Use Case:
ISO/SAE 21434 Compliance
Get an appointment

USE CASE: ISO/SAE 21434 CompliancE

Client:

  • AutomotiveSupplier (Tier 1)

Clients Size:

  • 500.. 2000 employees

Demand:

  • ISO/SAE21434 compliance (CSMS)
  • Distributed UN r155 requirements from OEMs
  • Cybersecurity project support for a medium complexity ECU

Required Inputs from Client

  • Budget allocation for personnel, tooling and cybersecurity activities
  • Access to required client resources (documentation, tools,experts etc.)
  • Definition of the project scope,
  • Client participation to meetingsand trainings,
  • Beingreadyto absorb additional workload in all lifecycle of the product especially conception, development, verification and validation.

Estimated Duration:

  • 4-8 months

APPROACH

ISO/SAE 21434 Compliance Approach

ISO/SAE 21434 compliance activities start with a gap analysis that will identify the estimated workload at company and project level including QMS, policies, processes, rules, guidelines, templates, work products and tools. A client project is chosen as a candidate to work on. The gap analysis can be performed as a standalone activity if demanded.

The next step is to review the gap analysis report with the client and agree on the planning and the commercial offer. At this phase, it is crucial to define the milestones and the KPIs clearly for perfect synchronization with client teams.

Once an agreement is reached, the planning starts being executed. A dashboard shall be created to enable all stakeholders to view the advancement of the activities as well as delays and blocking points.

work breakdown

It is highly recommended to create work packages to facilitate the follow-up and to incorporate multiple teams in parallel. An example is given below with the associated 6 months planning:

WP-1 Compliance with ISO/SAE 21434 Chapter 5 CSMS and OEM distributed UN r155 requirements

WP-2 Policies/Rules/Processes to be created, improved or reviewed:

  • Organisational Cybersecurity Policy
  • Development processes (cybersecurity activities to be integrated)
  • TARA methodology
  • Vulnerability Analysis,
  • Cybersecurity Management System for Production
  • Cybersecurity Events
  • Monitoring and Incident Response

WP-3 Verification and Validation of the project

WP-4 ISO/SAE 21434templates, work products, checklists

WP-5 Dashboard and Tools

WP-6 Trainings (ISO/SAE 21434, UN r155, Vulnerability Awareness/Cybersecurity Culture, TARA)

ISO/SAE 21434 Compliance Planning

Conclusion

Compliance with ISO/SAE 21434 require a rigorous and multidimensional approach that can only be achieved with the help of expert consultation service.

Rappel Cybersecurity provides end-to-end and scalable consultancy services that spans entire product lifecycle. Contact us for your needs regarding cybersecurity compliance at any dimension and phase.

See also our page on ISO/SAE 21434 standard for more information.

Get an appointment