Managing Potential Conflicts Between Vehicle Safety and Cybersecurity
Andy Davis, Transport Cybersecurity Practice Director
Managing Potential Conflicts Between Vehicle Safety and - - PowerPoint PPT Presentation
Managing Potential Conflicts Between Vehicle Safety and Cybersecurity Andy Davis, Transport Cybersecurity Practice Director Agenda What do we mean by Safety - critical and Cybersecurity - critical? Potential conflict areas
Andy Davis, Transport Cybersecurity Practice Director
Safety and Cybersecurity
Potential conflicts
Images: motoringexposure.com, mazdahandsfree.com, engadget.com
Images: youtube.com
Images: youtube.com, naimark.net
Image: deusm.com
Striking the right balance between Safety and Cybersecurity
potential conflict areas
from day one (Secure Development Lifecycle) – bolt-on solutions are never as effective and often very costly
that vulnerabilities haven’t been introduced during development or integration,
SAE J3061 ISO 26262 MISRA C CERT C NIST FIPS 199 TVRA EVITA HEAVENS (cyber-physical focused) (safety focused) (functional safety focused) ISO 12207 ISO 27001 (information security management) (systems and software engineering) (software architecture design threats) (security focused) (risk assessment – telecomms network focussed) (risk assessment – aligned with ISO 26262) (risk assessment – designed By US DoD for healthcare security) STRIDE (threat modelling) Auto Alliance
Consumer Privacy Protection Principles
OCTAVE (risk assessment - electrical systems focused) NIST FIPS 140-2 (Security requirements for cryptographic modules) (privacy focused)
Europe
North America
Canada
0161 209 5200 AutomotiveSecurity@nccgroup.trust www.nccgroup.trust
Australia