SAE規格 J3061, 2021: Cybersecurity Guidebook for Cyber-Physical Vehicle Systems

SAE規格 J3061, 2021

産業規格・仕様書  >  SAE  > 




SAE規格 J3061, 2021

42,020(税込)

数量

書名

SAE J3061, 2021: Cybersecurity Guidebook for Cyber-Physical Vehicle Systems
SAE規格 J3061, 2021: サイバーフィジカル車両システムのためのサイバーセキュリティガイドブック
発行元 SAE International
発行年/月 2021年12月   
装丁 ペーパー
ページ数 129 ページ
発送予定 海外倉庫よりお取り寄せ 2週間以内に発送します
※PDF版(シングルユーザー版)をご希望のお客様は別途お問合せ下さいませ。
※当ウェブ・ショップに掲載のない規格につきましては、別途お問合せ下さいませ。
※掲載の規格は、当ウェブ・ショップに掲載時点で確認できた最新版でございます。 最新の発行状況につきましては受注時に改めて確認をさせて頂きますので予めご了承下さい。


 

 

Description

This recommended practice provides guidance on vehicle Cybersecurity and was created based off of, and expanded on from, existing practices which are being implemented or reported in industry, government and conference papers. The best practices are intended to be flexible, pragmatic, and adaptable in their further application to the vehicle industry as well as to other cyber-physical vehicle systems (e.g., commercial and military vehicles, trucks, busses). Other proprietary Cybersecurity development processes and standards may have been established to support a specific manufacturer’s development processes, and may not be comprehensively represented in this document, however, information contained in this document may help refine existing in-house processes, methods, etc.

This recommended practice establishes a set of high-level guiding principles for Cybersecurity as it relates to cyber-physical vehicle systems. This includes:

• Defining a complete lifecycle process framework that can be tailored and utilized within each organization’s development processes to incorporate Cybersecurity into cyber-physical vehicle systems from concept phase through production, operation, service, and decommissioning.

• Providing information on some common existing tools and methods used when designing, verifying and validating cyber-physical vehicle systems.
• Providing basic guiding principles on Cybersecurity for vehicle systems.
• Providing the foundation for further standards development activities in vehicle Cybersecurity.

The appendices provide additional information to be aware of and may be used in helping improve Cybersecurity of feature designs. Much of the information identified in the appendices is available but some experts may not be aware of all of the available information. Therefore, the appendices provide an overview of some of this information to provide further guidance on building Cybersecurity into cyber-physical vehicle systems. The objective of the overviews is to encourage research to help improve designs and identify methods and tools for applying a company’s internal Cybersecurity process.

Appendices A-C - Describe some techniques for Threat Analysis and Risk Assessment, Threat Modeling and Vulnerability Analysis (e.g., Attack Trees) and when to use them.
Appendices D-I - Provide awareness of information that is available to the Vehicle Industry.
Appendix D - Provides an overview of sample Cybersecurity and privacy controls derived from NIST SP 800-53 that may be considered in design phases.
Appendix E - Provides references to some available vulnerability databases and vulnerability classification schemes.
Appendix F - Describes vehicle-level considerations, including some good design practices for electrical architecture.
Appendix G -Lists current Cybersecurity standards and guidelines of potential interest to the vehicle industry.
Appendix H - Provides an overview of vehicle Cybersecurity-related research projects starting from 2004.
Appendix I - Describes some existing security test tools of potential interest to the vehicle industry.

Refer to the definitions section to understand the terminology used throughout the document.

Purpose
Just as with system safety, Cybersecurity should be built in to the design rather than added on at the end of development. Building Cybersecurity into the design requires an appropriate lifecycle process from the concept phase through production, operation, service, and decommissioning. This document provides a complete lifecycle process framework that may be tailored to a company-specific process. The process framework described in this document is analogous to the process framework described in ISO 26262 Functional Safety Road Vehicles (1). These two processes are different, but are related and require integrated communications in order to maintain consistency and completeness between an organizations safety process outputs and their Cybersecurity process outputs. An organization is free to maintain separate processes with appropriate levels of interaction between the two processes, or to attempt to directly integrate the two processes. The Cybersecurity process framework described in this document can be tailored to either application (integrated or separate) by individual organizations.