Draft:ISO/SAE 21434
Review waiting, please be patient.
This may take 5 weeks or more, since drafts are reviewed in no specific order. There are 2,564 pending submissions waiting for review.
Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
Reviewer tools
|
| ISO/SAE 21434 | |
|---|---|
| Road vehicles – Cybersecurity engineering | |
| Status | Published |
| Year started | 2016 |
| First published | August 2021 |
| Latest version | First edition (2021) |
| Organization | International Organization for Standardization (ISO) SAE International |
| Committee | ISO/TC 22/SC 32 and SAE TEVEES18A |
| Related standards | ISO 26262, ISO/PAS 5112, ISO/SAE PAS 8475, ISO 24089 |
| Predecessor | SAE J3061:2016 |
| Domain | Road vehicle cybersecurity |
| Website | iso.org/standard/70918 |
ISO/SAE 21434 Road vehicles – Cybersecurity engineering is an international standard developed jointly by the International Organization for Standardization (ISO) and SAE International that specifies engineering requirements for cybersecurity risk management of electrical and electronic (E/E) systems in road vehicles, including their components and interfaces.[1]: 1 It covers the life cycle of these systems from concept and product development through production, operation and maintenance to decommissioning, and defines a common vocabulary for communicating and managing cybersecurity risk throughout the automotive supply chain.[1]: iv, 1 The first edition was published in August 2021 and superseded the SAE guidebook SAE J3061:2016.[1]: iii
The standard is process-oriented: it specifies objectives, requirements and work products for cybersecurity activities, but does not prescribe specific technologies or solutions.[1]: 1, vi A central element is the threat analysis and risk assessment (TARA), a set of modular methods for identifying threat scenarios and determining the resulting cybersecurity risk.[1]: vi ISO/SAE 21434 is regarded as a means of fulfilling the risk management requirements of UN Regulation No. 155, which makes a cybersecurity management system a condition for vehicle type approval in the European Union and other markets, and it has seen fast adoption throughout the automotive industry.[2][3]
History
[edit]Before ISO/SAE 21434, guidance on vehicle cybersecurity engineering was provided by SAE J3061, Cybersecurity Guidebook for Cyber-Physical Vehicle Systems (2016), and by threat analysis and risk assessment methods developed in research projects and industry, such as EVITA and HEAVENS.[4][2]
Joint work by ISO and SAE on an international standard began in 2016.[5] The standard was prepared by a joint working group of the ISO technical committee ISO/TC 22 (Road vehicles), subcommittee SC 32 (Electrical and electronic components and general system aspects), working group WG 11, together with the SAE Vehicle Cybersecurity Systems Engineering Committee (TEVEES18A).[1]: iii [5] During the same period, the UNECE World Forum for Harmonization of Vehicle Regulations (WP.29) prepared UN Regulation No. 155 on cybersecurity and UN Regulation No. 156 on software updates, which were adopted in June 2020.[6]
The first edition of ISO/SAE 21434 was published in August 2021. According to its foreword, it cancels and supersedes SAE J3061:2016, with a complete rework of contents and structure.[1]: iii
Scope
[edit]ISO/SAE 21434 applies to E/E systems of series-production road vehicles, including their components and interfaces, whose development or modification began after the publication of the standard.[1]: 1 The object of analysis is called an item, a component or set of components that implements functionality at the vehicle level.[1]: 3 Systems outside the vehicle, such as back-end infrastructure, are not covered; the joint working group decided to keep this scope for the second edition and to refer to applicable standards instead.[7]
The standard defines cybersecurity as the condition in which assets are sufficiently protected against threat scenarios to items of road vehicles, their functions and their electrical or electronic components.[1]: 2 An asset is an object that has value or contributes to value; it has one or more cybersecurity properties (for example confidentiality, integrity or availability) whose compromise can lead to damage scenarios.[1]: 1
Structure
[edit]The main body of the standard consists of 15 clauses. Clauses 1 to 3 contain the scope, normative references and definitions, and clause 4 is informative. Clauses 5 to 15 each have their own objectives, provisions and work products.[1]: v–vi
| Clause | Title | Content |
|---|---|---|
| 4 | General considerations | Context and perspective of the approach to road vehicle cybersecurity engineering (informative) |
| 5 | Organizational cybersecurity management | Cybersecurity management and the organization's cybersecurity policies, rules and processes |
| 6 | Project dependent cybersecurity management | Cybersecurity management and activities at project level |
| 7 | Distributed cybersecurity activities | Assignment of responsibilities for cybersecurity activities between customer and supplier |
| 8 | Continual cybersecurity activities | Activities that provide information for ongoing risk assessments; vulnerability management until the end of cybersecurity support |
| 9 | Concept | Determination of cybersecurity risks, cybersecurity goals and cybersecurity requirements for an item |
| 10 | Product development | Definition of cybersecurity specifications; implementation and verification of cybersecurity requirements |
| 11 | Cybersecurity validation | Validation of an item at the vehicle level |
| 12 | Production | Cybersecurity aspects of manufacturing and assembly |
| 13 | Operations and maintenance | Cybersecurity incident response and updates |
| 14 | End of cybersecurity support and decommissioning | Cybersecurity considerations for the end of support and decommissioning |
| 15 | Threat analysis and risk assessment methods | Modular methods to determine the extent of cybersecurity risk |
Each provision has a unique identifier consisting of a two-letter abbreviation – "RQ" for a requirement, "RC" for a recommendation, "PM" for a permission and "WP" for a work product – followed by the clause number and a sequence number; for example, [RQ-05-14] is the 14th provision of clause 5, which is a requirement.[1]: vi A summary of all cybersecurity activities and work products is given in Annex A. Further informative annexes provide, among other things, guidance on cybersecurity assurance levels (Annex E), impact rating (Annex F) and attack feasibility rating (Annex G), as well as an example application of the TARA methods (Annex H).[1]: vi, Annexes A, E–H
At the project level, the standard uses a cybersecurity case, a structured argument supported by evidence that the risks are not unreasonable, and a cybersecurity assessment, a judgement of the cybersecurity of an item or component.[1]: 2
Threat analysis and risk assessment
[edit]Clause 15 describes the threat analysis and risk assessment (TARA) as a set of modular methods that are used at several points in the life cycle, in particular during the concept phase and when new information such as vulnerabilities becomes available.[1]: v–vi [3] The methods and their resulting work products are:[1]: Clause 15
- Asset identification (15.3): damage scenarios and assets with their cybersecurity properties.
- Threat scenario identification (15.4): threat scenarios that can compromise the cybersecurity properties of assets.
- Impact rating (15.5): the adverse consequences of each damage scenario for road users are rated in the categories safety, financial, operational and privacy, on the four levels severe, major, moderate and negligible; organizations may add further categories and stakeholders.
- Attack path analysis (15.6): the sets of deliberate actions (attack paths) by which a threat scenario can be realized.
- Attack feasibility rating (15.7): each attack path is rated high, medium, low or very low. The informative Annex G describes three approaches: an attack potential-based approach adapted from ISO/IEC 18045 that considers elapsed time, specialist expertise, knowledge of the item or component, window of opportunity and equipment; an approach based on the Common Vulnerability Scoring System (CVSS); and an attack vector-based approach suited to early development phases.
- Risk value determination (15.8): the impact and attack feasibility of each threat scenario are combined, for example by a risk matrix, into a risk value from 1 (lowest) to 5.
- Risk treatment decision (15.9): for each threat scenario, one or more of the options avoiding, reducing, sharing or retaining the risk is chosen.
Risks that are to be reduced lead to cybersecurity goals and requirements for the item, while a decision to retain or share a risk is documented in a cybersecurity claim, a statement about the risk that can include the justification for the decision.[1]: 2, Clause 9, Clause 15
The standard does not mandate a particular method for performing these steps. Existing methods such as HEAVENS were revised to conform to it; the updated model HEAVENS 2.0, proposed in 2021, applies 17 changes to the original HEAVENS model to close the gaps to ISO/SAE 21434 and to address other identified weaknesses.[2]
Cybersecurity assurance levels
[edit]The informative Annex E introduces cybersecurity assurance levels (CAL) as a way to scale the rigour of cybersecurity engineering activities. A CAL can be determined for each cybersecurity goal by considering the impact rating and attack vector of the related threat scenarios, and cybersecurity requirements inherit the CAL of their parent goal.[5] The supplementary specification ISO/SAE PAS 8475 elaborates this concept and adds targeted attack feasibility (TAF), which specifies the desired attack feasibility rating after cybersecurity controls have been applied and is intended to facilitate communication between customers and suppliers.[5]
Relationship with regulation
[edit]UN Regulation No. 155, adopted by WP.29 in June 2020, requires vehicle manufacturers to manage vehicle cyber risks, to secure vehicles by design along the value chain, and to detect and respond to security incidents across their vehicle fleets.[6] Manufacturers must operate a cybersecurity management system (CSMS) that is certified as a condition for type approval.[8] In the European Union, protection of vehicles against cyberattacks became a type-approval requirement under Regulation (EU) 2019/2144 for new vehicle types from 6 July 2022 and for the registration of all new vehicles from 7 July 2024.[9][10]
ISO/SAE 21434 is not itself legally binding, but it is widely regarded as a way of implementing the risk management required by UN Regulation No. 155, which was expected to be adopted into national law in 54 countries.[2] A comparative analysis published in 2022 concluded that the two documents, which both span the entire life cycle of a vehicle, overlap in some processes but are also complementary.[11] Other jurisdictions have introduced related requirements; for example, the Chinese national standard GB 44495-2024 on vehicle cybersecurity aligns with UN Regulation No. 155 and ISO/SAE 21434 while adding requirements specific to the Chinese market.[12]
Related standards and documents
[edit]- ISO 26262 (Road vehicles – Functional safety): ISO/SAE 21434 includes a normative reference to ISO 26262 and shows a strong correlation with it in structure and approach.[1]: 1 [13]
- ISO/PAS 5112:2022 (Road vehicles – Guidelines for auditing cybersecurity engineering): supplements the general audit guidelines of ISO 19011 with guidance on auditing a cybersecurity management system whose elements are based on the processes of ISO/SAE 21434.[14]
- ISO/SAE PAS 8475 (Cybersecurity assurance levels and targeted attack feasibility) and ISO/SAE TR 8477 (Cybersecurity verification and validation): supplementary documents developed by the joint working group from 2022 and 2023, respectively, with publication expected in 2026. ISO/SAE TR 8477 provides further guidance because the verification and validation requirements of ISO/SAE 21434 are very high-level.[5]
- ISO 24089:2023 (Road vehicles – Software update engineering): specifies requirements and recommendations for software update engineering for road vehicles at the organizational and project level.[15]
Revision
[edit]Feedback on the first edition was collected from industry in 2024, and the joint working group took decisions on key issues and the scope of a second edition in November 2025. According to a presentation by the chair of the SAE Vehicle Cybersecurity Systems Engineering Committee, the second edition will keep the scope and structure of the first edition, will integrate the content of ISO/SAE TR 8477 while ISO/PAS 5112 remains separate, and may add guidance and examples, for instance on applying the standard with only partial information ("out of context") and on conducting a TARA from different viewpoints in the supply chain. Development was expected to start in 2026 and to take more than three years.[7]
Reception
[edit]Research on the standard has pointed to areas in which it leaves details to the implementing organization. A 2022 review of the standard discussed possible limits of its implementation, including application methods and specific thresholds for security risk analysis.[13] A 2023 gap analysis found that early industry efforts concentrated on the TARA in the concept and development phases, exposing the challenge of managing TARA results coherently throughout the supply chain and life cycle, and that the standard is not explicit about how TARA results are to be updated. The authors also found that vulnerability and incident handling received less attention, and proposed a TARA management process and changes to the vulnerability and incident handling processes to align them with established IT security standards.[3] A 2025 presentation on ISO/SAE PAS 8475 described the standardization of a single definition of how cybersecurity assurance levels scale engineering activities across all tiers of the supply chain as an open challenge.[5]
See also
[edit]References
[edit]- 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 ISO/SAE 21434:2021 – Road vehicles – Cybersecurity engineering (1st ed.). Geneva; Warrendale, PA: International Organization for Standardization; SAE International. August 2021.
- 1 2 3 4 Lautenbach, Aljoscha; Almgren, Magnus; Olovsson, Tomas (2021). Proposing HEAVENS 2.0 – an automotive risk assessment model. Computer Science in Cars Symposium (CSCS '21). Association for Computing Machinery. pp. 1–12. doi:10.1145/3488904.3493378.
- 1 2 3 Grimm, Daniel; Lautenbach, Aljoscha; Almgren, Magnus; Olovsson, Tomas; Sax, Eric (2023). Gap analysis of ISO/SAE 21434 – Improving the automotive cybersecurity engineering life cycle. 2023 IEEE International Conference on Intelligent Transportation Systems (ITSC). IEEE. pp. 1904–1911. doi:10.1109/ITSC57777.2023.10422100.
- ↑ Macher, Georg; Armengaud, Eric; Brenner, Eugen; Kreiner, Christian (2016). "A Review of Threat Analysis and Risk Assessment Methods in the Automotive Context". Computer Safety, Reliability, and Security (SAFECOMP 2016). Lecture Notes in Computer Science. Vol. 9922. Springer. pp. 130–141. doi:10.1007/978-3-319-45477-1_11.
- 1 2 3 4 5 6 Wooderson, Paul (9 December 2025). "Update on ISO/SAE PAS 8475 and TR 8477" (PDF) (Presentation slides). GlobalPlatform. Retrieved 26 September 2026.
- 1 2 "UN Regulations on Cybersecurity and Software Updates to pave the way for mass roll out of connected vehicles" (Press release). United Nations Economic Commission for Europe. 25 June 2020. Retrieved 26 September 2026.
- 1 2 Krzeszewski, John T. (9 December 2025). "Roadmap and development status: 2nd edition of ISO/SAE 21434" (PDF) (Presentation slides). GlobalPlatform. Retrieved 26 September 2026.
- ↑ "UN Regulation No 155 – Uniform provisions concerning the approval of vehicles with regards to cybersecurity and cybersecurity management system [2021/387]". Official Journal of the European Union. 9 March 2021. L 82, pp. 30–59. Retrieved 26 September 2026.
- ↑ "Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users". EUR-Lex. 16 December 2019. Annex II, item D4. Retrieved 26 September 2026.
- ↑ Polly, Sebastian; Borst, Leopold M.; Golling, Manuel (11 January 2022). "New cyber security and software update rules in the automotive industry in 2022". Hogan Lovells. Retrieved 26 September 2026.
- ↑ Costantino, Gianpiero; De Vincenzi, Marco; Matteucci, Ilaria (2022). A Comparative Analysis of UNECE WP.29 R155 and ISO/SAE 21434. 2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE. pp. 340–347. doi:10.1109/EuroSPW55150.2022.00041.
- ↑ Schädlich, Eric (2 September 2024). "China's New Vehicle Cybersecurity Standard: GB 44495-2024". dissecto. Retrieved 26 September 2026.
- 1 2 Costantino, Gianpiero; De Vincenzi, Marco; Matteucci, Ilaria (2022). "In-Depth Exploration of ISO/SAE 21434 and Its Correlations with Existing Standards". IEEE Communications Standards Magazine. 6 (1): 84–92. doi:10.1109/MCOMSTD.0001.2100080.
- ↑ ISO/PAS 5112:2022 – Road vehicles – Guidelines for auditing cybersecurity engineering (1st ed.). Geneva: International Organization for Standardization. March 2022. Clause 1.
- ↑ ISO 24089:2023 – Road vehicles – Software update engineering. Geneva: International Organization for Standardization. 2023. Clause 1.
Further reading
[edit]- Kim, Shiho; Shrestha, Rakesh (2020). Automotive Cyber Security. Singapore: Springer. doi:10.1007/978-981-15-8053-6. ISBN 978-981-15-8052-9.
- Oka, Dennis Kengo (2021). Building Secure Cars: Assuring the Automotive Software Development Lifecycle. Wiley. doi:10.1002/9781119710783. ISBN 978-1-119-71074-5.
- Ward, David; Wooderson, Paul (2021). Automotive Cybersecurity: An Introduction to ISO/SAE 21434. SAE International. doi:10.4271/9781468600810. ISBN 978-1-4686-0081-0.
- Nasser, Ahmad MK (2023). Automotive Cybersecurity Engineering Handbook. Birmingham: Packt Publishing. ISBN 978-1-80107-263-2.
- do Carmo, Rodrigo; Schlensog, Alexander (2024). Automotive Threat Analysis and Risk Assessment in Practice. Berlin, Heidelberg: Springer. doi:10.1007/978-3-662-69614-9. ISBN 978-3-662-69613-2.
External links
[edit]- ISO/SAE 21434:2021 in the ISO catalogue
- ISO/SAE 21434 at SAE International
