Integration of Cybersecurity Related Development Processes by Using a Quantification Method

Publikation: Beitrag in Buch/Bericht/Sammelwerk/KonferenzbandAufsatz in KonferenzbandForschungPeer-Review

Autoren

  • Hassan Noun
  • Florian Rehm
  • Guillaume Zeller
  • G. Rajesh
  • Roland Lachmayer

Externe Organisationen

  • ZF CV Systems Hannover GmbH
  • ZF CV Systems Europe B.V. Brüssel
Forschungs-netzwerk anzeigen

Details

OriginalspracheEnglisch
Titel des SammelwerksScience of Cyber Security - 4th International Conference, SciSec 2022, Revised Selected Papers
Herausgeber/-innenChunhua Su, Kouichi Sakurai, Feng Liu
Herausgeber (Verlag)Springer Science and Business Media Deutschland GmbH
Seiten233-242
Seitenumfang10
ISBN (elektronisch)978-3-031-17551-0
ISBN (Print)9783031175503
PublikationsstatusVeröffentlicht - 2022
Veranstaltung4th International Conference on Science of Cyber Security, SciSec 2022 - Matsue, Japan
Dauer: 10 Aug. 202212 Aug. 2022

Publikationsreihe

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Band13580 LNCS
ISSN (Print)0302-9743
ISSN (elektronisch)1611-3349

Abstract

The international standard ISO 21434 is used to derive new development processes, work products and roles during product development in the automotive industry. For a suitable development of security relevant vehicle systems, the new work steps must be integrated into the existing development process. The challenge is to apply a proper method for an integration of these additional activities. For the integration a quantification of the process maturity of the security relevant development processes supports thereby, in order to make a statement about the precondition for the treatment of security relevant vehicle systems. Furthermore, this identifies development fields in the process integration. This paper shows how a coefficient for measuring process maturity is established. Therefore, the functional security related activities are identified and isolated. In the next step supporting processes are defined. Further, weighted means are determined. The aim is to have an indicator for the security relevant development processes already at the beginning of the development and thus to be able to take appropriate measures in advance. As an application example, an automotive project for ADAS system is considered. This is followed by differentiated derivations of measures based on the established coefficients for the individual domains.

ASJC Scopus Sachgebiete

Zitieren

Integration of Cybersecurity Related Development Processes by Using a Quantification Method. / Noun, Hassan; Rehm, Florian; Zeller, Guillaume et al.
Science of Cyber Security - 4th International Conference, SciSec 2022, Revised Selected Papers. Hrsg. / Chunhua Su; Kouichi Sakurai; Feng Liu. Springer Science and Business Media Deutschland GmbH, 2022. S. 233-242 (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics); Band 13580 LNCS).

Publikation: Beitrag in Buch/Bericht/Sammelwerk/KonferenzbandAufsatz in KonferenzbandForschungPeer-Review

Noun, H, Rehm, F, Zeller, G, Rajesh, G & Lachmayer, R 2022, Integration of Cybersecurity Related Development Processes by Using a Quantification Method. in C Su, K Sakurai & F Liu (Hrsg.), Science of Cyber Security - 4th International Conference, SciSec 2022, Revised Selected Papers. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), Bd. 13580 LNCS, Springer Science and Business Media Deutschland GmbH, S. 233-242, 4th International Conference on Science of Cyber Security, SciSec 2022, Matsue, Japan, 10 Aug. 2022. https://doi.org/10.1007/978-3-031-17551-0_15
Noun, H., Rehm, F., Zeller, G., Rajesh, G., & Lachmayer, R. (2022). Integration of Cybersecurity Related Development Processes by Using a Quantification Method. In C. Su, K. Sakurai, & F. Liu (Hrsg.), Science of Cyber Security - 4th International Conference, SciSec 2022, Revised Selected Papers (S. 233-242). (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics); Band 13580 LNCS). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-031-17551-0_15
Noun H, Rehm F, Zeller G, Rajesh G, Lachmayer R. Integration of Cybersecurity Related Development Processes by Using a Quantification Method. in Su C, Sakurai K, Liu F, Hrsg., Science of Cyber Security - 4th International Conference, SciSec 2022, Revised Selected Papers. Springer Science and Business Media Deutschland GmbH. 2022. S. 233-242. (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)). Epub 2022 Sep 30. doi: 10.1007/978-3-031-17551-0_15
Noun, Hassan ; Rehm, Florian ; Zeller, Guillaume et al. / Integration of Cybersecurity Related Development Processes by Using a Quantification Method. Science of Cyber Security - 4th International Conference, SciSec 2022, Revised Selected Papers. Hrsg. / Chunhua Su ; Kouichi Sakurai ; Feng Liu. Springer Science and Business Media Deutschland GmbH, 2022. S. 233-242 (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)).
Download
@inproceedings{38d9310d228f4a6cac006f1bb0a09c3f,
title = "Integration of Cybersecurity Related Development Processes by Using a Quantification Method",
abstract = "The international standard ISO 21434 is used to derive new development processes, work products and roles during product development in the automotive industry. For a suitable development of security relevant vehicle systems, the new work steps must be integrated into the existing development process. The challenge is to apply a proper method for an integration of these additional activities. For the integration a quantification of the process maturity of the security relevant development processes supports thereby, in order to make a statement about the precondition for the treatment of security relevant vehicle systems. Furthermore, this identifies development fields in the process integration. This paper shows how a coefficient for measuring process maturity is established. Therefore, the functional security related activities are identified and isolated. In the next step supporting processes are defined. Further, weighted means are determined. The aim is to have an indicator for the security relevant development processes already at the beginning of the development and thus to be able to take appropriate measures in advance. As an application example, an automotive project for ADAS system is considered. This is followed by differentiated derivations of measures based on the established coefficients for the individual domains.",
keywords = "Cybersecurity, Integration method, Process integration, System security",
author = "Hassan Noun and Florian Rehm and Guillaume Zeller and G. Rajesh and Roland Lachmayer",
year = "2022",
doi = "10.1007/978-3-031-17551-0_15",
language = "English",
isbn = "9783031175503",
series = "Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)",
publisher = "Springer Science and Business Media Deutschland GmbH",
pages = "233--242",
editor = "Chunhua Su and Kouichi Sakurai and Feng Liu",
booktitle = "Science of Cyber Security - 4th International Conference, SciSec 2022, Revised Selected Papers",
address = "Germany",
note = "4th International Conference on Science of Cyber Security, SciSec 2022 ; Conference date: 10-08-2022 Through 12-08-2022",

}

Download

TY - GEN

T1 - Integration of Cybersecurity Related Development Processes by Using a Quantification Method

AU - Noun, Hassan

AU - Rehm, Florian

AU - Zeller, Guillaume

AU - Rajesh, G.

AU - Lachmayer, Roland

PY - 2022

Y1 - 2022

N2 - The international standard ISO 21434 is used to derive new development processes, work products and roles during product development in the automotive industry. For a suitable development of security relevant vehicle systems, the new work steps must be integrated into the existing development process. The challenge is to apply a proper method for an integration of these additional activities. For the integration a quantification of the process maturity of the security relevant development processes supports thereby, in order to make a statement about the precondition for the treatment of security relevant vehicle systems. Furthermore, this identifies development fields in the process integration. This paper shows how a coefficient for measuring process maturity is established. Therefore, the functional security related activities are identified and isolated. In the next step supporting processes are defined. Further, weighted means are determined. The aim is to have an indicator for the security relevant development processes already at the beginning of the development and thus to be able to take appropriate measures in advance. As an application example, an automotive project for ADAS system is considered. This is followed by differentiated derivations of measures based on the established coefficients for the individual domains.

AB - The international standard ISO 21434 is used to derive new development processes, work products and roles during product development in the automotive industry. For a suitable development of security relevant vehicle systems, the new work steps must be integrated into the existing development process. The challenge is to apply a proper method for an integration of these additional activities. For the integration a quantification of the process maturity of the security relevant development processes supports thereby, in order to make a statement about the precondition for the treatment of security relevant vehicle systems. Furthermore, this identifies development fields in the process integration. This paper shows how a coefficient for measuring process maturity is established. Therefore, the functional security related activities are identified and isolated. In the next step supporting processes are defined. Further, weighted means are determined. The aim is to have an indicator for the security relevant development processes already at the beginning of the development and thus to be able to take appropriate measures in advance. As an application example, an automotive project for ADAS system is considered. This is followed by differentiated derivations of measures based on the established coefficients for the individual domains.

KW - Cybersecurity

KW - Integration method

KW - Process integration

KW - System security

UR - http://www.scopus.com/inward/record.url?scp=85140445107&partnerID=8YFLogxK

U2 - 10.1007/978-3-031-17551-0_15

DO - 10.1007/978-3-031-17551-0_15

M3 - Conference contribution

AN - SCOPUS:85140445107

SN - 9783031175503

T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)

SP - 233

EP - 242

BT - Science of Cyber Security - 4th International Conference, SciSec 2022, Revised Selected Papers

A2 - Su, Chunhua

A2 - Sakurai, Kouichi

A2 - Liu, Feng

PB - Springer Science and Business Media Deutschland GmbH

T2 - 4th International Conference on Science of Cyber Security, SciSec 2022

Y2 - 10 August 2022 through 12 August 2022

ER -