Security Architecture Map

Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.

Last updated: 2026-06-29 11:49
RTRFQX Review TeamWorkspace

Security Architecture Map

Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.

Security Capability Matrix

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Security CapabilityProtectsApplied ToMechanismEvidenceOpen Decision
Secure Diagnostics and RBACDiagnostic access state and privileged servicesDiagnostic Tester Interface / Diagnostic ServerUDS Auth 0x29, authorization, lockout and auditStrongConfirm final role model and service list
Secure Software UpdateECU software and firmware authenticityBootloader / Update LogicSigned packages, integrity validation, rollback control and update loggingStrongConfirm signing chain, rollback and campaign ownership
Data Authenticity and Integrity VerificationSecurity-relevant vehicle dataVehicle Network / Secure Data Transfer InterfaceSecOC/SDT-style MAC, freshness and replay rejectionModerateConfirm protected signal allocation
Key and Certificate HandlingKeys, certificates and trust anchorsSecurity Services / Hardware Platform / PKIProvisioning, validation, protected storage and renewal/revocationStrongConfirm HSM capability and PKI ownership
Communication Boundary ControlVehicle and offboard interface boundariesExternal Interfaces / Security ServicesInput validation, boundary filtering and fail-safe discard behaviourModerateConfirm exact boundaries and failure policy
Security LoggingSecurity event evidenceLogging / Event Reporting InterfaceEvent capture, retention, integrity and reportingModerateConfirm event set and reporting channel
Vulnerability and Incident HandlingField security postureSecurity Operations / Compliance ProcessVulnerability intake, triage, mitigation and incident workflowStrongConfirm reporting channels and responsibilities
Cybersecurity Evidence and DIAApproval and residual-risk caseEngineering Toolchain / OEM Approval InterfaceTraceability, V&V evidence, decision logging and residual-risk approvalStrongConfirm DIA split and authority

Security Capability Map

flowchart LR subgraph Protect["Protected areas"] Data["Vehicle data"] Software["ECU software"] Diag["Diagnostic access"] Trust["Keys and certificates"] Evidence["Security evidence"] end subgraph Capabilities["Security capabilities"] Comms["Secure communication"] UpdateSec["Secure update"] RBAC["Diagnostics RBAC"] KeyMgmt["Key / certificate management"] Audit["Logging and evidence"] end Comms --> Data UpdateSec --> Software RBAC --> Diag KeyMgmt --> Trust Audit --> Evidence
Mermaid source
flowchart LR
  subgraph Protect["Protected areas"]
    Data["Vehicle data"]
    Software["ECU software"]
    Diag["Diagnostic access"]
    Trust["Keys and certificates"]
    Evidence["Security evidence"]
  end
  subgraph Capabilities["Security capabilities"]
    Comms["Secure communication"]
    UpdateSec["Secure update"]
    RBAC["Diagnostics RBAC"]
    KeyMgmt["Key / certificate management"]
    Audit["Logging and evidence"]
  end
  Comms --> Data
  UpdateSec --> Software
  RBAC --> Diag
  KeyMgmt --> Trust
  Audit --> Evidence

Protected Asset Table

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

AssetThreat ExposureProtection StrategyEvidenceOpen Decision
Clutch control behaviourCommand spoofing, unsafe state or malformed dataCommand validation, authenticated/fresh messages where allocated, diagnostic authorizationConfirmed function; security allocation inferredConfirm protected signal set
ECU software and firmwareTampered or wrong software installedSigned update, IVD/integrity checks, secure boot/platform integrityStrong update/flash evidenceConfirm signing chain and rollback
Keys, certificates and trust anchorsCredential theft or invalid trust decisionsProtected storage, certificate validation, lifecycle managementStrong key/certificate evidenceConfirm HSM and PKI owner
Diagnostic access stateUnauthorized privileged service accessUDS Auth 0x29, RBAC, lockout and auditStrong diagnostic evidenceConfirm role model
Security evidence and decisionsUntrusted evidence or unapproved residual riskTraceability, review workflow and decision loggingStrong process evidenceConfirm approval authority

Attack Surface Table

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Attack SurfaceEntry PointRequired ControlsEvidenceStatus
Vehicle networkCAN / PWM command and status pathMessage validation, authenticity/freshness where allocated, safe discardCAN/PWM requirements and SecOC/SDT evidenceRequires confirmation
Diagnostic accessUDS tester and programming servicesAuthentication, authorization, lockout, rate limiting and auditUDS/Auth 0x29 evidenceRequires confirmation
Software update / flashProgramming/update package pathSignature validation, IVD/integrity checks, rollback and loggingFlash/update evidenceRequires confirmation
PKI / provisioningKey and certificate injection or renewal pathProtected storage, certificate validation, ownership and revocation controlsKey/certificate evidenceRequires confirmation
Supplier engineering evidenceALM, CI/test and evidence repositoryAccess control, artifact integrity and audit trailCybersecurity concept/evidence requirementsRequires confirmation

Security Decision Table

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

ConclusionStatusEvidenceImpactDecision Needed
ECA ECU product identity and AMT platform contextConfirmedsource document function statements; source documentStabilizes review-board namingConfirm final product designation/variant
Cybersecurity concept and evidence package are in scopeConfirmedCybersecurity and process requirementsMakes this an architecture/security baseline, not a brochureConfirm approval workflow
Secure diagnostics, update and key/certificate handling apply to the ECUInferredUDS, flash/IVD and certificate/key requirementsDrives security services and trust-boundary designConfirm exact allocation
SecOC/SDT-style protection is needed for selected data flowsRequires ConfirmationSecure communication requirementsBlocks final interface-security allocationCustomer must identify protected signals
Asset Model

Asset: Vehicle function data

Classification: Inferred from Requirements

Why It Needs Protection

Compromise affects product security goals, customer evidence, or lifecycle operations.

Evidence Basis:

  • Related requirements: RFQX-3299216-1-0006; RFQX-3299216-1-0079; RFQX-3299216-1-0088; RFQX-3299216-1-0094; RFQX-3299216-1-0095; RFQX-3299216-1-0100; RFQX-3299216-1-0135; RFQX-3299216-1-0164; RFQX-3299216-1-0167; RFQX-3299216-1-0170 (sample: 10 of 55)
  • Source document: source document page 4; source document page 20; source document page 22; source document page 23; source document page 27; source document page 31; source document page 33; source document page 6(sample: 8 of 36)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Asset: ECU software and firmware

Classification: Explicit Requirement

Why It Needs Protection

Compromise affects product security goals, customer evidence, or lifecycle operations.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0021; RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0027; RFQX-1001379436-P10-000-01-0045; RFQX-1001379436-P10-000-01-0056; RFQX-3299216-1-0061; RFQX-3299216-1-0075; RFQX-3299216-1-0137 (sample: 10 of 362)
  • Source document: source document page 5; source document page 6; source document page 7; source document page 9; source document page 11; source document page 15; source document page 19; source document page 27(sample: 8 of 130)
  • Confidence level: Low
  • Classification: Explicit Requirement

Asset: Cryptographic keys and certificates

Classification: Explicit Requirement

Why It Needs Protection

Compromise affects product security goals, customer evidence, or lifecycle operations.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-CVS123-2-0090; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0295; RFQX-CVS123-2-0296; RFQX-CVS124-0072; RFQX-CVS124-0118; RFQX-CVS124-0119 (sample: 10 of 125)
  • Source document: source document page 9; source document page 14; source document page 16; source document page 37; source document page 22; source document page 30; source document page 34; source document page 40(sample: 8 of 40)
  • Confidence level: Low
  • Classification: Explicit Requirement

Asset: Diagnostic access state

Classification: Explicit Requirement

Why It Needs Protection

Compromise affects product security goals, customer evidence, or lifecycle operations.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-3299216-1-0107; RFQX-3299216-1-0126; RFQX-3299216-1-0127; RFQX-CVS123-2-0005; RFQX-CVS123-2-0009; RFQX-CVS123-2-0010; RFQX-CVS123-2-0013; RFQX-CVS123-2-0017 (sample: 10 of 575)
  • Source document: source document page 8; source document page 23; source document page 25; source document page 4; source document page 5; source document page 6; source document page 7; source document page 9(sample: 8 of 139)
  • Confidence level: Low
  • Classification: Explicit Requirement

Asset: Cybersecurity concept and evidence

Classification: Explicit Requirement

Why It Needs Protection

Compromise affects product security goals, customer evidence, or lifecycle operations.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0021; RFQX-1001379436-P10-000-01-0023 (sample: 10 of 60)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 5; source document page 23; source document page 27; source document page 50(sample: 8 of 34)
  • Confidence level: Medium
  • Classification: Explicit Requirement

Asset: Backend/update and security operations data

Classification: Inferred from Requirements

Why It Needs Protection

Compromise affects product security goals, customer evidence, or lifecycle operations.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0051; RFQX-1001379436-P10-000-01-0054; RFQX-1001379436-P10-000-01-0055; RFQX-1001379436-P10-000-01-0056; RFQX-1001379436-P10-000-01-0058 (sample: 10 of 497)
  • Source document: source document page 5; source document page 10; source document page 11; source document page 12; source document page 9; source document page 10; source document page 11; source document page 12(sample: 8 of 155)
  • Confidence level: Medium
  • Classification: Inferred from Requirements

Asset: Hardware platform integrity

Classification: Inferred from Requirements

Why It Needs Protection

Compromise affects product security goals, customer evidence, or lifecycle operations.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0022; RFQX-1001379436-P10-000-01-0027; RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0036; RFQX-1001379436-P10-000-01-0056 (sample: 10 of 104)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 11; source document page 12; source document page 4(sample: 8 of 68)
  • Confidence level: Low
  • Classification: Inferred from Requirements
Security Capability Model

Security Capability: Identity and Access Control

Purpose

Ensure only authorized tools, systems, users, and software actors can perform security-relevant actions.

Threat / Risk Addressed

Unauthorized actor gains privileged access.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0044; RFQX-3299216-1-0135; RFQX-3299216-1-0141; RFQX-CVS123-2-0005; RFQX-CVS123-2-0017; RFQX-CVS123-2-0023; RFQX-CVS123-2-0078; RFQX-CVS123-2-0079; RFQX-CVS123-2-0097; RFQX-CVS123-2-0099; RFQX-CVS123-2-0123; RFQX-CVS123-2-0158; RFQX-CVS123-2-0200; RFQX-CVS124-0061; RFQX-CVS124-0083; RFQX-CVS124-0305; RFQX-CVS124-0306 (sample: 18 of 312)
  • Source document sections: source document page 7; source document page 9; source document page 27; source document page 4; source document page 5; source document page 6; source document page 12; source document page 14(sample: 8 of 66)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • OEM/customer cybersecurity approval and evidence interface
  • Secure update, flash, and IVD interface
  • Certificate and key provisioning interface
  • Development, ALM, and evidence tooling interface
  • Security operations and vulnerability reporting interface
  • Hardware platform and key storage interface

Architecture Elements Involved

  • Security Services
  • Diagnostic Server
  • Backend/PKI

Expected Mechanisms

  • Authentication
  • Authorization
  • Secure sessions
  • Role or certificate validation

Explicit vs Inferred Status

Explicit Requirement

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0044; RFQX-3299216-1-0135; RFQX-3299216-1-0141; RFQX-CVS123-2-0005; RFQX-CVS123-2-0017; RFQX-CVS123-2-0023; RFQX-CVS123-2-0078; RFQX-CVS123-2-0079; RFQX-CVS123-2-0097 (sample: 10 of 312)
  • Source document: source document page 7; source document page 9; source document page 27; source document page 4; source document page 5; source document page 6; source document page 12; source document page 14(sample: 8 of 66)
  • Confidence level: Low
  • Classification: Explicit Requirement

Security Capability: Cryptographic Protection

Purpose

Provide authenticity, integrity, confidentiality, and non-repudiation where required.

Threat / Risk Addressed

Data, software, or credentials are modified, disclosed, or forged.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0028; RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-3299216-1-0031; RFQX-3299216-1-0036; RFQX-CVS123-2-0061; RFQX-CVS123-2-0063; RFQX-CVS123-2-0064; RFQX-CVS123-2-0065; RFQX-CVS123-2-0110; RFQX-CVS123-2-0111; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0114; RFQX-CVS123-2-0141; RFQX-CVS123-2-0143; RFQX-CVS123-2-0145 (sample: 18 of 183)
  • Source document sections: source document page 7; source document page 9; source document page 10; source document page 11; source document page 16; source document page 18; source document page 19; source document page 25(sample: 8 of 67)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • See interface catalog; exact allocation needs confirmation.

Architecture Elements Involved

  • Security Services
  • Hardware Platform / HSM
  • Application Software

Expected Mechanisms

  • Encryption
  • Signatures/MACs
  • Integrity checks
  • Key isolation

Explicit vs Inferred Status

Inferred from Requirements

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0028; RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-3299216-1-0031; RFQX-3299216-1-0036; RFQX-CVS123-2-0061; RFQX-CVS123-2-0063; RFQX-CVS123-2-0064; RFQX-CVS123-2-0065 (sample: 10 of 183)
  • Source document: source document page 7; source document page 9; source document page 10; source document page 11; source document page 16; source document page 18; source document page 19; source document page 25(sample: 8 of 67)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Security Capability: Secure Communication

Purpose

Protect vehicle, diagnostic, backend, and service data exchanges against tampering, spoofing, and replay.

Threat / Risk Addressed

Attacker injects, replays, modifies, or observes security-relevant traffic.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0031; RFQX-1001379436-P10-000-01-0032; RFQX-3299216-1-0006; RFQX-3299216-1-0042; RFQX-3299216-1-0079; RFQX-3299216-1-0088; RFQX-3299216-1-0092; RFQX-3299216-1-0094; RFQX-3299216-1-0095; RFQX-3299216-1-0100; RFQX-3299216-1-0135; RFQX-3299216-1-0147; RFQX-3299216-1-0158; RFQX-3299216-1-0164; RFQX-3299216-1-0167; RFQX-3299216-1-0170; RFQX-3299216-1-0215 (sample: 18 of 264)
  • Source document sections: source document page 8; source document page 4; source document page 11; source document page 20; source document page 22; source document page 23; source document page 27; source document page 28(sample: 8 of 65)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • Vehicle network secure data communication interface
  • Secure update, flash, and IVD interface

Architecture Elements Involved

  • External Interfaces
  • Application Software
  • Security Services

Expected Mechanisms

  • SecOC/SDT-style protection
  • Freshness counters
  • Replay protection
  • Fail-closed discard rules

Explicit vs Inferred Status

Inferred from Requirements

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0031; RFQX-1001379436-P10-000-01-0032; RFQX-3299216-1-0006; RFQX-3299216-1-0042; RFQX-3299216-1-0079; RFQX-3299216-1-0088; RFQX-3299216-1-0092; RFQX-3299216-1-0094; RFQX-3299216-1-0095 (sample: 10 of 264)
  • Source document: source document page 8; source document page 4; source document page 11; source document page 20; source document page 22; source document page 23; source document page 27; source document page 28(sample: 8 of 65)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Security Capability: Secure Boot and Platform Integrity

Purpose

Ensure only valid and authorized software executes on an ECU with an integrity-preserving platform.

Threat / Risk Addressed

Unauthorized software or tampered platform state is trusted.

Requirement Basis

  • Related requirements: RFQX-3299216-1-0117; RFQX-3299216-1-0126; RFQX-3299216-1-0144; RFQX-CVS123-2-0009; RFQX-CVS123-2-0023; RFQX-CVS123-2-0024; RFQX-CVS123-2-0025; RFQX-CVS123-2-0027; RFQX-CVS123-2-0031; RFQX-CVS123-2-0035; RFQX-CVS123-2-0037; RFQX-CVS123-2-0039; RFQX-CVS123-2-0044; RFQX-CVS123-2-0045; RFQX-CVS123-2-0052; RFQX-CVS123-2-0053; RFQX-CVS123-2-0054; RFQX-CVS123-2-0055 (sample: 18 of 91)
  • Source document sections: source document page 24; source document page 25; source document page 28; source document page 4; source document page 6; source document page 7; source document page 9; source document page 10(sample: 8 of 42)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • Vehicle network secure data communication interface
  • Secure update, flash, and IVD interface

Architecture Elements Involved

  • Hardware Platform
  • Boot/Update Manager
  • Security Services

Expected Mechanisms

  • Secure boot
  • Platform integrity checks
  • Debug restrictions
  • Authentic software checks

Explicit vs Inferred Status

Inferred from Requirements

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-3299216-1-0117; RFQX-3299216-1-0126; RFQX-3299216-1-0144; RFQX-CVS123-2-0009; RFQX-CVS123-2-0023; RFQX-CVS123-2-0024; RFQX-CVS123-2-0025; RFQX-CVS123-2-0027; RFQX-CVS123-2-0031; RFQX-CVS123-2-0035 (sample: 10 of 91)
  • Source document: source document page 24; source document page 25; source document page 28; source document page 4; source document page 6; source document page 7; source document page 9; source document page 10(sample: 8 of 42)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Security Capability: Secure Software Update

Purpose

Ensure update and flash content is authentic, intact, authorized, and traceable.

Threat / Risk Addressed

Malicious or wrong software is installed or update evidence is lost.

Requirement Basis

  • Related requirements: RFQX-3299216-1-0176; RFQX-CVS123-2-0001; RFQX-CVS123-2-0004; RFQX-CVS123-2-0006; RFQX-CVS123-2-0007; RFQX-CVS123-2-0008; RFQX-CVS123-2-0013; RFQX-CVS123-2-0023; RFQX-CVS123-2-0026; RFQX-CVS123-2-0030; RFQX-CVS123-2-0031; RFQX-CVS123-2-0037; RFQX-CVS123-2-0039; RFQX-CVS123-2-0042; RFQX-CVS123-2-0043; RFQX-CVS123-2-0048; RFQX-CVS123-2-0049; RFQX-CVS123-2-0050 (sample: 18 of 131)
  • Source document sections: source document page 34; source document page 1; source document page 4; source document page 6; source document page 7; source document page 9; source document page 10; source document page 11(sample: 8 of 56)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • Vehicle network secure data communication interface
  • Secure update, flash, and IVD interface
  • Application software to security services interface

Architecture Elements Involved

  • Backend and IT Systems
  • Boot/Update Manager
  • Security Services

Expected Mechanisms

  • Signed packages
  • IVD checks
  • Certificate validation
  • Update logging

Explicit vs Inferred Status

Inferred from Requirements

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-3299216-1-0176; RFQX-CVS123-2-0001; RFQX-CVS123-2-0004; RFQX-CVS123-2-0006; RFQX-CVS123-2-0007; RFQX-CVS123-2-0008; RFQX-CVS123-2-0013; RFQX-CVS123-2-0023; RFQX-CVS123-2-0026; RFQX-CVS123-2-0030 (sample: 10 of 131)
  • Source document: source document page 34; source document page 1; source document page 4; source document page 6; source document page 7; source document page 9; source document page 10; source document page 11(sample: 8 of 56)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Security Capability: Secure Diagnostics

Purpose

Enable service access while preventing unauthorized diagnostic control.

Threat / Risk Addressed

Diagnostic service becomes a bypass for security controls.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-3299216-1-0107; RFQX-3299216-1-0126; RFQX-3299216-1-0127; RFQX-CVS123-2-0005; RFQX-CVS123-2-0009; RFQX-CVS123-2-0010; RFQX-CVS123-2-0013; RFQX-CVS123-2-0017; RFQX-CVS123-2-0023; RFQX-CVS123-2-0026; RFQX-CVS123-2-0028; RFQX-CVS123-2-0031; RFQX-CVS123-2-0034; RFQX-CVS123-2-0042; RFQX-CVS123-2-0047; RFQX-CVS123-2-0052 (sample: 18 of 572)
  • Source document sections: source document page 8; source document page 23; source document page 25; source document page 4; source document page 5; source document page 6; source document page 7; source document page 9(sample: 8 of 137)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • Vehicle network secure data communication interface
  • Secure update, flash, and IVD interface

Architecture Elements Involved

  • Diagnostic Interface
  • Security Services
  • Application Software

Expected Mechanisms

  • UDS authentication
  • Access control
  • Rate limiting
  • Diagnostic audit

Explicit vs Inferred Status

Explicit Requirement

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-3299216-1-0107; RFQX-3299216-1-0126; RFQX-3299216-1-0127; RFQX-CVS123-2-0005; RFQX-CVS123-2-0009; RFQX-CVS123-2-0010; RFQX-CVS123-2-0013; RFQX-CVS123-2-0017 (sample: 10 of 572)
  • Source document: source document page 8; source document page 23; source document page 25; source document page 4; source document page 5; source document page 6; source document page 7; source document page 9(sample: 8 of 137)
  • Confidence level: Low
  • Classification: Explicit Requirement

Security Capability: Key and Certificate Management

Purpose

Maintain trustworthy cryptographic identities and secrets across lifecycle.

Threat / Risk Addressed

Compromised trust material invalidates multiple controls.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-CVS123-2-0090; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0295; RFQX-CVS123-2-0296; RFQX-CVS124-0072; RFQX-CVS124-0118; RFQX-CVS124-0119; RFQX-CVS124-0122; RFQX-CVS124-0123; RFQX-CVS124-0126; RFQX-CVS124-0127; RFQX-CVS124-0156; RFQX-CVS124-0160; RFQX-CVS124-0161; RFQX-CVS124-0162 (sample: 18 of 125)
  • Source document sections: source document page 9; source document page 14; source document page 16; source document page 37; source document page 22; source document page 30; source document page 34; source document page 40(sample: 8 of 40)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data

Interfaces Protected

  • OEM/customer cybersecurity approval and evidence interface
  • Secure update, flash, and IVD interface
  • Certificate and key provisioning interface
  • Development, ALM, and evidence tooling interface
  • Security operations and vulnerability reporting interface
  • Hardware platform and key storage interface

Architecture Elements Involved

  • Security Services
  • PKI/Provisioning
  • Hardware Platform

Expected Mechanisms

  • PKI lifecycle
  • Trust-anchor management
  • Secure provisioning
  • Protected key storage

Explicit vs Inferred Status

Explicit Requirement

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-CVS123-2-0090; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0295; RFQX-CVS123-2-0296; RFQX-CVS124-0072; RFQX-CVS124-0118; RFQX-CVS124-0119 (sample: 10 of 125)
  • Source document: source document page 9; source document page 14; source document page 16; source document page 37; source document page 22; source document page 30; source document page 34; source document page 40(sample: 8 of 40)
  • Confidence level: Low
  • Classification: Explicit Requirement

Security Capability: Logging and Audit

Purpose

Record security-relevant activity for accountability, evidence, and investigation.

Threat / Risk Addressed

Security events cannot be investigated or evidenced.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0134; RFQX-3299216-1-0136; RFQX-3299216-1-0181; RFQX-3299216-1-0192; RFQX-3299216-1-0281; RFQX-3299216-1-0286; RFQX-3299216-1-0288; RFQX-CVS123-2-0067; RFQX-CVS123-2-0143; RFQX-CVS123-2-0144; RFQX-CVS123-2-0207; RFQX-CVS123-2-0212 (sample: 18 of 69)
  • Source document sections: source document page 3; source document page 6; source document page 7; source document page 12; source document page 27; source document page 36; source document page 49; source document page 50(sample: 8 of 43)

Protected Assets

  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • OEM/customer cybersecurity approval and evidence interface
  • Secure update, flash, and IVD interface
  • Certificate and key provisioning interface
  • Development, ALM, and evidence tooling interface
  • Security operations and vulnerability reporting interface
  • Hardware platform and key storage interface

Architecture Elements Involved

  • Security Services
  • Backend/SecOps
  • Evidence Repository

Expected Mechanisms

  • Security event logging
  • Evidence retention
  • Audit trail
  • Traceability IDs

Explicit vs Inferred Status

Explicit Requirement

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0134; RFQX-3299216-1-0136; RFQX-3299216-1-0181; RFQX-3299216-1-0192 (sample: 10 of 69)
  • Source document: source document page 3; source document page 6; source document page 7; source document page 12; source document page 27; source document page 36; source document page 49; source document page 50(sample: 8 of 43)
  • Confidence level: Low
  • Classification: Explicit Requirement

Security Capability: Security Monitoring and Detection

Purpose

Identify security-relevant anomalies or events that need response.

Threat / Risk Addressed

Attacks or control failures remain invisible.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0058; RFQX-1001379436-P10-000-01-0059; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0137; RFQX-3299216-1-0139; RFQX-3299216-1-0144; RFQX-3299216-1-0165; RFQX-3299216-1-0181; RFQX-3299216-1-0194; RFQX-CVS123-2-0031; RFQX-CVS123-2-0153; RFQX-CVS123-2-0188; RFQX-CVS123-2-0253; RFQX-CVS123-2-0259; RFQX-CVS123-2-0261; RFQX-CVS124-0086; RFQX-CVS124-0266; RFQX-CVS124-0344 (sample: 18 of 20)
  • Source document sections: source document page 11; source document page 12; source document page 27; source document page 28; source document page 31; source document page 36; source document page 7; source document page 20(sample: 8 of 15)

Protected Assets

  • ECU software and firmware
  • Diagnostic access state
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • OEM/customer cybersecurity approval and evidence interface
  • Security operations and vulnerability reporting interface
  • Application software to security services interface

Architecture Elements Involved

  • Security Services
  • Backend/SecOps
  • Logging Path

Expected Mechanisms

  • Security event collection
  • Alert triage
  • Detection rules
  • Escalation path

Explicit vs Inferred Status

Inferred from Requirements

Confidence Level

Medium

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0058; RFQX-1001379436-P10-000-01-0059; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0137; RFQX-3299216-1-0139; RFQX-3299216-1-0144; RFQX-3299216-1-0165; RFQX-3299216-1-0181; RFQX-3299216-1-0194; RFQX-CVS123-2-0031 (sample: 10 of 20)
  • Source document: source document page 11; source document page 12; source document page 27; source document page 28; source document page 31; source document page 36; source document page 7; source document page 20(sample: 8 of 15)
  • Confidence level: Medium
  • Classification: Inferred from Requirements

Security Capability: Vulnerability and Incident Handling

Purpose

Assess, treat, communicate, and track vulnerabilities and incidents over releases.

Threat / Risk Addressed

Known vulnerabilities or incidents remain untreated.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0051; RFQX-1001379436-P10-000-01-0054; RFQX-1001379436-P10-000-01-0055; RFQX-1001379436-P10-000-01-0056; RFQX-1001379436-P10-000-01-0058
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 10; source document page 11

Protected Assets

  • ECU software and firmware
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • OEM/customer cybersecurity approval and evidence interface
  • Secure update, flash, and IVD interface
  • Certificate and key provisioning interface
  • Development, ALM, and evidence tooling interface
  • Security operations and vulnerability reporting interface
  • Hardware platform and key storage interface

Architecture Elements Involved

  • Compliance Process
  • Security Operations
  • Engineering Toolchain

Expected Mechanisms

  • Vulnerability intake
  • Risk treatment
  • Incident workflow
  • Mitigation verification

Explicit vs Inferred Status

Explicit Requirement

Confidence Level

High

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0051 (sample: 10 of 14)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 10; source document page 11
  • Confidence level: High
  • Classification: Explicit Requirement

Security Capability: Development and Toolchain Security

Purpose

Protect the engineering environment and evidence chain that produce security-relevant artifacts.

Threat / Risk Addressed

Compromised tooling produces compromised products or false evidence.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0034; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0059; RFQX-3299216-1-0034; RFQX-3299216-1-0035; RFQX-3299216-1-0036; RFQX-3299216-1-0039; RFQX-3299216-1-0040; RFQX-3299216-1-0070; RFQX-3299216-1-0126; RFQX-3299216-1-0135; RFQX-3299216-1-0141; RFQX-3299216-1-0156 (sample: 18 of 102)
  • Source document sections: source document page 5; source document page 7; source document page 8; source document page 10; source document page 11; source document page 10; source document page 11; source document page 16(sample: 8 of 65)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data

Interfaces Protected

  • OEM/customer cybersecurity approval and evidence interface
  • Secure update, flash, and IVD interface
  • Certificate and key provisioning interface
  • Development, ALM, and evidence tooling interface
  • Security operations and vulnerability reporting interface
  • Hardware platform and key storage interface

Architecture Elements Involved

  • Engineering Toolchain
  • ALM/CI
  • Evidence Repository

Expected Mechanisms

  • Access control
  • Artifact integrity
  • Review workflow
  • Build/test evidence

Explicit vs Inferred Status

Inferred from Requirements

Confidence Level

Medium

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0034; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0059; RFQX-3299216-1-0034; RFQX-3299216-1-0035 (sample: 10 of 102)
  • Source document: source document page 5; source document page 7; source document page 8; source document page 10; source document page 11; source document page 10; source document page 11; source document page 16(sample: 8 of 65)
  • Confidence level: Medium
  • Classification: Inferred from Requirements

Security Capability: Backend/Cloud Security

Purpose

Protect offboard systems that influence update, evidence, monitoring, and operational security.

Threat / Risk Addressed

Offboard compromise affects products, updates, evidence, or operational data.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0022 (sample: 18 of 1033)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 230)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • Backend/cloud/IT operational interface

Architecture Elements Involved

  • Backend and IT Systems
  • External Interfaces
  • Security Operations

Expected Mechanisms

  • Mutual authentication
  • Network segregation
  • API authorization
  • Backend audit logging

Explicit vs Inferred Status

Inferred from Requirements

Confidence Level

Low

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013 (sample: 10 of 1033)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 230)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Security Capability: Compliance and Evidence Management

Purpose

Demonstrate that requirements, controls, verification, validation, and residual risk remain traceable.

Threat / Risk Addressed

Customer cannot verify that security obligations are met.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0021; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0027; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-3299216-1-0018; RFQX-3299216-1-0036; RFQX-3299216-1-0041; RFQX-3299216-1-0042; RFQX-3299216-1-0070 (sample: 18 of 142)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 10; source document page 5; source document page 10; source document page 11(sample: 8 of 86)

Protected Assets

  • Vehicle function data
  • ECU software and firmware
  • Cryptographic keys and certificates
  • Diagnostic access state
  • Cybersecurity concept and evidence
  • Backend/update and security operations data
  • Hardware platform integrity

Interfaces Protected

  • OEM/customer cybersecurity approval and evidence interface
  • Secure update, flash, and IVD interface
  • Certificate and key provisioning interface
  • Development, ALM, and evidence tooling interface
  • Security operations and vulnerability reporting interface
  • Hardware platform and key storage interface

Architecture Elements Involved

  • Compliance Process
  • Engineering Toolchain
  • OEM/Customer Interface

Expected Mechanisms

  • Requirement traceability
  • Control mapping
  • V&V reports
  • Residual-risk approval records

Explicit vs Inferred Status

Explicit Requirement

Confidence Level

Medium

Open Decisions

  • Confirm concrete mechanisms, ownership, parameters, and verification evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0021; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0027 (sample: 10 of 142)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 10; source document page 5; source document page 10; source document page 11(sample: 8 of 86)
  • Confidence level: Medium
  • Classification: Explicit Requirement
Trust Boundary Model

Trust Boundary: Electric Clutch Actuator ECU boundary

Classification: Inferred from Requirements

Separates the in-scope clutch-actuator ECU hardware and software from vehicle, service, backend, customer, and supplier environments.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012 (sample: 10 of 628)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 186)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Trust Boundary: Vehicle/network boundary

Classification: Inferred from Requirements

Separates the ECU/application from other ECUs and vehicle networks carrying SecOC/SDT or function data.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0025 (sample: 10 of 367)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 103)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Trust Boundary: Diagnostic access boundary

Classification: Explicit Requirement

Separates service tools and engineering testers from privileged ECU diagnostic functions.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-3299216-1-0107; RFQX-3299216-1-0126; RFQX-3299216-1-0127; RFQX-CVS123-2-0005; RFQX-CVS123-2-0009; RFQX-CVS123-2-0010; RFQX-CVS123-2-0013; RFQX-CVS123-2-0017 (sample: 10 of 565)
  • Source document: source document page 8; source document page 23; source document page 25; source document page 4; source document page 5; source document page 6; source document page 7; source document page 9(sample: 8 of 137)
  • Confidence level: Low
  • Classification: Explicit Requirement

Trust Boundary: Backend/cloud boundary

Classification: Inferred from Requirements

Separates offboard update, IT, evidence, monitoring, and supplier/OEM systems from product runtime.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013 (sample: 10 of 1095)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 231)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Trust Boundary: Development/tooling boundary

Classification: Explicit Requirement

Separates engineering tooling and evidence repositories from product artifacts and customer-facing evidence.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0034; RFQX-1001379436-P10-000-01-0059; RFQX-3299216-1-0034; RFQX-3299216-1-0035 (sample: 10 of 68)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 11; source document page 10; source document page 11(sample: 8 of 39)
  • Confidence level: Low
  • Classification: Explicit Requirement

Trust Boundary: Customer/OEM approval boundary

Classification: Explicit Requirement

Separates supplier-owned security engineering work products from OEM/customer approval and residual-risk acceptance.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018 (sample: 10 of 140)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 60)
  • Confidence level: Medium
  • Classification: Explicit Requirement

Trust Boundary: Unknown assumed deployment boundary

Classification: Needs Customer Clarification

Marks deployment zones, ownership, and connectivity that cannot be confirmed from the extracted requirements alone.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0004; RFQX-3299216-1-0019; RFQX-3299216-1-0069; RFQX-3299216-1-0098; RFQX-3299216-1-0099; RFQX-3299216-1-0100; RFQX-3299216-1-0128; RFQX-3299216-1-0129; RFQX-3299216-1-0133; RFQX-3299216-1-0141 (sample: 10 of 75)
  • Source document: source document page 3; source document page 7; source document page 16; source document page 23; source document page 25; source document page 26; source document page 27; source document page 29(sample: 8 of 39)
  • Confidence level: Low
  • Classification: Needs Customer Clarification
Security Mechanisms

Security Mechanism Catalog

MechanismPurposeRelated capabilitiesClassificationEvidence
Authentication; Authorization; Secure sessions; Role or certificate validationEnsure only authorized tools, systems, users, and software actors can perform security-relevant actions.Identity and Access ControlExplicit RequirementRFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0044; RFQX-3299216-1-0135; RFQX-3299216-1-0141; RFQX-CVS123-2-0005; RFQX-CVS123-2-0017; RFQX-CVS123-2-0023; RFQX-CVS123-2-0078 (sample: 8 of 312)
Encryption; Signatures/MACs; Integrity checks; Key isolationProvide authenticity, integrity, confidentiality, and non-repudiation where required.Cryptographic ProtectionInferred from RequirementsRFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0028; RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-3299216-1-0031; RFQX-3299216-1-0036; RFQX-CVS123-2-0061; RFQX-CVS123-2-0063 (sample: 8 of 183)
SecOC/SDT-style protection; Freshness counters; Replay protection; Fail-closed discard rulesProtect vehicle, diagnostic, backend, and service data exchanges against tampering, spoofing, and replay.Secure CommunicationInferred from RequirementsRFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0031; RFQX-1001379436-P10-000-01-0032; RFQX-3299216-1-0006; RFQX-3299216-1-0042; RFQX-3299216-1-0079; RFQX-3299216-1-0088; RFQX-3299216-1-0092 (sample: 8 of 264)
Secure boot; Platform integrity checks; Debug restrictions; Authentic software checksEnsure only valid and authorized software executes on an ECU with an integrity-preserving platform.Secure Boot and Platform IntegrityInferred from RequirementsRFQX-3299216-1-0117; RFQX-3299216-1-0126; RFQX-3299216-1-0144; RFQX-CVS123-2-0009; RFQX-CVS123-2-0023; RFQX-CVS123-2-0024; RFQX-CVS123-2-0025; RFQX-CVS123-2-0027 (sample: 8 of 91)
Signed packages; IVD checks; Certificate validation; Update loggingEnsure update and flash content is authentic, intact, authorized, and traceable.Secure Software UpdateInferred from RequirementsRFQX-3299216-1-0176; RFQX-CVS123-2-0001; RFQX-CVS123-2-0004; RFQX-CVS123-2-0006; RFQX-CVS123-2-0007; RFQX-CVS123-2-0008; RFQX-CVS123-2-0013; RFQX-CVS123-2-0023 (sample: 8 of 131)
UDS authentication; Access control; Rate limiting; Diagnostic auditEnable service access while preventing unauthorized diagnostic control.Secure DiagnosticsExplicit RequirementRFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-3299216-1-0107; RFQX-3299216-1-0126; RFQX-3299216-1-0127; RFQX-CVS123-2-0005; RFQX-CVS123-2-0009; RFQX-CVS123-2-0010 (sample: 8 of 572)
PKI lifecycle; Trust-anchor management; Secure provisioning; Protected key storageMaintain trustworthy cryptographic identities and secrets across lifecycle.Key and Certificate ManagementExplicit RequirementRFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-CVS123-2-0090; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0295; RFQX-CVS123-2-0296; RFQX-CVS124-0072 (sample: 8 of 125)
Security event logging; Evidence retention; Audit trail; Traceability IDsRecord security-relevant activity for accountability, evidence, and investigation.Logging and AuditExplicit RequirementRFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0134; RFQX-3299216-1-0136 (sample: 8 of 69)
Security event collection; Alert triage; Detection rules; Escalation pathIdentify security-relevant anomalies or events that need response.Security Monitoring and DetectionInferred from RequirementsRFQX-1001379436-P10-000-01-0058; RFQX-1001379436-P10-000-01-0059; RFQX-1001379436-P10-000-01-0067; RFQX-3299216-1-0137; RFQX-3299216-1-0139; RFQX-3299216-1-0144; RFQX-3299216-1-0165; RFQX-3299216-1-0181 (sample: 8 of 20)
Vulnerability intake; Risk treatment; Incident workflow; Mitigation verificationAssess, treat, communicate, and track vulnerabilities and incidents over releases.Vulnerability and Incident HandlingExplicit RequirementRFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049 (sample: 8 of 14)
Access control; Artifact integrity; Review workflow; Build/test evidenceProtect the engineering environment and evidence chain that produce security-relevant artifacts.Development and Toolchain SecurityInferred from RequirementsRFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0034; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0059 (sample: 8 of 102)
Mutual authentication; Network segregation; API authorization; Backend audit loggingProtect offboard systems that influence update, evidence, monitoring, and operational security.Backend/Cloud SecurityInferred from RequirementsRFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008 (sample: 8 of 1033)
Requirement traceability; Control mapping; V&V reports; Residual-risk approval recordsDemonstrate that requirements, controls, verification, validation, and residual risk remain traceable.Compliance and Evidence ManagementExplicit RequirementRFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0021 (sample: 8 of 142)
TARA Input Candidates

These are candidates only, not final TARA results.

  • REQ-AUTO-00001: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0001: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0002: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0003: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0022: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00009: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0023: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00011: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0024: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0004: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0005: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0042: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0008: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0009: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0027: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0016: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0019: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0015: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0043: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0030: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0045: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00051: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_SEC_0051: derive threat scenario candidates from source wording. Tag: Inferred
  • req-6.20: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00169: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00282: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00290: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00298: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00299: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00310: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00315: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00318: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00333: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00334: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00335: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00350: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00370: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00372: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00377: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00411: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00412: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00413: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00442: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00450: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00455: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00496: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0008: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0040: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0041: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0042: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0043: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0045: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0055: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0063: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0068: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0070: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0076: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0344: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0092: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0107: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0223: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ_UDS-0224: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00788: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00808: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00818: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00821: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00832: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00839: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00843: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00875: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00892: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00895: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00907: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00933: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00934: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00935: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00937: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00938: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00939: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00940: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00942: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00943: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00944: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00947: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00950: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00951: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00953: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00955: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00956: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00957: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00960: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00967: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00991: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00992: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00994: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-00995: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01014: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01017: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01022: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01023: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01024: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01028: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01035: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01041: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01042: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01043: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01058: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01068: derive threat scenario candidates from source wording. Tag: Inferred
  • REQ-AUTO-01069: derive threat scenario candidates from source wording. Tag: Inferred
Open Security Decisions

Security Open Decisions

  • Needs Customer Clarification: Confirm ownership and control allocation for Electric Clutch Actuator ECU boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Vehicle/network boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Diagnostic access boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Backend/cloud boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Development/tooling boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Customer/OEM approval boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Unknown assumed deployment boundary.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Cryptographic Protection.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Secure Communication.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Secure Boot and Platform Integrity.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Secure Software Update.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Security Monitoring and Detection.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Development and Toolchain Security.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Backend/Cloud Security.
Security Concept Overview Evidence

Security Architecture Map

Security Capability Matrix

Security CapabilityProtectsApplied ToMechanismEvidenceOpen Decision
Secure Diagnostics and RBACDiagnostic access state and privileged servicesDiagnostic Tester Interface / Diagnostic ServerUDS Auth 0x29, authorization, lockout and auditStrongConfirm final role model and service list
Secure Software UpdateECU software and firmware authenticityBootloader / Update LogicSigned packages, integrity validation, rollback control and update loggingStrongConfirm signing chain, rollback and campaign ownership
Data Authenticity and Integrity VerificationSecurity-relevant vehicle dataVehicle Network / Secure Data Transfer InterfaceSecOC/SDT-style MAC, freshness and replay rejectionModerateConfirm protected signal allocation
Key and Certificate HandlingKeys, certificates and trust anchorsSecurity Services / Hardware Platform / PKIProvisioning, validation, protected storage and renewal/revocationStrongConfirm HSM capability and PKI ownership
Communication Boundary ControlVehicle and offboard interface boundariesExternal Interfaces / Security ServicesInput validation, boundary filtering and fail-safe discard behaviourModerateConfirm exact boundaries and failure policy
Security LoggingSecurity event evidenceLogging / Event Reporting InterfaceEvent capture, retention, integrity and reportingModerateConfirm event set and reporting channel
Vulnerability and Incident HandlingField security postureSecurity Operations / Compliance ProcessVulnerability intake, triage, mitigation and incident workflowStrongConfirm reporting channels and responsibilities
Cybersecurity Evidence and DIAApproval and residual-risk caseEngineering Toolchain / OEM Approval InterfaceTraceability, V&V evidence, decision logging and residual-risk approvalStrongConfirm DIA split and authority

Protected Asset Table

AssetThreat ExposureProtection StrategyEvidenceOpen Decision
Clutch control behaviourCommand spoofing, unsafe state or malformed dataCommand validation, authenticated/fresh messages where allocated, diagnostic authorizationConfirmed function; security allocation inferredConfirm protected signal set
ECU software and firmwareTampered or wrong software installedSigned update, IVD/integrity checks, secure boot/platform integrityStrong update/flash evidenceConfirm signing chain and rollback
Keys, certificates and trust anchorsCredential theft or invalid trust decisionsProtected storage, certificate validation, lifecycle managementStrong key/certificate evidenceConfirm HSM and PKI owner
Diagnostic access stateUnauthorized privileged service accessUDS Auth 0x29, RBAC, lockout and auditStrong diagnostic evidenceConfirm role model
Security evidence and decisionsUntrusted evidence or unapproved residual riskTraceability, review workflow and decision loggingStrong process evidenceConfirm approval authority

Attack Surface Table

Attack SurfaceEntry PointRequired ControlsEvidenceStatus
Vehicle networkCAN / PWM command and status pathMessage validation, authenticity/freshness where allocated, safe discardCAN/PWM requirements and SecOC/SDT evidenceRequires confirmation
Diagnostic accessUDS tester and programming servicesAuthentication, authorization, lockout, rate limiting and auditUDS/Auth 0x29 evidenceRequires confirmation
Software update / flashProgramming/update package pathSignature validation, IVD/integrity checks, rollback and loggingFlash/update evidenceRequires confirmation
PKI / provisioningKey and certificate injection or renewal pathProtected storage, certificate validation, ownership and revocation controlsKey/certificate evidenceRequires confirmation
Supplier engineering evidenceALM, CI/test and evidence repositoryAccess control, artifact integrity and audit trailCybersecurity concept/evidence requirementsRequires confirmation

Security Decision Table

ConclusionStatusEvidenceImpactDecision Needed
ECA ECU product identity and AMT platform contextConfirmedsource document function statements; source documentStabilizes review-board namingConfirm final product designation/variant
Cybersecurity concept and evidence package are in scopeConfirmedCybersecurity and process requirementsMakes this an architecture/security baseline, not a brochureConfirm approval workflow
Secure diagnostics, update and key/certificate handling apply to the ECUInferredUDS, flash/IVD and certificate/key requirementsDrives security services and trust-boundary designConfirm exact allocation
SecOC/SDT-style protection is needed for selected data flowsRequires ConfirmationSecure communication requirementsBlocks final interface-security allocationCustomer must identify protected signals

Executive Security Conclusion

The Electric Clutch Actuator ECU must protect clutch-control behaviour, software and firmware, cryptographic keys/certificates, diagnostic access, vehicle data exchange and security evidence. Diagnostic role allocation, update-sequence ownership, key hierarchy, HSM capability, and SecOC/SDT signal scope still require OEM/supplier agreement.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015 (sample: 10 of 553)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 158)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Protected Assets

  • Inferred from Requirements: Vehicle function data (RFQX-3299216-1-0006; RFQX-3299216-1-0079; RFQX-3299216-1-0088; RFQX-3299216-1-0094; RFQX-3299216-1-0095; RFQX-3299216-1-0100; RFQX-3299216-1-0135; RFQX-3299216-1-0164 (sample: 8 of 55))
  • Explicit Requirement: ECU software and firmware (RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0021; RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0027; RFQX-1001379436-P10-000-01-0045; RFQX-1001379436-P10-000-01-0056; RFQX-3299216-1-0061 (sample: 8 of 362))
  • Explicit Requirement: Cryptographic keys and certificates (RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042; RFQX-CVS123-2-0090; RFQX-CVS123-2-0112; RFQX-CVS123-2-0113; RFQX-CVS123-2-0295; RFQX-CVS123-2-0296; RFQX-CVS124-0072 (sample: 8 of 125))
  • Explicit Requirement: Diagnostic access state (RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-3299216-1-0107; RFQX-3299216-1-0126; RFQX-3299216-1-0127; RFQX-CVS123-2-0005; RFQX-CVS123-2-0009; RFQX-CVS123-2-0010 (sample: 8 of 575))
  • Explicit Requirement: Cybersecurity concept and evidence (RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019 (sample: 8 of 60))
  • Inferred from Requirements: Backend/update and security operations data (RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0048; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-1001379436-P10-000-01-0051; RFQX-1001379436-P10-000-01-0054; RFQX-1001379436-P10-000-01-0055 (sample: 8 of 497))
  • Inferred from Requirements: Hardware platform integrity (RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0020; RFQX-1001379436-P10-000-01-0022; RFQX-1001379436-P10-000-01-0027; RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030 (sample: 8 of 104))

Main Attack Surfaces

  • Inferred from Requirements: Diagnostic access, vehicle network communication, secure update/flash path, certificate/key provisioning, backend/IT interfaces, development/evidence tooling, and customer evidence handoff.

Security Architecture Logic

  • Recommendation: Protect the highest-risk boundaries first - diagnostics, vehicle communication, update/flash, and key/certificate handling - using authenticated access, signed and integrity-verified software, message authenticity and freshness, and isolated key storage, with logging and traceable evidence feeding OEM approval. Preserve authenticity, integrity, freshness, software validity, diagnostic access control, and evidence integrity as the main security goals.

Open Security Decisions

  • Needs Customer Clarification: Final TARA, item definition, exact assets, algorithms, certificate hierarchy, diagnostic roles, backend responsibilities, and deployment topology.
  • Needs Customer Clarification: Allocation of secure-communication (SecOC/SDT) protection to specific signals, plus the protection profile and freshness model.
  • Needs Customer Clarification: Ownership split (supplier/OEM) for update sequence, key provisioning, monitoring, and incident response.

See the Security Capability Model, Asset Model, Trust Boundary Model, and Security Mechanism Catalog below for the detailed control evidence.