Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a448d6c24bc0fa14

Jump to content

Draft:ISO/SAE 21434

From Wikipedia, the free encyclopedia

ISO/SAE 21434
Road vehicles – Cybersecurity engineering
StatusPublished
Year started2016
First publishedAugust 2021
Latest versionFirst edition (2021)
OrganizationInternational Organization for Standardization (ISO)
SAE International
CommitteeISO/TC 22/SC 32 and SAE TEVEES18A
Related standardsISO 26262, ISO/PAS 5112, ISO/SAE PAS 8475, ISO 24089
PredecessorSAE J3061:2016
DomainRoad vehicle cybersecurity
Websiteiso.org/standard/70918

ISO/SAE 21434 Road vehicles – Cybersecurity engineering is an international standard developed jointly by the International Organization for Standardization (ISO) and SAE International that specifies engineering requirements for cybersecurity risk management of electrical and electronic (E/E) systems in road vehicles, including their components and interfaces.[1]: 1  It covers the life cycle of these systems from concept and product development through production, operation and maintenance to decommissioning, and defines a common vocabulary for communicating and managing cybersecurity risk throughout the automotive supply chain.[1]: iv, 1  The first edition was published in August 2021 and superseded the SAE guidebook SAE J3061:2016.[1]: iii 

The standard is process-oriented: it specifies objectives, requirements and work products for cybersecurity activities, but does not prescribe specific technologies or solutions.[1]: 1, vi  A central element is the threat analysis and risk assessment (TARA), a set of modular methods for identifying threat scenarios and determining the resulting cybersecurity risk.[1]: vi  ISO/SAE 21434 is regarded as a means of fulfilling the risk management requirements of UN Regulation No. 155, which makes a cybersecurity management system a condition for vehicle type approval in the European Union and other markets, and it has seen fast adoption throughout the automotive industry.[2][3]

History

[edit]

Before ISO/SAE 21434, guidance on vehicle cybersecurity engineering was provided by SAE J3061, Cybersecurity Guidebook for Cyber-Physical Vehicle Systems (2016), and by threat analysis and risk assessment methods developed in research projects and industry, such as EVITA and HEAVENS.[4][2]

Joint work by ISO and SAE on an international standard began in 2016.[5] The standard was prepared by a joint working group of the ISO technical committee ISO/TC 22 (Road vehicles), subcommittee SC 32 (Electrical and electronic components and general system aspects), working group WG 11, together with the SAE Vehicle Cybersecurity Systems Engineering Committee (TEVEES18A).[1]: iii [5] During the same period, the UNECE World Forum for Harmonization of Vehicle Regulations (WP.29) prepared UN Regulation No. 155 on cybersecurity and UN Regulation No. 156 on software updates, which were adopted in June 2020.[6]

The first edition of ISO/SAE 21434 was published in August 2021. According to its foreword, it cancels and supersedes SAE J3061:2016, with a complete rework of contents and structure.[1]: iii 

Scope

[edit]

ISO/SAE 21434 applies to E/E systems of series-production road vehicles, including their components and interfaces, whose development or modification began after the publication of the standard.[1]: 1  The object of analysis is called an item, a component or set of components that implements functionality at the vehicle level.[1]: 3  Systems outside the vehicle, such as back-end infrastructure, are not covered; the joint working group decided to keep this scope for the second edition and to refer to applicable standards instead.[7]

The standard defines cybersecurity as the condition in which assets are sufficiently protected against threat scenarios to items of road vehicles, their functions and their electrical or electronic components.[1]: 2  An asset is an object that has value or contributes to value; it has one or more cybersecurity properties (for example confidentiality, integrity or availability) whose compromise can lead to damage scenarios.[1]: 1 

Structure

[edit]

The main body of the standard consists of 15 clauses. Clauses 1 to 3 contain the scope, normative references and definitions, and clause 4 is informative. Clauses 5 to 15 each have their own objectives, provisions and work products.[1]: v–vi 

Clauses 4–15 of ISO/SAE 21434:2021[1]: v–vi 
ClauseTitleContent
4General considerationsContext and perspective of the approach to road vehicle cybersecurity engineering (informative)
5Organizational cybersecurity managementCybersecurity management and the organization's cybersecurity policies, rules and processes
6Project dependent cybersecurity managementCybersecurity management and activities at project level
7Distributed cybersecurity activitiesAssignment of responsibilities for cybersecurity activities between customer and supplier
8Continual cybersecurity activitiesActivities that provide information for ongoing risk assessments; vulnerability management until the end of cybersecurity support
9ConceptDetermination of cybersecurity risks, cybersecurity goals and cybersecurity requirements for an item
10Product developmentDefinition of cybersecurity specifications; implementation and verification of cybersecurity requirements
11Cybersecurity validationValidation of an item at the vehicle level
12ProductionCybersecurity aspects of manufacturing and assembly
13Operations and maintenanceCybersecurity incident response and updates
14End of cybersecurity support and decommissioningCybersecurity considerations for the end of support and decommissioning
15Threat analysis and risk assessment methodsModular methods to determine the extent of cybersecurity risk

Each provision has a unique identifier consisting of a two-letter abbreviation – "RQ" for a requirement, "RC" for a recommendation, "PM" for a permission and "WP" for a work product – followed by the clause number and a sequence number; for example, [RQ-05-14] is the 14th provision of clause 5, which is a requirement.[1]: vi  A summary of all cybersecurity activities and work products is given in Annex A. Further informative annexes provide, among other things, guidance on cybersecurity assurance levels (Annex E), impact rating (Annex F) and attack feasibility rating (Annex G), as well as an example application of the TARA methods (Annex H).[1]: vi, Annexes A, E–H 

At the project level, the standard uses a cybersecurity case, a structured argument supported by evidence that the risks are not unreasonable, and a cybersecurity assessment, a judgement of the cybersecurity of an item or component.[1]: 2 

Threat analysis and risk assessment

[edit]

Clause 15 describes the threat analysis and risk assessment (TARA) as a set of modular methods that are used at several points in the life cycle, in particular during the concept phase and when new information such as vulnerabilities becomes available.[1]: v–vi [3] The methods and their resulting work products are:[1]: Clause 15 

  • Asset identification (15.3): damage scenarios and assets with their cybersecurity properties.
  • Threat scenario identification (15.4): threat scenarios that can compromise the cybersecurity properties of assets.
  • Impact rating (15.5): the adverse consequences of each damage scenario for road users are rated in the categories safety, financial, operational and privacy, on the four levels severe, major, moderate and negligible; organizations may add further categories and stakeholders.
  • Attack path analysis (15.6): the sets of deliberate actions (attack paths) by which a threat scenario can be realized.
  • Attack feasibility rating (15.7): each attack path is rated high, medium, low or very low. The informative Annex G describes three approaches: an attack potential-based approach adapted from ISO/IEC 18045 that considers elapsed time, specialist expertise, knowledge of the item or component, window of opportunity and equipment; an approach based on the Common Vulnerability Scoring System (CVSS); and an attack vector-based approach suited to early development phases.
  • Risk value determination (15.8): the impact and attack feasibility of each threat scenario are combined, for example by a risk matrix, into a risk value from 1 (lowest) to 5.
  • Risk treatment decision (15.9): for each threat scenario, one or more of the options avoiding, reducing, sharing or retaining the risk is chosen.

Risks that are to be reduced lead to cybersecurity goals and requirements for the item, while a decision to retain or share a risk is documented in a cybersecurity claim, a statement about the risk that can include the justification for the decision.[1]: 2, Clause 9, Clause 15 

The standard does not mandate a particular method for performing these steps. Existing methods such as HEAVENS were revised to conform to it; the updated model HEAVENS 2.0, proposed in 2021, applies 17 changes to the original HEAVENS model to close the gaps to ISO/SAE 21434 and to address other identified weaknesses.[2]

Cybersecurity assurance levels

[edit]

The informative Annex E introduces cybersecurity assurance levels (CAL) as a way to scale the rigour of cybersecurity engineering activities. A CAL can be determined for each cybersecurity goal by considering the impact rating and attack vector of the related threat scenarios, and cybersecurity requirements inherit the CAL of their parent goal.[5] The supplementary specification ISO/SAE PAS 8475 elaborates this concept and adds targeted attack feasibility (TAF), which specifies the desired attack feasibility rating after cybersecurity controls have been applied and is intended to facilitate communication between customers and suppliers.[5]

Relationship with regulation

[edit]

UN Regulation No. 155, adopted by WP.29 in June 2020, requires vehicle manufacturers to manage vehicle cyber risks, to secure vehicles by design along the value chain, and to detect and respond to security incidents across their vehicle fleets.[6] Manufacturers must operate a cybersecurity management system (CSMS) that is certified as a condition for type approval.[8] In the European Union, protection of vehicles against cyberattacks became a type-approval requirement under Regulation (EU) 2019/2144 for new vehicle types from 6 July 2022 and for the registration of all new vehicles from 7 July 2024.[9][10]

ISO/SAE 21434 is not itself legally binding, but it is widely regarded as a way of implementing the risk management required by UN Regulation No. 155, which was expected to be adopted into national law in 54 countries.[2] A comparative analysis published in 2022 concluded that the two documents, which both span the entire life cycle of a vehicle, overlap in some processes but are also complementary.[11] Other jurisdictions have introduced related requirements; for example, the Chinese national standard GB 44495-2024 on vehicle cybersecurity aligns with UN Regulation No. 155 and ISO/SAE 21434 while adding requirements specific to the Chinese market.[12]

[edit]
  • ISO 26262 (Road vehicles – Functional safety): ISO/SAE 21434 includes a normative reference to ISO 26262 and shows a strong correlation with it in structure and approach.[1]: 1 [13]
  • ISO/PAS 5112:2022 (Road vehicles – Guidelines for auditing cybersecurity engineering): supplements the general audit guidelines of ISO 19011 with guidance on auditing a cybersecurity management system whose elements are based on the processes of ISO/SAE 21434.[14]
  • ISO/SAE PAS 8475 (Cybersecurity assurance levels and targeted attack feasibility) and ISO/SAE TR 8477 (Cybersecurity verification and validation): supplementary documents developed by the joint working group from 2022 and 2023, respectively, with publication expected in 2026. ISO/SAE TR 8477 provides further guidance because the verification and validation requirements of ISO/SAE 21434 are very high-level.[5]
  • ISO 24089:2023 (Road vehicles – Software update engineering): specifies requirements and recommendations for software update engineering for road vehicles at the organizational and project level.[15]

Revision

[edit]

Feedback on the first edition was collected from industry in 2024, and the joint working group took decisions on key issues and the scope of a second edition in November 2025. According to a presentation by the chair of the SAE Vehicle Cybersecurity Systems Engineering Committee, the second edition will keep the scope and structure of the first edition, will integrate the content of ISO/SAE TR 8477 while ISO/PAS 5112 remains separate, and may add guidance and examples, for instance on applying the standard with only partial information ("out of context") and on conducting a TARA from different viewpoints in the supply chain. Development was expected to start in 2026 and to take more than three years.[7]

Reception

[edit]

Research on the standard has pointed to areas in which it leaves details to the implementing organization. A 2022 review of the standard discussed possible limits of its implementation, including application methods and specific thresholds for security risk analysis.[13] A 2023 gap analysis found that early industry efforts concentrated on the TARA in the concept and development phases, exposing the challenge of managing TARA results coherently throughout the supply chain and life cycle, and that the standard is not explicit about how TARA results are to be updated. The authors also found that vulnerability and incident handling received less attention, and proposed a TARA management process and changes to the vulnerability and incident handling processes to align them with established IT security standards.[3] A 2025 presentation on ISO/SAE PAS 8475 described the standardization of a single definition of how cybersecurity assurance levels scale engineering activities across all tiers of the supply chain as an open challenge.[5]

See also

[edit]

References

[edit]
  1. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 ISO/SAE 21434:2021 – Road vehicles – Cybersecurity engineering (1st ed.). Geneva; Warrendale, PA: International Organization for Standardization; SAE International. August 2021.
  2. 1 2 3 4 Lautenbach, Aljoscha; Almgren, Magnus; Olovsson, Tomas (2021). Proposing HEAVENS 2.0 – an automotive risk assessment model. Computer Science in Cars Symposium (CSCS '21). Association for Computing Machinery. pp. 1–12. doi:10.1145/3488904.3493378.
  3. 1 2 3 Grimm, Daniel; Lautenbach, Aljoscha; Almgren, Magnus; Olovsson, Tomas; Sax, Eric (2023). Gap analysis of ISO/SAE 21434 – Improving the automotive cybersecurity engineering life cycle. 2023 IEEE International Conference on Intelligent Transportation Systems (ITSC). IEEE. pp. 1904–1911. doi:10.1109/ITSC57777.2023.10422100.
  4. ↑ Macher, Georg; Armengaud, Eric; Brenner, Eugen; Kreiner, Christian (2016). "A Review of Threat Analysis and Risk Assessment Methods in the Automotive Context". Computer Safety, Reliability, and Security (SAFECOMP 2016). Lecture Notes in Computer Science. Vol. 9922. Springer. pp. 130–141. doi:10.1007/978-3-319-45477-1_11.
  5. 1 2 3 4 5 6 Wooderson, Paul (9 December 2025). "Update on ISO/SAE PAS 8475 and TR 8477" (PDF) (Presentation slides). GlobalPlatform. Retrieved 26 September 2026.
  6. 1 2 "UN Regulations on Cybersecurity and Software Updates to pave the way for mass roll out of connected vehicles" (Press release). United Nations Economic Commission for Europe. 25 June 2020. Retrieved 26 September 2026.
  7. 1 2 Krzeszewski, John T. (9 December 2025). "Roadmap and development status: 2nd edition of ISO/SAE 21434" (PDF) (Presentation slides). GlobalPlatform. Retrieved 26 September 2026.
  8. ↑ "UN Regulation No 155 – Uniform provisions concerning the approval of vehicles with regards to cybersecurity and cybersecurity management system [2021/387]". Official Journal of the European Union. 9 March 2021. L 82, pp. 30–59. Retrieved 26 September 2026.
  9. ↑ "Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users". EUR-Lex. 16 December 2019. Annex II, item D4. Retrieved 26 September 2026.
  10. ↑ Polly, Sebastian; Borst, Leopold M.; Golling, Manuel (11 January 2022). "New cyber security and software update rules in the automotive industry in 2022". Hogan Lovells. Retrieved 26 September 2026.
  11. ↑ Costantino, Gianpiero; De Vincenzi, Marco; Matteucci, Ilaria (2022). A Comparative Analysis of UNECE WP.29 R155 and ISO/SAE 21434. 2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE. pp. 340–347. doi:10.1109/EuroSPW55150.2022.00041.
  12. ↑ Schädlich, Eric (2 September 2024). "China's New Vehicle Cybersecurity Standard: GB 44495-2024". dissecto. Retrieved 26 September 2026.
  13. 1 2 Costantino, Gianpiero; De Vincenzi, Marco; Matteucci, Ilaria (2022). "In-Depth Exploration of ISO/SAE 21434 and Its Correlations with Existing Standards". IEEE Communications Standards Magazine. 6 (1): 84–92. doi:10.1109/MCOMSTD.0001.2100080.
  14. ↑ ISO/PAS 5112:2022 – Road vehicles – Guidelines for auditing cybersecurity engineering (1st ed.). Geneva: International Organization for Standardization. March 2022. Clause 1.
  15. ↑ ISO 24089:2023 – Road vehicles – Software update engineering. Geneva: International Organization for Standardization. 2023. Clause 1.

Further reading

[edit]
[edit]