Security Capability: Identity and Access Control
Purpose
Ensure only authorized tools, systems, users, and software actors can perform security-relevant actions.
Threat / Risk Addressed
Unauthorized actor gains privileged access.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0044; RFQX-3299216-1-0135; RFQX-3299216-1-0141; RFQX-CVS123-2-0005; RFQX-CVS123-2-0017; RFQX-CVS123-2-0023; RFQX-CVS123-2-0078; RFQX-CVS123-2-0079; RFQX-CVS123-2-0097; RFQX-CVS123-2-0099; RFQX-CVS123-2-0123; RFQX-CVS123-2-0158; RFQX-CVS123-2-0200; RFQX-CVS124-0061; RFQX-CVS124-0083; RFQX-CVS124-0305; RFQX-CVS124-0306 (sample: 18 of 312)
- Source document sections: source document page 7; source document page 9; source document page 27; source document page 4; source document page 5; source document page 6; source document page 12; source document page 14(sample: 8 of 66)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- OEM/customer cybersecurity approval and evidence interface
- Secure update, flash, and IVD interface
- Certificate and key provisioning interface
- Development, ALM, and evidence tooling interface
- Security operations and vulnerability reporting interface
- Hardware platform and key storage interface
Architecture Elements Involved
- Security Services
- Diagnostic Server
- Backend/PKI
Expected Mechanisms
- Authentication
- Authorization
- Secure sessions
- Role or certificate validation
Explicit vs Inferred Status
Explicit Requirement
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0044; RFQX-3299216-1-0135; RFQX-3299216-1-0141; RFQX-CVS123-2-0005; RFQX-CVS123-2-0017; RFQX-CVS123-2-0023; RFQX-CVS123-2-0078; RFQX-CVS123-2-0079; RFQX-CVS123-2-0097 (sample: 10 of 312)
- Source document: source document page 7; source document page 9; source document page 27; source document page 4; source document page 5; source document page 6; source document page 12; source document page 14(sample: 8 of 66)
- Confidence level: Low
- Classification: Explicit Requirement
Security Capability: Cryptographic Protection
Purpose
Provide authenticity, integrity, confidentiality, and non-repudiation where required.
Threat / Risk Addressed
Data, software, or credentials are modified, disclosed, or forged.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0028; RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-3299216-1-0031; RFQX-3299216-1-0036; RFQX-CVS123-2-0061; RFQX-CVS123-2-0063; RFQX-CVS123-2-0064; RFQX-CVS123-2-0065; RFQX-CVS123-2-0110; RFQX-CVS123-2-0111; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0114; RFQX-CVS123-2-0141; RFQX-CVS123-2-0143; RFQX-CVS123-2-0145 (sample: 18 of 183)
- Source document sections: source document page 7; source document page 9; source document page 10; source document page 11; source document page 16; source document page 18; source document page 19; source document page 25(sample: 8 of 67)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- See interface catalog; exact allocation needs confirmation.
Architecture Elements Involved
- Security Services
- Hardware Platform / HSM
- Application Software
Expected Mechanisms
- Encryption
- Signatures/MACs
- Integrity checks
- Key isolation
Explicit vs Inferred Status
Inferred from Requirements
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0028; RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-3299216-1-0031; RFQX-3299216-1-0036; RFQX-CVS123-2-0061; RFQX-CVS123-2-0063; RFQX-CVS123-2-0064; RFQX-CVS123-2-0065 (sample: 10 of 183)
- Source document: source document page 7; source document page 9; source document page 10; source document page 11; source document page 16; source document page 18; source document page 19; source document page 25(sample: 8 of 67)
- Confidence level: Low
- Classification: Inferred from Requirements
Security Capability: Secure Communication
Purpose
Protect vehicle, diagnostic, backend, and service data exchanges against tampering, spoofing, and replay.
Threat / Risk Addressed
Attacker injects, replays, modifies, or observes security-relevant traffic.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0031; RFQX-1001379436-P10-000-01-0032; RFQX-3299216-1-0006; RFQX-3299216-1-0042; RFQX-3299216-1-0079; RFQX-3299216-1-0088; RFQX-3299216-1-0092; RFQX-3299216-1-0094; RFQX-3299216-1-0095; RFQX-3299216-1-0100; RFQX-3299216-1-0135; RFQX-3299216-1-0147; RFQX-3299216-1-0158; RFQX-3299216-1-0164; RFQX-3299216-1-0167; RFQX-3299216-1-0170; RFQX-3299216-1-0215 (sample: 18 of 264)
- Source document sections: source document page 8; source document page 4; source document page 11; source document page 20; source document page 22; source document page 23; source document page 27; source document page 28(sample: 8 of 65)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- Vehicle network secure data communication interface
- Secure update, flash, and IVD interface
Architecture Elements Involved
- External Interfaces
- Application Software
- Security Services
Expected Mechanisms
- SecOC/SDT-style protection
- Freshness counters
- Replay protection
- Fail-closed discard rules
Explicit vs Inferred Status
Inferred from Requirements
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0031; RFQX-1001379436-P10-000-01-0032; RFQX-3299216-1-0006; RFQX-3299216-1-0042; RFQX-3299216-1-0079; RFQX-3299216-1-0088; RFQX-3299216-1-0092; RFQX-3299216-1-0094; RFQX-3299216-1-0095 (sample: 10 of 264)
- Source document: source document page 8; source document page 4; source document page 11; source document page 20; source document page 22; source document page 23; source document page 27; source document page 28(sample: 8 of 65)
- Confidence level: Low
- Classification: Inferred from Requirements
Purpose
Ensure only valid and authorized software executes on an ECU with an integrity-preserving platform.
Threat / Risk Addressed
Unauthorized software or tampered platform state is trusted.
Requirement Basis
- Related requirements: RFQX-3299216-1-0117; RFQX-3299216-1-0126; RFQX-3299216-1-0144; RFQX-CVS123-2-0009; RFQX-CVS123-2-0023; RFQX-CVS123-2-0024; RFQX-CVS123-2-0025; RFQX-CVS123-2-0027; RFQX-CVS123-2-0031; RFQX-CVS123-2-0035; RFQX-CVS123-2-0037; RFQX-CVS123-2-0039; RFQX-CVS123-2-0044; RFQX-CVS123-2-0045; RFQX-CVS123-2-0052; RFQX-CVS123-2-0053; RFQX-CVS123-2-0054; RFQX-CVS123-2-0055 (sample: 18 of 91)
- Source document sections: source document page 24; source document page 25; source document page 28; source document page 4; source document page 6; source document page 7; source document page 9; source document page 10(sample: 8 of 42)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- Vehicle network secure data communication interface
- Secure update, flash, and IVD interface
Architecture Elements Involved
- Hardware Platform
- Boot/Update Manager
- Security Services
Expected Mechanisms
- Secure boot
- Platform integrity checks
- Debug restrictions
- Authentic software checks
Explicit vs Inferred Status
Inferred from Requirements
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-3299216-1-0117; RFQX-3299216-1-0126; RFQX-3299216-1-0144; RFQX-CVS123-2-0009; RFQX-CVS123-2-0023; RFQX-CVS123-2-0024; RFQX-CVS123-2-0025; RFQX-CVS123-2-0027; RFQX-CVS123-2-0031; RFQX-CVS123-2-0035 (sample: 10 of 91)
- Source document: source document page 24; source document page 25; source document page 28; source document page 4; source document page 6; source document page 7; source document page 9; source document page 10(sample: 8 of 42)
- Confidence level: Low
- Classification: Inferred from Requirements
Security Capability: Secure Software Update
Purpose
Ensure update and flash content is authentic, intact, authorized, and traceable.
Threat / Risk Addressed
Malicious or wrong software is installed or update evidence is lost.
Requirement Basis
- Related requirements: RFQX-3299216-1-0176; RFQX-CVS123-2-0001; RFQX-CVS123-2-0004; RFQX-CVS123-2-0006; RFQX-CVS123-2-0007; RFQX-CVS123-2-0008; RFQX-CVS123-2-0013; RFQX-CVS123-2-0023; RFQX-CVS123-2-0026; RFQX-CVS123-2-0030; RFQX-CVS123-2-0031; RFQX-CVS123-2-0037; RFQX-CVS123-2-0039; RFQX-CVS123-2-0042; RFQX-CVS123-2-0043; RFQX-CVS123-2-0048; RFQX-CVS123-2-0049; RFQX-CVS123-2-0050 (sample: 18 of 131)
- Source document sections: source document page 34; source document page 1; source document page 4; source document page 6; source document page 7; source document page 9; source document page 10; source document page 11(sample: 8 of 56)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- Vehicle network secure data communication interface
- Secure update, flash, and IVD interface
- Application software to security services interface
Architecture Elements Involved
- Backend and IT Systems
- Boot/Update Manager
- Security Services
Expected Mechanisms
- Signed packages
- IVD checks
- Certificate validation
- Update logging
Explicit vs Inferred Status
Inferred from Requirements
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-3299216-1-0176; RFQX-CVS123-2-0001; RFQX-CVS123-2-0004; RFQX-CVS123-2-0006; RFQX-CVS123-2-0007; RFQX-CVS123-2-0008; RFQX-CVS123-2-0013; RFQX-CVS123-2-0023; RFQX-CVS123-2-0026; RFQX-CVS123-2-0030 (sample: 10 of 131)
- Source document: source document page 34; source document page 1; source document page 4; source document page 6; source document page 7; source document page 9; source document page 10; source document page 11(sample: 8 of 56)
- Confidence level: Low
- Classification: Inferred from Requirements
Security Capability: Secure Diagnostics
Purpose
Enable service access while preventing unauthorized diagnostic control.
Threat / Risk Addressed
Diagnostic service becomes a bypass for security controls.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-3299216-1-0107; RFQX-3299216-1-0126; RFQX-3299216-1-0127; RFQX-CVS123-2-0005; RFQX-CVS123-2-0009; RFQX-CVS123-2-0010; RFQX-CVS123-2-0013; RFQX-CVS123-2-0017; RFQX-CVS123-2-0023; RFQX-CVS123-2-0026; RFQX-CVS123-2-0028; RFQX-CVS123-2-0031; RFQX-CVS123-2-0034; RFQX-CVS123-2-0042; RFQX-CVS123-2-0047; RFQX-CVS123-2-0052 (sample: 18 of 572)
- Source document sections: source document page 8; source document page 23; source document page 25; source document page 4; source document page 5; source document page 6; source document page 7; source document page 9(sample: 8 of 137)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- Vehicle network secure data communication interface
- Secure update, flash, and IVD interface
Architecture Elements Involved
- Diagnostic Interface
- Security Services
- Application Software
Expected Mechanisms
- UDS authentication
- Access control
- Rate limiting
- Diagnostic audit
Explicit vs Inferred Status
Explicit Requirement
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-3299216-1-0107; RFQX-3299216-1-0126; RFQX-3299216-1-0127; RFQX-CVS123-2-0005; RFQX-CVS123-2-0009; RFQX-CVS123-2-0010; RFQX-CVS123-2-0013; RFQX-CVS123-2-0017 (sample: 10 of 572)
- Source document: source document page 8; source document page 23; source document page 25; source document page 4; source document page 5; source document page 6; source document page 7; source document page 9(sample: 8 of 137)
- Confidence level: Low
- Classification: Explicit Requirement
Security Capability: Key and Certificate Management
Purpose
Maintain trustworthy cryptographic identities and secrets across lifecycle.
Threat / Risk Addressed
Compromised trust material invalidates multiple controls.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-CVS123-2-0090; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0295; RFQX-CVS123-2-0296; RFQX-CVS124-0072; RFQX-CVS124-0118; RFQX-CVS124-0119; RFQX-CVS124-0122; RFQX-CVS124-0123; RFQX-CVS124-0126; RFQX-CVS124-0127; RFQX-CVS124-0156; RFQX-CVS124-0160; RFQX-CVS124-0161; RFQX-CVS124-0162 (sample: 18 of 125)
- Source document sections: source document page 9; source document page 14; source document page 16; source document page 37; source document page 22; source document page 30; source document page 34; source document page 40(sample: 8 of 40)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
Interfaces Protected
- OEM/customer cybersecurity approval and evidence interface
- Secure update, flash, and IVD interface
- Certificate and key provisioning interface
- Development, ALM, and evidence tooling interface
- Security operations and vulnerability reporting interface
- Hardware platform and key storage interface
Architecture Elements Involved
- Security Services
- PKI/Provisioning
- Hardware Platform
Expected Mechanisms
- PKI lifecycle
- Trust-anchor management
- Secure provisioning
- Protected key storage
Explicit vs Inferred Status
Explicit Requirement
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-CVS123-2-0090; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0295; RFQX-CVS123-2-0296; RFQX-CVS124-0072; RFQX-CVS124-0118; RFQX-CVS124-0119 (sample: 10 of 125)
- Source document: source document page 9; source document page 14; source document page 16; source document page 37; source document page 22; source document page 30; source document page 34; source document page 40(sample: 8 of 40)
- Confidence level: Low
- Classification: Explicit Requirement
Security Capability: Logging and Audit
Purpose
Record security-relevant activity for accountability, evidence, and investigation.
Threat / Risk Addressed
Security events cannot be investigated or evidenced.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0134; RFQX-3299216-1-0136; RFQX-3299216-1-0181; RFQX-3299216-1-0192; RFQX-3299216-1-0281; RFQX-3299216-1-0286; RFQX-3299216-1-0288; RFQX-CVS123-2-0067; RFQX-CVS123-2-0143; RFQX-CVS123-2-0144; RFQX-CVS123-2-0207; RFQX-CVS123-2-0212 (sample: 18 of 69)
- Source document sections: source document page 3; source document page 6; source document page 7; source document page 12; source document page 27; source document page 36; source document page 49; source document page 50(sample: 8 of 43)
Protected Assets
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- OEM/customer cybersecurity approval and evidence interface
- Secure update, flash, and IVD interface
- Certificate and key provisioning interface
- Development, ALM, and evidence tooling interface
- Security operations and vulnerability reporting interface
- Hardware platform and key storage interface
Architecture Elements Involved
- Security Services
- Backend/SecOps
- Evidence Repository
Expected Mechanisms
- Security event logging
- Evidence retention
- Audit trail
- Traceability IDs
Explicit vs Inferred Status
Explicit Requirement
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0134; RFQX-3299216-1-0136; RFQX-3299216-1-0181; RFQX-3299216-1-0192 (sample: 10 of 69)
- Source document: source document page 3; source document page 6; source document page 7; source document page 12; source document page 27; source document page 36; source document page 49; source document page 50(sample: 8 of 43)
- Confidence level: Low
- Classification: Explicit Requirement
Security Capability: Security Monitoring and Detection
Purpose
Identify security-relevant anomalies or events that need response.
Threat / Risk Addressed
Attacks or control failures remain invisible.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0058; RFQX-1001379436-P10-000-01-0059; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0137; RFQX-3299216-1-0139; RFQX-3299216-1-0144; RFQX-3299216-1-0165; RFQX-3299216-1-0181; RFQX-3299216-1-0194; RFQX-CVS123-2-0031; RFQX-CVS123-2-0153; RFQX-CVS123-2-0188; RFQX-CVS123-2-0253; RFQX-CVS123-2-0259; RFQX-CVS123-2-0261; RFQX-CVS124-0086; RFQX-CVS124-0266; RFQX-CVS124-0344 (sample: 18 of 20)
- Source document sections: source document page 11; source document page 12; source document page 27; source document page 28; source document page 31; source document page 36; source document page 7; source document page 20(sample: 8 of 15)
Protected Assets
- ECU software and firmware
- Diagnostic access state
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- OEM/customer cybersecurity approval and evidence interface
- Security operations and vulnerability reporting interface
- Application software to security services interface
Architecture Elements Involved
- Security Services
- Backend/SecOps
- Logging Path
Expected Mechanisms
- Security event collection
- Alert triage
- Detection rules
- Escalation path
Explicit vs Inferred Status
Inferred from Requirements
Confidence Level
Medium
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0058; RFQX-1001379436-P10-000-01-0059; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0137; RFQX-3299216-1-0139; RFQX-3299216-1-0144; RFQX-3299216-1-0165; RFQX-3299216-1-0181; RFQX-3299216-1-0194; RFQX-CVS123-2-0031 (sample: 10 of 20)
- Source document: source document page 11; source document page 12; source document page 27; source document page 28; source document page 31; source document page 36; source document page 7; source document page 20(sample: 8 of 15)
- Confidence level: Medium
- Classification: Inferred from Requirements
Security Capability: Vulnerability and Incident Handling
Purpose
Assess, treat, communicate, and track vulnerabilities and incidents over releases.
Threat / Risk Addressed
Known vulnerabilities or incidents remain untreated.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0051; RFQX-1001379436-P10-000-01-0054; RFQX-1001379436-P10-000-01-0055; RFQX-1001379436-P10-000-01-0056; RFQX-1001379436-P10-000-01-0058
- Source document sections: source document page 3; source document page 5; source document page 6; source document page 10; source document page 11
Protected Assets
- ECU software and firmware
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- OEM/customer cybersecurity approval and evidence interface
- Secure update, flash, and IVD interface
- Certificate and key provisioning interface
- Development, ALM, and evidence tooling interface
- Security operations and vulnerability reporting interface
- Hardware platform and key storage interface
Architecture Elements Involved
- Compliance Process
- Security Operations
- Engineering Toolchain
Expected Mechanisms
- Vulnerability intake
- Risk treatment
- Incident workflow
- Mitigation verification
Explicit vs Inferred Status
Explicit Requirement
Confidence Level
High
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0051 (sample: 10 of 14)
- Source document: source document page 3; source document page 5; source document page 6; source document page 10; source document page 11
- Confidence level: High
- Classification: Explicit Requirement
Purpose
Protect the engineering environment and evidence chain that produce security-relevant artifacts.
Threat / Risk Addressed
Compromised tooling produces compromised products or false evidence.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0034; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0059; RFQX-3299216-1-0034; RFQX-3299216-1-0035; RFQX-3299216-1-0036; RFQX-3299216-1-0039; RFQX-3299216-1-0040; RFQX-3299216-1-0070; RFQX-3299216-1-0126; RFQX-3299216-1-0135; RFQX-3299216-1-0141; RFQX-3299216-1-0156 (sample: 18 of 102)
- Source document sections: source document page 5; source document page 7; source document page 8; source document page 10; source document page 11; source document page 10; source document page 11; source document page 16(sample: 8 of 65)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
Interfaces Protected
- OEM/customer cybersecurity approval and evidence interface
- Secure update, flash, and IVD interface
- Certificate and key provisioning interface
- Development, ALM, and evidence tooling interface
- Security operations and vulnerability reporting interface
- Hardware platform and key storage interface
Architecture Elements Involved
- Engineering Toolchain
- ALM/CI
- Evidence Repository
Expected Mechanisms
- Access control
- Artifact integrity
- Review workflow
- Build/test evidence
Explicit vs Inferred Status
Inferred from Requirements
Confidence Level
Medium
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0034; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0059; RFQX-3299216-1-0034; RFQX-3299216-1-0035 (sample: 10 of 102)
- Source document: source document page 5; source document page 7; source document page 8; source document page 10; source document page 11; source document page 10; source document page 11; source document page 16(sample: 8 of 65)
- Confidence level: Medium
- Classification: Inferred from Requirements
Security Capability: Backend/Cloud Security
Purpose
Protect offboard systems that influence update, evidence, monitoring, and operational security.
Threat / Risk Addressed
Offboard compromise affects products, updates, evidence, or operational data.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0022 (sample: 18 of 1033)
- Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 230)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- Backend/cloud/IT operational interface
Architecture Elements Involved
- Backend and IT Systems
- External Interfaces
- Security Operations
Expected Mechanisms
- Mutual authentication
- Network segregation
- API authorization
- Backend audit logging
Explicit vs Inferred Status
Inferred from Requirements
Confidence Level
Low
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013 (sample: 10 of 1033)
- Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 230)
- Confidence level: Low
- Classification: Inferred from Requirements
Security Capability: Compliance and Evidence Management
Purpose
Demonstrate that requirements, controls, verification, validation, and residual risk remain traceable.
Threat / Risk Addressed
Customer cannot verify that security obligations are met.
Requirement Basis
- Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0021; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0027; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-3299216-1-0018; RFQX-3299216-1-0036; RFQX-3299216-1-0041; RFQX-3299216-1-0042; RFQX-3299216-1-0070 (sample: 18 of 142)
- Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 10; source document page 5; source document page 10; source document page 11(sample: 8 of 86)
Protected Assets
- Vehicle function data
- ECU software and firmware
- Cryptographic keys and certificates
- Diagnostic access state
- Cybersecurity concept and evidence
- Backend/update and security operations data
- Hardware platform integrity
Interfaces Protected
- OEM/customer cybersecurity approval and evidence interface
- Secure update, flash, and IVD interface
- Certificate and key provisioning interface
- Development, ALM, and evidence tooling interface
- Security operations and vulnerability reporting interface
- Hardware platform and key storage interface
Architecture Elements Involved
- Compliance Process
- Engineering Toolchain
- OEM/Customer Interface
Expected Mechanisms
- Requirement traceability
- Control mapping
- V&V reports
- Residual-risk approval records
Explicit vs Inferred Status
Explicit Requirement
Confidence Level
Medium
Open Decisions
- Confirm concrete mechanisms, ownership, parameters, and verification evidence.
Evidence Basis:
- Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0021; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0027 (sample: 10 of 142)
- Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 10; source document page 5; source document page 10; source document page 11(sample: 8 of 86)
- Confidence level: Medium
- Classification: Explicit Requirement