New

Newsroom more...

Cyber Security Management Systeme (CSMS)

A new dimension of safety in the car

A new dimension of safety in the car

Innovations in the automotive industry such as autonomous driving, connectivity, electric engine types and modern mobility concepts are shaping a new understanding of vehicles. Increasingly comprehensive IT systems are enabling the basis for these developments. Today, up to 150 ECUs and around 100 million lines of code can be found in a vehicle. That's four times more than in a fighter jet. And this development is far from over: According to the UNECE (United Nations Economic Commission for Europe), digital systems from OEMs will anticipate 300 million lines of code by 2030.

In this context, the interdependence between ECUs and other vehicle hardware, as well as access to them via external sources, raises security concerns. These concerns have been heightened by demonstrative hacking successes by security professionals, putting the issue of cybersecurity in the focus of OEMs.

Do you have any questions?

Christina Brandstetter

Business Development Automotive

Standard against cyber risks in the automotive industry

As a consequence, the call for uniform standards is becoming increasingly louder. The EU Cybersecurity Act initiated in 2019 focused on cybersecurity management systems and Software Management Update Systems in a UNECE working group. This working group is concerned with the global harmonization of vehicle regulations.

One result of this: In collaboration with the International Organization for Standardization (ISO) and the Society of Automotive Engineers (SAE), the UNECE is creating a certification for Cybersecurity Management Systems (CSMS). The ISO/SAE 21434 standard is currently in "approval status" and is expected to apply to newly registered vehicle types from mid-2022 and to all newly produced vehicles from 2024. The goal is to specify a structured process for CSMS at automakers and in-vehicle cybersecurity that reduces the success rate of hacking attacks and establishes a standard against cyber threats in the automotive industry. The requirement for cybersecurity thus increases from individual features to entire management systems – ergo from project to organizational level. This standard does not specify cybersecurity technologies or concrete methods. Instead, it suggests an approach for prioritizing cybersecurity activities and the recording of measures.

Certified cybersecurity system as basis for approval of new vehicle types

The principles laid down in UN Regulation 155 and the ISO/SAE 21434 standard apply in Germany as a prerequisite for type approval (homologation) by the Federal Motor Transport Authority (Kraftfahrtbundesamt) and by the corresponding bodies in all UNECE member states and recognizing third countries.

Four areas are described in the ISO/SAE 21434 standard:

  • The management of cyber risks from the vehicle and its environment
  • The inherent safeguarding of a vehicle and its value chain
  • Establishing a cybersecurity incident response system to identify and address cybersecurity incidents
  • Remote software updates for an up-to-date software status

In practice, this means that a management system for cybersecurity and remote software updates certified by independent auditors is a prerequisite for the approval of new vehicle types. Certification is relevant for OEMs and suppliers alike. The standard differentiates between a CSMS for the organization and the application of the CSMS at product level. In terms of content, companies can use the sections of the standard as a guide when creating a CSMS in the future: These address the creation of a (1) CSMS concept, its (2) management, (3) risk determination methods, the integration of cybersecurity aspects in (4) product development, and (5) production, operation, and maintenance.

Accordingly, a cybersecurity management system comprises various processes at organizational and project level. In detail, it is about the identification, assessment and treatment of cyber risks in an appropriate timeframe over the entire lifecycle of a vehicle. Ultimately, the entire CSMS must be validated alongside a SUMS by an independent third party for type approval clearance. The implementation of UN Regulation 155 covers several areas – from the concept phase, product development, cybersecurity systems management, risk determination methods, production, operation and maintenance, and supporting processes.

The IT, automotive and homologation experts at msg

msg has in-depth IT and industry expertise. Experts in the areas of cybersecurity and software update management systems as well as electrics/electronics support our customers in identifying relevant regulations, in evaluating company-specific processes and homologation procedures up to obtaining type approval. Consulting, conception, functional specification up to the implementation of IT systems – we are ready to help.

How can we help you with your cybersecurity management system?

Get in touch.

SDV

Join us for an in-depth look at the challenges and opportunities for ADAS in the backend and find out why providing additional information for ADAS functions is so crucial.

SDV, Quantum Computing

Experts assume that information security will be threatened by quantum computers in the future. With the right action plan, companies from the IIoT, automotive and KRITIS sectors can prepare themselves today for the use of new encryption technologies and thus mitigate the risks posed by quantum computers.

Homologation, SDV, Cybersecurity

With the growing proportion of software in automobiles, the risk of a cyber attack is rising in parallel. This adds another dimension to the concept of vehicle quality – that of cybersecurity.

Data-based ecosystems, SDV

The development of highly complex driving functions for autonomous driving requires improved sensors and optimized data use in the collaboration between automobile manufacturers, sensor suppliers and simulation development. Data ecosystems in conjunction with digital twins offer an efficient solution for safe and cost-effective updates.

Homologation

The WLTP procedure, which has been in force since 2021, means that detailed data on vehicle variants and their optional equipment must be combined in the areas of aerodynamics and engine type. This means that new calculation algorithms are necessary and internal processes have to be reorganized. Read our article to find out what challenges but also opportunities this entails.

Data-based ecosystems, SDV

The close interaction between hardware, software and data in the vehicle opens up new opportunities for car manufacturers.

Digital Twin, Homologation

Vehicle customers and authorities expect highly automated driving functions to be thoroughly tested by the automotive manufacturer and to be safe. New test methods and regulations must be developed and established for this purpose. This is not feasible without a digital twin. Why? You can read about this in the following article.

SDV

The goals of V2X include improving safety and trust in road traffic. Discover how this works on a global scale and why it is not enough on its own.