SecCT-AUTO System Certification Version
Requirements for Security Risk Management
On August 31, 2021, the International Organization for Standardization (ISO) officially released ISO/SAE 21434 "Road vehicles - Cybersecurity engineering", which specifies the information security risk management requirements for road vehicle electronic and electrical systems and their components and interfaces in the conceptual, development, production, operation, maintenance, and destruction stages of engineering.
Information security of vehicles
How to implement information security monitoring and establish an emergency response mechanism for information security incidents throughout the entire product lifecycle for OEMs, and continuously ensure the information security of vehicles, is an important issue facing every automotive company.
Solutions
Support the information security management process system
The toolchain system covering the entire lifecycle of ISO 21434 helps enterprises build a risk management based information security management process system, which is used to identify, analyze, and defend against potential risks such as information security risks, threats, vulnerabilities, and attacks. It realizes the linkage from "standards → security technical requirements → security design requirements → vulnerability library+threat library+test cases".
Highlights of the plan
Develop information security related processes
Support CSMS certification and assist OEMs in developing information security related processes throughout the entire lifecycle of automobiles to ensure that there are corresponding process measures in place to control related risks throughout the automotive lifecycle.
Ensure information security protection
Support VTA certification and assist OEMs in managing the execution of specific work in information security development, with the goal of ensuring that vehicle information security protection technology can cover the security requirements of each lifecycle and ensure the implementation of information security protection.
Core Development Process Management
Support the management of all relevant fields and core development activity processes for the "V model" under the requirements of ISO/SAE 21434 standard.
Featured Features

Compare the standards with the current system status

Differentiation analysis

Control, decompose, and track requirements

Collaborate with TARA and target TARA

Output for full cycle control and tracking

Cooperate to establish enterprises/vehicle models/systems/

Asset library and vulnerability library at the part level

Attack Library

Integrate penetration testing into the R&D process

And manage it