Abstract
Vehicle functions are 90% controlled by electronic and software thus, modern vehicles need to comply with cybersecurity standards and data security law. Under the EU Blueprint for Automotive - DRIVES project (www.project-drives.eu), key skills and job roles for future Automotive development are designed. These also include cybersecurity management, cybersecurity engineering, and cybersecurity testing. The working party SOQRATES (www.soqrates.de) agreed to develop the pattern of such skills set in cooperation with DRIVES. Also, to share required best practices and skills to be transferred to allow implementing the norms. This paper provides an overview of the current version of the skills set, and an example of what type of best practice is shared.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
References
Automotive SPICE © 3.1. Process Assessment Model, VDA QMC Working Group
Automotive SPICE © Guidelines. 2nd Edition Nov 2017, VDA QMC Working Group 13, November 2017
Macher, G., Sporer, H., Brenner, E., Kreiner, C.: Supporting cyber-security based on hardware-software interface definition. In: Kreiner, C., O’Connor, R.V., Poth, A., Messnarz, R. (eds.) EuroSPI 2016. CCIS, vol. 633, pp. 148–159. Springer, Cham (2016). https://doi.org/10.1007/978-3-319-44817-6_12
Macher, G., Messnarz, R., Kreiner, C., et. al.: Integrated Safety and Security Development in the Automotive Domain, Working Group 17AE-0252/2017-01-1661. SAE International, June 2017
Macher, G., Much, A., Riel, A., Messnarz, R., Kreiner, C.: Automotive SPICE, safety and cybersecurity integration. In: Tonetta, S., Schoitsch, E., Bitsch, F. (eds.) SAFECOMP 2017. LNCS, vol. 10489, pp. 273–285. Springer, Cham (2017). https://doi.org/10.1007/978-3-319-66284-8_23
Messnarz, R., Kreiner, C., Macher, G., Walker, A.: Extending automotive SPICE 3.0 for the use in ADAS and future self‐driving service architectures. J. Softw. Evol. Process 30(5), e1948 (2018)
Messnarz, R., Kreiner, C., Riel, A.: Integrating automotive SPICE, functional safety, and cybersecurity concepts: a cybersecurity layer model. Softw. Qual. Prof. 18, 13 (2016)
Messnarz, R., Sehr, M., Wüstemann, I., Humpohl, J., Ekert, D.: Experiences with SQIL – SW quality improvement leadership approach from Volkswagen. In: Stolfa, J., Stolfa, S., O’Connor, R.V., Messnarz, R. (eds.) EuroSPI 2017. CCIS, vol. 748, pp. 421–435. Springer, Cham (2017). https://doi.org/10.1007/978-3-319-64218-5_35
SAE J3061. Cybersecurity Guidebook for Cyber-Physical Vehicle Systems, SAE - Society of Automotive Engineers, USA, January 2016
SOQRATES. Task Forces Developing Integration of Automotive SPICE, ISO 26262 and SAE J3061. http://soqrates.eurospi.net/
EU Blueprint Project DRIVES. https://www.project-drives.eu/. Accessed 17 Apr 2020
GEAR 2030. High Level Group on the Competitiveness and Sustainable Growth of the Automotive Industry in the European Union (2017)
European Sector Skill Council: Report, Eu Skill Council Automotive Industry (2013)
Macher, G., Sporer, H., Berlach, R., Armengaud, E., Kreiner, C.: SAHARA: a security-aware hazard and risk analysis method. In: Design, Automation Test in Europe Conference Exhibition (DATE), pp. 621–624, March 2015
Microsoft Corporation. The STRIDE threat model (2005)
Macher, G., Armengaud, E., Brenner, E., Kreiner, C.: A review of threat analysis and risk assessment methods in the automotive context. In: Skavhaug, A., Guiochet, J., Bitsch, F. (eds.) SAFECOMP 2016. LNCS, vol. 9922, pp. 130–141. Springer, Cham (2016). https://doi.org/10.1007/978-3-319-45477-1_11
Macher, G., Höller, A., Sporer, H., Armengaud, E., Kreiner, C.: A comprehensive safety, security, and serviceability assessment method. In: Koornneef, F., van Gulijk, C. (eds.) SAFECOMP 2015. LNCS, vol. 9337, pp. 410–424. Springer, Cham (2015). https://doi.org/10.1007/978-3-319-24255-2_30
Riel, A., Kreiner, C., Messnarz, R., Much, A.: An architectural approach to the integration of safety and security requirements in smart products and systems design. CIRP Ann. 67(1), 173–176 (2018)
Riel, A., et al.: EU project SafEUr – competence requirements for functional safety managers. In: Winkler, D., O’Connor, R.V., Messnarz, R. (eds.) EuroSPI 2012. CCIS, vol. 301, pp. 253–265. Springer, Heidelberg (2012). https://doi.org/10.1007/978-3-642-31199-4_22
Riel, A., Tichkiewitch, S., Messnarz, R.: The profession of integrated engineering: formation and certification on a European level. Acad. J. Manuf. 6, 6–13 (2008)
Riel, A., Draghici, A., Draghici, G., Grajewski, D., Messnarz, R.: Process and product innovation needs integrated engineering collaboration skills. J. Softw. Evol. Process 24(5), 551–560 (2012)
ISO/SAE 21434. Road vehicles – Cybersecurity engineering, ISO and SAE, Committee Draft (CD) (2018)
Christian, K., Messnarz, R., Riel, A., et al.: The AQUA automotive sector skills alliance: best practice in an integrated engineering approach. Softw. Qual. Prof. 17(3), 35–45 (2015). 11 p.
Messnarz, R., et al.: Integrating functional safety, automotive SPICE and Six Sigma – the AQUA knowledge base and integration examples. In: Barafort, B., O’Connor, R.V., Poth, A., Messnarz, R. (eds.) EuroSPI 2014. CCIS, vol. 425, pp. 285–295. Springer, Heidelberg (2014). https://doi.org/10.1007/978-3-662-43896-1_26
Kreiner, C., et al.: Automotive knowledge alliance AQUA – integrating automotive SPICE, Six Sigma, and functional safety. In: McCaffery, F., O’Connor, R.V., Messnarz, R. (eds.) EuroSPI 2013. CCIS, vol. 364, pp. 333–344. Springer, Heidelberg (2013). https://doi.org/10.1007/978-3-642-39179-8_30
Messnarz, R., Spork, G., Riel, A., Tichkiewitch, S.: Dynamic learning organisations supporting knowledge creation for competitive and integrated product design. In: Proceedings of the 19th CIRP Design Conference – Competitive Design, 30–31 March 2009, p. 104. Cranfield University (2009)
Messnarz, R., Kreiner, C., Riel, A., et.al.: Implementing functional safety standards has an impact on system and SW design - required knowledge and competencies (SafEUr). Software Quality Professional (2015)
Messnarz, R., et al.: Implementing functional safety standards – experiences from the trials about required knowledge and competencies (SafEUr). In: McCaffery, F., O’Connor, Rory V., Messnarz, R. (eds.) EuroSPI 2013. CCIS, vol. 364, pp. 323–332. Springer, Heidelberg (2013). https://doi.org/10.1007/978-3-642-39179-8_29
Messnarz, R., König, F., Bachmann, V.O.: Experiences with trial assessments combining automotive SPICE and functional safety standards. In: Winkler, D., O’Connor, R.V., Messnarz, R. (eds.) EuroSPI 2012. CCIS, vol. 301, pp. 266–275. Springer, Heidelberg (2012). https://doi.org/10.1007/978-3-642-31199-4_23
Messnarz, R., Much, A., Kreiner, C., Biro, M., Gorner, J.: Need for the continuous evolution of systems engineering practices for modern vehicle engineering. In: Stolfa, J., Stolfa, S., O’Connor, R.V., Messnarz, R. (eds.) EuroSPI 2017. CCIS, vol. 748, pp. 439–452. Springer, Cham (2017). https://doi.org/10.1007/978-3-319-64218-5_36
Much, A.: Automotive Security: Challenges, Standards and Solutions. Softw. Qual. Prof. 18, 4–12 (2016)
Stolfa, J., et al.: Automotive quality universities - AQUA alliance extension to higher education. In: Kreiner, C., O’Connor, R.V., Poth, A., Messnarz, R. (eds.) EuroSPI 2016. CCIS, vol. 633, pp. 176–187. Springer, Cham (2016). https://doi.org/10.1007/978-3-319-44817-6_14
Korsaa, M., et al.: The SPI manifesto and the ECQA SPI manager certification scheme. J. Softw. Evol. Process 24(5), 525–540 (2012)
Korsaa, M., et al.: The people aspects in modern process improvement management approaches. J. Softw. Evol. Process 25(4), 381–391 (2013)
Messnarz, R., et al.: Social responsibility aspects supporting the success of SPI. J. Softw. Evol. Process 26(3), 284–294 (2014)
Messnarz, R., Ekert, D.: Assessment‐based learning systems - learning from best projects. Wiley Inersci. Softw. Process Improv. Pract. 12(6), 569–577 (2007). https://doi.org/10.1002/spip.347. Special Issue on Industrial Experiences in SPI
Messnarz, R., Ekert, D., Zehetner, T., Aschbacher, L.: Experiences with ASPICE 3.1 and the VDA automotive SPICE guidelines – using advanced assessment systems. In: Walker, A., O’Connor, R.V., Messnarz, R. (eds.) EuroSPI 2019. CCIS, vol. 1060, pp. 549–562. Springer, Cham (2019). https://doi.org/10.1007/978-3-030-28005-5_42
Stolfa, J., et al.: DRIVES—EU blueprint project for the automotive sector—a literature review of drivers of change in automotive industry. J. Softw. Evol. Process 32(3), e2222 (2020). Special Issue: Addressing Evolving Requirements Faced by the Software Industry
Acknowledgements
We are grateful to the European Commission which has funded the Blueprint project Development and Research on Innovative Vocational Skills (DRIVES, 2018-2021, www.project-drives.eu). The project DRIVES – Project number 591988-EPP-1-2017-1-CZ-EPPKA2-SSA-B is co-funded by the Erasmus + Programme of the European Union.
The European Commission support for the production of this publication under the Grant Agreement Nº 2017-3295/001-001 does not constitute an endorsement of the contents which reflects the views only of the authors, and the Commission cannot be held responsible for any use which may be made of the information contained therein.
Work is partially supported by Grant of SGS No. SP2020/62, VŠB - Technical University of Ostrava, Czech Republic.
We are grateful to a working party of Automotive suppliers SOQRATES (www.soqrates.de) who exchange knowledge about such assessment strategies. This includes: Böhner Martin (Elektrobit), Brasse Michael (HELLA), Bressau Ernst (BBraun), Dallinger Martin (ZF), Dorociak Rafal (HELLA), Dreves Rainer (Continental Automotive), Ekert Damjan (ISCN), Forster Martin (ZKW), Geipel Thomas (BOSCH), Grave Rudolf (Elektrobit), Griessnig Gerhard (AVL), Gruber Andreas (ZKW), Habel Stephan (Continental Automotive), Hällmayer Frank (Software Factory), Haunert Lutz (Giesecke & Devrient), Karner Christoph (KTM), Kinalzyk Dietmar (AVL), König Frank (ZF), Lichtenberger Christoph (MAGNA ECS), Lindermuth Peter (Magna Powertrain), Macher Georg (TU Graz & ISCN), Mandic Irenka (Magna Powertrain), Maric Dijas (Lorit Consultancy), Mayer Ralf (BOSCH Engineering), Mergen Silvana (TDK/EPCOS), Messnarz Richard (ISCN), Much Alexander (Elektrobit), Nikolov Borislav (msg Plaut), Oehler Couso Daniel (Magna Powertrain), Riel Andreas (Grenoble INP & ISCN), Rieß Armin (BBraun), Santer Christian (AVL), Schlager Christian (Magna ECS), Schmittner Christoph (Austrian Institute of Technology AIT), Schubert Marion (ZKW), Sechser Bernhard (Process Fellows), Sokic Ivan (Continental Automotive), Sporer Harald (Infineon), Stahl Florian (AVL), Wachter Stefan (msg Plaut), Walker Alastair (Lorit Consultancy), Wegner Thomas (ZF).
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2020 Springer Nature Switzerland AG
About this paper
Cite this paper
Messnarz, R. et al. (2020). Automotive Cybersecurity Engineering Job Roles and Best Practices – Developed for the EU Blueprint Project DRIVES. In: Yilmaz, M., Niemann, J., Clarke, P., Messnarz, R. (eds) Systems, Software and Services Process Improvement. EuroSPI 2020. Communications in Computer and Information Science, vol 1251. Springer, Cham. https://doi.org/10.1007/978-3-030-56441-4_37
Download citation
DOI: https://doi.org/10.1007/978-3-030-56441-4_37
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-030-56440-7
Online ISBN: 978-3-030-56441-4
eBook Packages: Computer ScienceComputer Science (R0)