Automotive Threat Analysis and Risk Assessment in Practice: A Practical Guide to Tara Following the Iso/Sae 21434 Standard for Automotive Embedded and
Do Carmo, Rodrigo, Schlensog, Alexander
相關主題
商品描述
The surge in automotive cybersecurity regulations necessitates a structured risk management method. This work examines these regulations, details the European cybersecurity legal framework, and explores the ISO/SAE 21434's threat analysis and risk assessment (TARA) approach. Implementing TARA in real-world scenarios presents challenges, such as identifying the correct assets or performing accurate threat modeling. This book employs a pragmatic approach to TARA across three domains: electrical and electronic systems within the vehicle, the vehicle's connected ecosystem, and manufacturing plants, integrating insights from ISO/IEC 27000 and IEC 62443 standard series without seeking to harmonize them. This book offers a technical guideline for TARA, presenting detailed case studies across these domains and emphasizing technical rigor while ensuring efficiency.
商品描述(中文翻譯)
汽車網路安全法規的激增需要一種結構化的風險管理方法。本書探討這些法規,詳細介紹歐洲的網路安全法律框架,並探討 ISO/SAE 21434 的威脅分析與風險評估(TARA)方法。在實際情境中實施 TARA 面臨挑戰,例如識別正確的資產或進行準確的威脅建模。本書採用務實的方法來應用 TARA,涵蓋三個領域:車輛內的電氣和電子系統、車輛的連接生態系統以及製造廠,並整合 ISO/IEC 27000 和 IEC 62443 標準系列的見解,而不尋求將其協調一致。本書提供 TARA 的技術指導,呈現這些領域的詳細案例研究,強調技術的嚴謹性,同時確保效率。
作者簡介
Dr.-Ing. Rodrigo do Carmo holds degrees in telecommunications engineering and computer science. He has held cybersecurity roles at Continental AG and secunet Security Networks AG, where he leads TARA projects and contributes to ISO/DIN automotive cybersecurity committees.
Dipl.-Phys. Alexander Schlensog with a background in physics and extensive experience in information security since 2001, leads the consulting business for the Industry division at secunet. He specializes in critical infrastructures and plays an active role in ISO/DIN standards committees for information security and data protection.
作者簡介(中文翻譯)
Dr.-Ing. Rodrigo do Carmo 擁有電信工程和計算機科學的學位。他曾在 Continental AG 和 secunet Security Networks AG 擔任網絡安全職位,負責領導 TARA 項目並參與 ISO/DIN 汽車網絡安全委員會。
Dipl.-Phys. Alexander Schlensog 擁有物理學背景,自 2001 年以來在資訊安全領域擁有豐富的經驗,負責 secunet 工業部門的諮詢業務。他專注於關鍵基礎設施,並在資訊安全和數據保護的 ISO/DIN 標準委員會中積極參與。