434:2018(X)
© ISO SAE 21434 – All rights reserved iii
Contents33
Foreword.......................................................................................................................................................................vii34
Introduction.................................................................................................................................................................viii35
1 Scope.......................................................................................................................................................................... 136
2 Normativereferences..........................................................................................................................................137
3 Termsandabbreviations....................................................................................................................................138
Termsanddefinitions..........................................................................................................................................1
3.1
39
Abbreviatedterms................................................................................................................................................6
3.2
40
4 Generalconsiderations(informative)...........................................................................................................641
Thevehicleecosystem.........................................................................................................................................6
4.1
42
Organizationaloverviewof cybersecuritymanagement........................................................................8
4.2
43
Lifecycle.....................................................................................................................................................................8
4.3
44
Stagesofthepost‐productionphase...............................................................................................................9
4.4
45
5 ManagementofCybersecurity.......................................................................................................................1046
OverallCybersecurityManagement............................................................................................................10
5.1
47
5.1.1 Objectives........................................................................................................................................................1048
5.1.2 General.............................................................................................................................................................1149
5.1.3 Inputs................................................................................................................................................................1150
5.1.4 Requirementsandrecommendations..................................................................................................1151
5.1.5 Workproducts...............................................................................................................................................1652
Cybersecuritymanagement duringtheconceptphaseandproductdevelopment....................16
5.2
53
5.2.1 Objectives........................................................................................................................................................1654
5.2.2 General.............................................................................................................................................................1655
5.2.3 Inputs................................................................................................................................................................1756
5.2.4 Requirementsandrecommendations..................................................................................................1757
5.2.5 Workproducts...............................................................................................................................................2458
Cybersecuritymanagement duringproduction,operationsandmaintenance...........................24
5.3
59
5.3.1 Objectives........................................................................................................................................................2460
5.3.2 General.............................................................................................................................................................2461
5.3.3 Inputs................................................................................................................................................................2462
5.3.4 Requirementsandrecommendations..................................................................................................2563
InformationCollectionandRetention........................................................................................................26
5.4
64
5.4.1 Objective..........................................................................................................................................................2665
5.4.2 General.............................................................................................................................................................2666
5.4.3 Inputs................................................................................................................................................................2667
5.4.4 Requirementsandrecommendations..................................................................................................2668
6 Riskassessmentmethods................................................................................................................................2769
Riskassessmentmethodsintroduction (informative).........................................................................27
6.1
70
Assetidentification............................................................................................................................................29
6.2
71
6.2.1 Objectives........................................................................................................................................................2972
6.2.2 General.............................................................................................................................................................2973
6.2.3 Inputs................................................................................................................................................................3074
6.2.4 RequirementsandRecommendations.................................................................................................3175
6.2.5 WorkProducts...............................................................................................................................................3176
ThreatAnalysis....................................................................................................................................................32
6.3
77
6.3.1 Objectives........................................................................................................................................................3278
6.3.2 General.............................................................................................................................................................3279
6.3.3 Inputs................................................................................................................................................................3280
6.3.4 Requirementsandrecommendations..................................................................................................3381
6.3.5 Workproducts...............................................................................................................................................3382

ISOSAE21434:2018(X)
iv © ISO SAE 21434 – All rights reserved
ImpactAssessment.............................................................................................................................................33
6.4
83
6.4.1 Objectives........................................................................................................................................................3384
6.4.2 General.............................................................................................................................................................3385
6.4.3 Inputs................................................................................................................................................................3486
6.4.4 RequirementsandRecommendations.................................................................................................3487
6.4.5 Workproducts...............................................................................................................................................3688
Vulnerabilityanalysis.......................................................................................................................................36
6.5
89
6.5.1 Objectives........................................................................................................................................................3690
6.5.2 General.............................................................................................................................................................3691
6.5.3 Inputs................................................................................................................................................................3892
6.5.4 RequirementsandRecommendations.................................................................................................3993
6.5.5 Workproducts...............................................................................................................................................4094
Attackanalysis.....................................................................................................................................................40
6.6
95
6.6.1 Objectives........................................................................................................................................................4096
6.6.2 General.............................................................................................................................................................4097
6.6.3 Inputs................................................................................................................................................................4098
6.6.4 Requirementsandrecommendations..................................................................................................4199
6.6.5 Workproducts...............................................................................................................................................42100
AttackFeasibilityAssessment........................................................................................................................42
6.7
101
6.7.1 Objectives........................................................................................................................................................42102
6.7.2 General.............................................................................................................................................................42103
6.7.3 Inputs................................................................................................................................................................42104
6.7.4 Requirementsandrecommendations..................................................................................................42105
6.7.5 Workproducts...............................................................................................................................................44106
Riskassessment..................................................................................................................................................44
6.8
107
6.8.1 Objectives........................................................................................................................................................44108
6.8.2 General.............................................................................................................................................................44109
6.8.3 Inputs................................................................................................................................................................45110
6.8.4 RequirementsandRecommendations.................................................................................................45111
6.8.5 Workproducts...............................................................................................................................................45112
RiskTreatment....................................................................................................................................................45
6.9
113
6.9.1 Objectives........................................................................................................................................................45114
6.9.2 General.............................................................................................................................................................45115
6.9.3 Inputs................................................................................................................................................................46116
6.9.4 RequirementsandRecommendations.................................................................................................47117
6.9.5 Workproducts...............................................................................................................................................47118
7 ConceptPhase......................................................................................................................................................47119
CybersecurityRelevance..................................................................................................................................47
7.1
120
7.1.1 Objectives........................................................................................................................................................47121
7.1.2 General.............................................................................................................................................................48122
7.1.3 Inputs................................................................................................................................................................48123
7.1.4 RequirementsandRecommendations.................................................................................................48124
7.1.5 Workproducts...............................................................................................................................................48125
ItemDefinition.....................................................................................................................................................48
7.2
126
7.2.1 Objectives........................................................................................................................................................48127
7.2.2 General.............................................................................................................................................................48128
7.2.3 Inputs................................................................................................................................................................49129
7.2.4 RequirementsandRecommendations.................................................................................................49130
7.2.5 Workproducts...............................................................................................................................................50131
Initiationofproductdevelopmentattheconceptphase.....................................................................50
7.3
132
7.3.1 Objectives........................................................................................................................................................50133
7.3.2 General.............................................................................................................................................................50134
7.3.3 Inputs................................................................................................................................................................50135
7.3.4 Requirementsandrecommendations..................................................................................................50136

ISOSAE21434:2018(X)
© ISO SAE 21434 – All rights reserved v
7.3.5 WorkProducts...............................................................................................................................................51137
Cybersecuritygoa ls............................................................................................................................................51
7.4
138
7.4.1 Objectives........................................................................................................................................................51139
7.4.2 General.............................................................................................................................................................51140
7.4.3 Inputs................................................................................................................................................................51141
7.4.4 Requirementsandrecommendations..................................................................................................51142
7.4.5 WorkProducts...............................................................................................................................................53143
Cybersecurityconcept......................................................................................................................................53
7.5
144
7.5.1 Objectives........................................................................................................................................................53145
7.5.2 General.............................................................................................................................................................53146
7.5.3 Inputs................................................................................................................................................................53147
7.5.4 Requirementsandrecommendations..................................................................................................54148
7.5.5 WorkProducts...............................................................................................................................................55149
8 Productdevelopment........................................................................................................................................55150
Systemdevelopmentphase.............................................................................................................................55
8.1
151
8.1.1 Objectives........................................................................................................................................................55152
8.1.2 General.............................................................................................................................................................55153
8.1.3 Inputs................................................................................................................................................................56154
8.1.4 Requirementsandrecommendations..................................................................................................57155
8.1.5 Workproducts...............................................................................................................................................63156
Hardwaredevelopmentphase.......................................................................................................................63
8.2
157
8.2.1 Objectives........................................................................................................................................................63158
8.2.2 General.............................................................................................................................................................64159
8.2.3 Inputs................................................................................................................................................................64160
8.2.4 Requirementsandrecommendations..................................................................................................65161
8.2.5 Workproducts...............................................................................................................................................68162
Softwaredevelopmentphase.........................................................................................................................68
8.3
163
8.3.1 Objectives........................................................................................................................................................68164
8.3.2 General.............................................................................................................................................................69165
8.3.3 Inputs................................................................................................................................................................69166
8.3.4 Requirementsandrecommendations..................................................................................................70167
8.3.5 Workproducts...............................................................................................................................................82168
Verificationandvalidation.............................................................................................................................83
8.4
169
8.4.1 Objective..........................................................................................................................................................83170
8.4.2 General.............................................................................................................................................................83171
8.4.3 Inputs................................................................................................................................................................84172
8.4.4 Requirementsandrecommendations..................................................................................................84173
8.4.5 Workproducts...............................................................................................................................................87174
Releaseforpost‐development.......................................................................................................................87
8.5
175
8.5.1 Objective..........................................................................................................................................................87176
8.5.2 General.............................................................................................................................................................87177
8.5.3 Inputs................................................................................................................................................................88178
8.5.4 Requirementsandrecommendations..................................................................................................88179
8.5.5 Workproducts...............................................................................................................................................89180
9 Production,operationsandmaintenance.................................................................................................89181
Production............................................................................................................................................................. 89
9.1
182
9.1.1 Objectives........................................................................................................................................................89183
9.1.2 General.............................................................................................................................................................89184
9.1.3 Inputs................................................................................................................................................................89185
9.1.4 Requirementsandrecommendations..................................................................................................89186
9.1.5 Workproducts...............................................................................................................................................91187
CybersecurityMonitoring................................................................................................................................91
9.2
188
9.2.1 Objectives........................................................................................................................................................91189
9.2.2 General.............................................................................................................................................................91190
剩余150页未读,继续阅读
资源评论

- coroutines2022-09-23有用,#完美解决问题
- 碎片记录2021-09-11资源很好,150页。
- Dr.罴2021-08-25资源很好,不过建议下载最新的DIS版。
- JohndyWu2021-07-12信息安全标准
- gqb6662021-02-19清晰,汽车信息安全标准规范

yxiaolian
- 粉丝: 5
- 资源: 6
上传资源 快速赚钱
我的内容管理 收起
我的资源 快来上传第一个资源
我的收益
登录查看自己的收益我的积分 登录查看自己的积分
我的C币 登录后查看C币余额
我的收藏
我的下载
下载帮助


会员权益专享
安全验证
文档复制为VIP权益,开通VIP直接复制
