论文标题
公路车辆的安全保证案件:行业的观点
Security Assurance Cases for Road Vehicles: an Industry Perspective
论文作者
论文摘要
保证案件是结构化论点,通常用于推理产品或服务的安全性。当前,正在持续推动使用保证案例的网络安全,尤其是在安全 - 关键领域(如汽车)中。尽管该行业面临定义建立安全保证案例的合理方法的挑战,但最新技术的状态相当不成熟。因此,我们对(外部)约束进行了彻底的调查,并且(内部)需求安全案件必须在汽车行业的背景下满足。这是在瑞典两家大型汽车公司的背景下进行的。最终结果是一组建议,该建议可以申请,以定义(i)与现有标准和即将到来的标准和法规所施加的约束,以及(ii)与内部产品开发过程和组织实践协调的安全案例。我们希望结果对其他关键领域的产品公司(如医疗保健,运输等)也是感兴趣的
Assurance cases are structured arguments that are commonly used to reason about the safety of a product or service. Currently, there is an ongoing push towards using assurance cases for also cybersecurity, especially in safety-critical domains, like automotive. While the industry is faced with the challenge of defining a sound methodology to build security assurance cases, the state of the art is rather immature. Therefore, we have conducted a thorough investigation of the (external) constraints and (internal) needs that security assurance cases have to satisfy in the context of the automotive industry. This has been done in the context of two large automotive companies in Sweden. The end result is a set of recommendations that automotive companies can apply in order to define security assurance cases that are (i) aligned with the constraints imposed by the existing and upcoming standards and regulations and (ii)harmonized with the internal product development processes and organizational practices. We expect the results to be also of interest for product companies in other safety-critical domains, like healthcare, transportation, and so on