1001379436_P10_000_01_RDDM-1140152501-1744

1001379436_P10_000_01_RDDM-1140152501-1744.pdf · Cybersecurity Requirement Standard · Cybersecurity

Last updated: 2026-06-29 11:50
RTRFQX Review TeamWorkspace

1001379436_P10_000_01_RDDM-1140152501-1744

1001379436_P10_000_01_RDDM-1140152501-1744.pdf · Cybersecurity Requirement Standard · Cybersecurity

Markdown-derived onlyOCR: falseLast generated 2026-06-29 11:50

What this document contains

Confirmed Requirements46customer ID + normative
Needs Clarification15no customer ID
Information1descriptive
Reference1definitions, scope
Critical20ranked impact
Open Points4linked
Tables / Diagrams4 / 0extracted
Derived SSRs17linked

Executive Takeaway

Systems-engineering read of what this document defines for the system - scope, boundaries, interfaces, obligations, and what is still open.

Document Purpose

Scope: this cybersecurity requirement standard specifies requirement, covering 2.1 Development process; 2.1.3 Cybersecurity concept; 2.1.5 Documentation; 2.2 System requirements; 2.2.3 Cryptographic libraries; 2.4 Information security.

System Boundary & Interfaces

System boundary and interfaces: the document constrains 2 interface(s) - OEM/Customer Review Interface; External Interfaces; OEM/Customer Review Interface; principal functions in scope are Security evidence and traceability.

Design / Security Impact

Design and security impact: affects Security evidence and traceability; security capabilities touched: Cybersecurity requirement handling; Vulnerability management; Authentication; Key management (sample: 4 of 6); 17 supplier system requirement(s) were derived from this document.

Open For Customer

Open for the customer: 4 document-linked open point(s) - mainly Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.; Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy). (sample: 3 of 4) - plus 15 unidentified requirement-like statement(s). Do not baseline these until the customer confirms.

Confidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used.

Main Requirement Themes

ThemeEngineering MeaningRequirement CountRepresentative Requirements
RequirementGroups related document requirements into a single engineering theme.46RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012
Responsibility and customer approval modelCreates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk.46RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005
Core ECA system behaviorDefines actuator ECU behavior, drivetrain integration, electrical/mechanical constraints, and verification scope.38RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0008
System architecture designGroups related document requirements into a single engineering theme.37RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0009
Cybersecurity concept and evidenceDrives cybersecurity concept, risk treatment, verification evidence, and traceability obligations.32RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005
CybersecurityGroups related document requirements into a single engineering theme.26RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005
Cybersecurity verification reportGroups related document requirements into a single engineering theme.26RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005
Security servicesGroups related document requirements into a single engineering theme.24RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007

Document Content Structure

SectionRequirementsInformationUnknown / Review NeededTotal ItemsCriticalOpen PointsSSR Links
1 Introduction0005100
-- 1.4 Abbreviated terms0005100
-- 2.1 Development process101016514
-- -- 2.1.3 Cybersecurity concept3107313
-- -- 2.1.5 Documentation7009213
-- 2.2 System requirements6007114
-- -- 2.2.3 Cryptographic libraries6007114
-- 2.4 Information security7009325
-- 2.6 Cybersecurity lifecycle23003010310
-- -- 2.6.1 Security updates8008113
-- -- 2.6.3 Vulnerability management7009325
-- -- 2.6.4 Product lifecycle6008225
-- -- 2.6.5 Logging2005412

Tables and Diagrams

Tables are reconstructed column-correct from the document text layer (no OCR). Diagrams are linked from converted image assets.

Tables4column-correct
Diagrams0image-linked
Linked Artifacts2requirement-linked

Tables (4)

TableTable 1: Definition of terms

1001379436_P10_000_01_RDDM-1140152501-1744 · page 3 · Linked: 1.3

TermDefinition
ShallThis word, or the term "Required", means that the definition is an absolute requirement of the specification.
Threat Analysis andA structured approach to identify possible threats and evaluate risks with respect to the potential
Risk Assessmentdamages and the effort needed for successful attack. A cybersecurity concept is a work product that documents cybersecurity relevant aspects of the
Cybersecurity conceptproduct. The cybersecurity concept shall describe the scope of the risk analysis, risks that were identified during the risk analysis, cybersecurity goals, cybersecurity requirements, mitigation strategies, validation, and verification strategies, etc.

Table source context

TableTable 2: Abbreviated terms

1001379436_P10_000_01_RDDM-1140152501-1744 · page 3 · Linked: 1.4; INFO_SEC_001; REQ_SEC_0001; REQ_SEC_0002

AbbreviationDescription
ECUElectronic Control Unit

Security protocol or cryptographic context

TableTable 3: Bibliography

1001379436_P10_000_01_RDDM-1140152501-1744 · page 15 · Linked: None

ID1Name Scania/MAN UnifiedVersionContent
[1]Diagnostic Services – Security access mechanisms1.0, 2018-04-18Scania/MAN Unified Diagnostic Services – Security access mechanisms

Table source context

TableTable 4: History of the document

1001379436_P10_000_01_RDDM-1140152501-1744 · page 16 · Linked: None

VersionDateEditorNotes
1.02021-06-02mxxm36Initial version. As close as possible to the last Excel sheet version of the requirements
2.02021-06-30mxxm36Added new requirements and adjusted old requirements. More clarifications and cosmetics.

Table source context

What This PDF Is About

FieldValue
Source PDF1001379436_P10_000_01_RDDM-1140152501-1744.pdf
Document TypeCybersecurity Requirement Standard
DomainCybersecurity
Scope Summary46 confirmed requirements, 15 needing clarification, 1 information, 1 reference items; 17 linked SSRs; 4 linked open points.
Main ThemesRequirement; Responsibility and customer approval model; Core ECA system behavior; System architecture design; Cybersecurity concept and evidence (sample: 5 of 8)
Does Not ConfirmCustomer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.
ConfidenceHigh
Evidence BasisMarkdown-derived requirements and generated RFQX registers; no downstream PDF analysis.

Critical Requirements

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

IDScoreCategoryRequirement / ReasonSupplier Position
RFQX-1001379436-P10-000-01-001081High risk due to unclear OEM/supplier responsibilityDocumentation on the method and results shall be provided to the vehicle manufacturer.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-001181High risk due to unclear OEM/supplier responsibilityNote: The vehicle manufacturer and supplier shall collaboratively define the context of the system or function to enable the supplier performing the risk assessment.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-001481High risk due to unclear OEM/supplier responsibilityFor each risk identified in the cybersecurity risk analyses, a risk treatment decision shall be made to avoid, reduce, share, or retain the risk.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-001681High risk due to unclear OEM/supplier responsibilityIt shall be possible to verify which cybersecurity controls were derived from which requirements.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-003581High risk due to unclear OEM/supplier responsibilityThe details shall be agreed upon between the vehicle manufacturer and the supplier.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-005681High risk due to unclear OEM/supplier responsibilityThe information shall contain • the version(s) of affected hardware or software components, • nature of the vulnerability, • description of the affected cybersecurity goal, • technical conditions to exploit the vulnerability, • impact of the exploitation and • possibilities to remove the vulnerability.security relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
REQ_SEC_001677High risk due to unclear OEM/supplier responsibilityIt shall be possible for the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECU according to the specification of the vehicle manufacturer.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
RFQX-1001379436-P10-000-01-000966High risk due to unclear OEM/supplier responsibilityMethod and scope shall be proposed to and approved by the vehicle manufacturer.architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-002666High risk due to unclear OEM/supplier responsibilityMethods shall be proposed to and approved by the vehicle manufacturer.architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-003366High risk due to unclear OEM/supplier responsibilityMethods shall be proposed and approved by the vehicle manufacturer.architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-005266High risk due to unclear OEM/supplier responsibilityThe report shall include information needed to identify the affected vehicles/products.architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification
RFQX-1001379436-P10-000-01-005366High risk due to unclear OEM/supplier responsibilityMethods including the stipulation of a reasonable notification time shall be proposed to and approved by the vehicle manufacturer.architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNeeds Customer Clarification

Customer Clarifications / Open Points

Total Open Points4document-linked
P10priority
P20priority
Blocking Conceptyesyes / no
Blocking Estimationyesyes / no
Blocking SSRyesyes / no

Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.

Impact if unresolved: ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.

OpenOpen

Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.

Impact if unresolved: Lifecycle effort and field-response capability stay unbounded; risk of an R155 compliance gap.

OpenOpen

Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).

Impact if unresolved: Hardware fusing and EOL process design stay open; risk of an exposed debug/production interface.

OpenOpen

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Impact if unresolved: Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.

OpenOpen
Open full open-point table (all fields)

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Open PointPriorityQuestion / ImpactRequired Customer DecisionRecommended Supplier PositionOwnerStatus
OP-003Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.Provide ECU-side secure storage and provisioning hooks; require OEM confirmation of PKI ownership and the provisioning interface.OEM / Customer (PKI) + Supplier (ECU)Open
OP-006Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.Lifecycle effort and field-response capability stay unbounded; risk of an R155 compliance gap.Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.Define supplier vulnerability handling and field-fix capability; require OEM confirmation of monitoring/communication ownership.OEM / Customer (fleet) + Supplier (ECU)Open
OP-008Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).Hardware fusing and EOL process design stay open; risk of an exposed debug/production interface.Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).Apply debug lock and secured production access; request the customer-confirmed production-security and EOL requirements.Shared (OEM process / Supplier ECU)Open
OP-011Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.Decide whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context.Carry the items as customer-confirmation dependencies and review them in the next clarification workshop.OEM / CustomerOpen

Confirmed requirements (46)

Items carrying a customer requirement ID and a normative (shall/must) statement.

REQ_SEC_0016RFQX-1001379436-P10-000-01-0041Requirement2.6.1 Security updatespage 9

It shall be possible for the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECU according to the specification of the vehicle manufacturer.

Partially AcceptOpen point OP-003SSR SSR-KEY-001
Details & reviewer feedback
Section

Key management

Page

page 9

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Key management

Supplier proposal

Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.

REQ_SEC_0026RFQX-1001379436-P10-000-01-0036Requirement2.4 Information securitypage 8

Only hardware interfaces and protocols specified by the vehicle manufacturer shall be available in series production.

Partially AcceptOpen point OP-008SSR SSR-COM-001
Details & reviewer feedback
Section

2.4 Information security

Page

page 8

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

REQ_SEC_0034RFQX-1001379436-P10-000-01-0054Requirement2.6.3 Vulnerability managementpage 10

Following each identified and reported vulnerability, the supplier and vehicle manufacturer shall agree on an initial response to the vulnerability.

Partially AcceptOpen point OP-006SSR SSR-VIH-003
Details & reviewer feedback
Section

2.6.3 Vulnerability management

Page

page 10

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0050RFQX-1001379436-P10-000-01-0063Requirement2.6.5 Loggingpage 12

All secrets specified by the vehicle manufacturer shall be protected throughout the lifecycle of the ECU.

Partially AcceptSSR SSR-HW-001
Details & reviewer feedback
Section

Marcus Lindner EPXC Published 12(16)

Page

page 12

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.

REQ_SEC_0020RFQX-1001379436-P10-000-01-0028Requirement2.2.3 Cryptographic librariespage 7

Selection of cryptographic methods and their use shall be agreed upon between the vehicle manufacturer and the supplier.

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

Cryptographic libraries

Page

page 7

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0019RFQX-1001379436-P10-000-01-0042Requirement2.6.1 Security updatespage 9

Secrets, public keys and other data used for cybersecurity controls in production vehicle systems shall be different from those used in pre-production phases.

Accept with AssumptionSSR SSR-KEY-001
Details & reviewer feedback
Section

2.6.1 Security updates

Page

page 9

Security capability

Key management

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0043RFQX-1001379436-P10-000-01-0045Requirement2.6.1 Security updatespage 9

It shall be possible to update the software of the ECU.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

Security updates

Page

page 9

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0001RFQX-1001379436-P10-000-01-0007Requirement2.1.3 Cybersecurity conceptpage 5

The supplier shall provide documentation describing their strategies and methods for working with embedded systems cybersecurity.

Accept with AssumptionSSR SSR-CON-0011 tables · 0 diagrams
Details & reviewer feedback
Section

Cybersecurity methods and strategies

Page

page 5

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-1001379436P1000001RDDM11-0002 Table: Table 2: Abbreviated terms page 3
    Security protocol or cryptographic context Image available: no View artifact
REQ_SEC_0002RFQX-1001379436-P10-000-01-0008Requirement2.1.3 Cybersecurity conceptpage 5

The supplier shall perform risk assessment based on a threat and vulnerability analysis for each release, including any vehicle manufacturer-specific adaptations.

Accept with AssumptionSSR SSR-VIH-0011 tables · 0 diagrams
Details & reviewer feedback
Section

Risk assessment

Page

page 5

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Vulnerability management

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation. Related source tables/diagrams are treated as interpretation context, not separate customer IDs.

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-1001379436P1000001RDDM11-0002 Table: Table 2: Abbreviated terms page 3
    Security protocol or cryptographic context Image available: no View artifact
REQ_SEC_0003RFQX-1001379436-P10-000-01-0012Requirement2.1.3 Cybersecurity conceptpage 5

The supplier shall describe the cybersecurity concept and how it is implemented in hardware and software respectively.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

Cybersecurity concept

Page

page 5

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.

REQ_SEC_0022RFQX-1001379436-P10-000-01-0013Requirement2.1.5 Documentationpage 6

All risks identified in cybersecurity risk analyses shall be evaluated.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

Marcus Lindner EPXC Published 6(16)

Page

page 6

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0023RFQX-1001379436-P10-000-01-0015Requirement2.1.5 Documentationpage 6

Cybersecurity controls shall sufficiently reduce the risk.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

2.1.5 Documentation

Page

page 6

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0024RFQX-1001379436-P10-000-01-0017Requirement2.1.5 Documentationpage 6

The cybersecurity concept of the supplier shall contain a documentation of the accepted residual risk and be agreed with the vehicle manufacturer.

Accept with AssumptionSSR SSR-CON-001
Details & reviewer feedback
Section

2.1.5 Documentation

Page

page 6

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.

REQ_SEC_0004RFQX-1001379436-P10-000-01-0018Requirement2.1.5 Documentationpage 6

The supplier shall provide documentation of the verification and validation methods of cybersecurity features.

Accept with AssumptionSSR SSR-CON-001
Details & reviewer feedback
Section

Verification and validation

Page

page 6

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0005RFQX-1001379436-P10-000-01-0019Requirement2.1.5 Documentationpage 6

The supplier shall provide test reports detailing the results from the verification and validation of cybersecurity features.

Accept with AssumptionSSR SSR-CON-001
Details & reviewer feedback
Section

2.1.5 Documentation

Page

page 6

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0007RFQX-1001379436-P10-000-01-0021Requirement2.1.5 Documentationpage 6

An inventory of software and protocols, including their versions, shall be provided by the supplier.

Accept with AssumptionSSR SSR-CON-003
Details & reviewer feedback
Section

Documentation

Page

page 6

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0025RFQX-1001379436-P10-000-01-0022Requirement2.2.3 Cryptographic librariespage 7

A BOM containing part numbers and versions of hardware components used in the product shall be provided by the supplier.

Accept with AssumptionSSR SSR-HW-001
Details & reviewer feedback
Section

Marcus Lindner EPXC Published 7(16)

Page

page 7

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0042RFQX-1001379436-P10-000-01-0024Requirement2.2.3 Cryptographic librariespage 7

The vehicle manufacturer and the supplier shall set up a cybersecurity DIA to agree on the responsibilities for the distributed cybersecurity activities.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

2.2.3 Cryptographic libraries

Page

page 7

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.

REQ_SEC_0008RFQX-1001379436-P10-000-01-0025Requirement2.2.3 Cryptographic librariespage 7

The ECU shall be able to verify integrity and authenticity of a vehicle manufacturer-specified set of data stored within the ECU.

Accept with AssumptionSSR SSR-DAI-001
Details & reviewer feedback
Section

Software security

Page

page 7

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Authentication

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0009RFQX-1001379436-P10-000-01-0027Requirement2.2.3 Cryptographic librariespage 7

The supplier shall apply methods for isolation of software/hardware components and data to reduce the effect in case of a cybersecurity breach.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

Security architecture

Page

page 7

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0010RFQX-1001379436-P10-000-01-0029Requirement2.4 Information securitypage 8

All network services implemented in the ECU shall undergo hardening.

Accept with AssumptionSSR SSR-PROD-001
Details & reviewer feedback
Section

Services

Page

page 8

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0011RFQX-1001379436-P10-000-01-0030Requirement2.4 Information securitypage 8

The ECU shall only expose network and communication services that have been agreed upon with the vehicle manufacturer.

Accept with AssumptionSSR SSR-COM-001
Details & reviewer feedback
Section

2.4 Information security

Page

page 8

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0012RFQX-1001379436-P10-000-01-0031Requirement2.4 Information securitypage 8

Communication interfaces shall use boundary controls such as ingress/egress filtering.

Accept with AssumptionSSR SSR-COM-002
Details & reviewer feedback
Section

Interfaces

Page

page 8

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0013RFQX-1001379436-P10-000-01-0032Requirement2.4 Information securitypage 8

Communication boundary controls shall be configurable by the vehicle manufacturer.

Accept with AssumptionSSR SSR-COM-003
Details & reviewer feedback
Section

2.4 Information security

Page

page 8

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0014RFQX-1001379436-P10-000-01-0034Requirement2.4 Information securitypage 8

Any interfaces used for development purposes shall be removed or disabled in series production.

Accept with AssumptionSSR SSR-COM-002
Details & reviewer feedback
Section

2.4 Information security

Page

page 8

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0027RFQX-1001379436-P10-000-01-0037Requirement2.4 Information securitypage 8

It shall be possible for the vehicle manufacturer to securely inject data into the product in accordance with the specification provided by the vehicle manufacturer.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

Information security

Page

page 8

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0021RFQX-1001379436-P10-000-01-0043Requirement2.6.1 Security updatespage 9

ECUs shall only contain the secrets agreed between the vehicle manufacturer and the supplier.

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

2.6.1 Security updates

Page

page 9

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0015RFQX-1001379436-P10-000-01-0044Requirement2.6.1 Security updatespage 9

ECUs shall conform to the harmonized Security Access specification [1] provided by the vehicle manufacturer.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

2.6.1 Security updates

Page

page 9

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept with assumption. Implement the ECU-side diagnostic behavior with configurable authorization and verification evidence, subject to customer-confirmed UDS service allocation and role model.

REQ_SEC_0030RFQX-1001379436-P10-000-01-0046Requirement2.6.3 Vulnerability managementpage 10

The supplier shall inform the vehicle manufacturer if any cybersecurity patches are available.

Accept with AssumptionSSR SSR-CON-002
Details & reviewer feedback
Section

Marcus Lindner EPXC Published 10(16)

Page

page 10

Feature / Interface

None / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0044RFQX-1001379436-P10-000-01-0047Requirement2.6.3 Vulnerability managementpage 10

An incident response process shall be proposed to and approved by the vehicle manufacturer.

Accept with AssumptionSSR SSR-VIH-002
Details & reviewer feedback
Section

Incident management

Page

page 10

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0045RFQX-1001379436-P10-000-01-0048Requirement2.6.3 Vulnerability managementpage 10

In case of cybersecurity incidents, the incident response process shall be used.

Accept with AssumptionSSR SSR-VIH-001
Details & reviewer feedback
Section

2.6.3 Vulnerability management

Page

page 10

Security capability

Incident response

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0046RFQX-1001379436-P10-000-01-0049Requirement2.6.3 Vulnerability managementpage 10

The incident response process shall be maintained for the entire product lifetime.

Accept with AssumptionSSR SSR-VIH-002
Details & reviewer feedback
Section

2.6.3 Vulnerability management

Page

page 10

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0032RFQX-1001379436-P10-000-01-0050Requirement2.6.3 Vulnerability managementpage 10

The incident response process shall ensure that risk is managed in coordination with the vehicle manufacturer.

Accept with AssumptionSSR SSR-VIH-002
Details & reviewer feedback
Section

2.6.3 Vulnerability management

Page

page 10

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0033RFQX-1001379436-P10-000-01-0051Requirement2.6.3 Vulnerability managementpage 10

Any vulnerabilities that are identified during product lifecycle shall be promptly communicated to the vehicle manufacturer.

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

Vulnerability management

Page

page 10

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0035RFQX-1001379436-P10-000-01-0055Requirement2.6.4 Product lifecyclepage 11

Within adequate time after the initial vulnerability report, the supplier shall provide more information about the identified vulnerability.

Accept with AssumptionSSR SSR-VIH-003
Details & reviewer feedback
Section

Marcus Lindner EPXC Published 11(16)

Page

page 11

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0036RFQX-1001379436-P10-000-01-0058Requirement2.6.4 Product lifecyclepage 11

The supplier shall have a method for monitoring available vulnerability databases for vulnerabilities that can affect the delivered product.

Accept with AssumptionSSR SSR-VIH-004
Details & reviewer feedback
Section

2.6.4 Product lifecycle

Page

page 11

Feature / Interface

None / External Interfaces; OEM/Customer Review Interface

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0037RFQX-1001379436-P10-000-01-0059Requirement2.6.4 Product lifecyclepage 11

Identified vulnerabilities shall be considered in all current development projects or projects under field monitoring.

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

2.6.4 Product lifecycle

Page

page 11

Supplier proposal

Accept with assumption. Supplier can provide vulnerability monitoring, reporting, and initial response process evidence; vehicle-level incident ownership and escalation path require customer confirmation.

REQ_SEC_0048RFQX-1001379436-P10-000-01-0061Requirement2.6.4 Product lifecyclepage 11

Field-return analysis secrets shall not be operational in the field.

Accept with AssumptionSSR SSR-SYS-001
Details & reviewer feedback
Section

2.6.4 Product lifecycle

Page

page 11

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0051RFQX-1001379436-P10-000-01-0067Requirement2.6.5 Loggingpage 12

Security related events shall be identified and logged.

Accept with AssumptionSSR SSR-LOG-001
Details & reviewer feedback
Section

Logging

Page

page 12

Security capability

Logging and audit trail

Supplier proposal

Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.

REQ_SEC_0041RFQX-1001379436-P10-000-01-0023Requirement2.2.3 Cryptographic librariespage 7

The vehicle manufacturer reserves the right to request documentation and evidence as well as to perform or order a compliance audit to determine whether the listed requirements are fulfilled.

Informational Only
Details & reviewer feedback
Section

2.2.3 Cryptographic libraries

Page

page 7

Feature / Interface

Security evidence and traceability / None

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

REQ_SEC_0028RFQX-1001379436-P10-000-01-0038Requirement2.6.1 Security updatespage 9

Data specified by the vehicle manufacturer shall be protected from manipulations.

AcceptSSR SSR-SYS-001
Details & reviewer feedback
Section

Marcus Lindner EPXC Published 9(16)

Page

page 9

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

REQ_SEC_0029RFQX-1001379436-P10-000-01-0039Requirement2.6.1 Security updatespage 9

Data specified by the vehicle manufacturer shall be protected from disclosure.

AcceptSSR SSR-SYS-001
Details & reviewer feedback
Section

2.6.1 Security updates

Page

page 9

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

REQ_SEC_0006RFQX-1001379436-P10-000-01-0040Requirement2.6.1 Security updatespage 9

Intellectual property of the vehicle manufacturer shall be protected from disclosure.

AcceptSSR SSR-SYS-001
Details & reviewer feedback
Section

2.6.1 Security updates

Page

page 9

Feature / Interface

None / OEM/Customer Review Interface

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

REQ_SEC_0047RFQX-1001379436-P10-000-01-0060Requirement2.6.4 Product lifecyclepage 11

An ECU returned from field shall allow for field-return analysis.

AcceptSSR SSR-HW-001
Details & reviewer feedback
Section

Product lifecycle

Page

page 11

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

REQ_SEC_0049RFQX-1001379436-P10-000-01-0062Requirement2.6.4 Product lifecyclepage 11

An ECU enabled for field-return analysis shall not be possible to use as a spare part.

AcceptSSR SSR-LIFE-001
Details & reviewer feedback
Section

2.6.4 Product lifecycle

Page

page 11

Supplier proposal

Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.

REQ_SEC_0040RFQX-1001379436-P10-000-01-0020Requirement2.1.5 Documentationpage 6

The vehicle manufacturer reserves the right to perform penetration testing on the ECU to identify potential vulnerabilities.

Informational Only
Details & reviewer feedback
Section

2.1.5 Documentation

Page

page 6

Supplier proposal

Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.

Needs customer clarification (15)

Reads like a requirement but no customer requirement ID was identified in the source. Confirm with the customer before baselining — not counted as a confirmed requirement.

RFQX-1001379436-P10-000-01-0010Needs Clarification2.1.3 Cybersecurity conceptpage 5

Documentation on the method and results shall be provided to the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.1.3 Cybersecurity concept

Page

page 5

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0011Needs Clarification2.1.3 Cybersecurity conceptpage 5

Note: The vehicle manufacturer and supplier shall collaboratively define the context of the system or function to enable the supplier performing the risk assessment.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.1.3 Cybersecurity concept

Page

page 5

Feature / Interface

None / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0014Needs Clarification2.1.5 Documentationpage 6

For each risk identified in the cybersecurity risk analyses, a risk treatment decision shall be made to avoid, reduce, share, or retain the risk.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.1.5 Documentation

Page

page 6

Security capability

Cybersecurity requirement handling

RFQX-1001379436-P10-000-01-0016Needs Clarification2.1.5 Documentationpage 6

It shall be possible to verify which cybersecurity controls were derived from which requirements.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.1.5 Documentation

Page

page 6

Security capability

Cybersecurity requirement handling

RFQX-1001379436-P10-000-01-0035Needs Clarification2.4 Information securitypage 8

The details shall be agreed upon between the vehicle manufacturer and the supplier.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.4 Information security

Page

page 8

Feature / Interface

None / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0056Needs Clarification2.6.4 Product lifecyclepage 11

The information shall contain • the version(s) of affected hardware or software components, • nature of the vulnerability, • description of the affected cybersecurity goal, • technical conditions to exploit the vulnerability, • impact of the exploitation and • possibilities to remove the vulnerability.

Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.

Open point OP-006
Details
Section

2.6.4 Product lifecycle

Page

page 11

Security capability

Vulnerability management

RFQX-1001379436-P10-000-01-0009Needs Clarification2.1.3 Cybersecurity conceptpage 5

Method and scope shall be proposed to and approved by the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.1.3 Cybersecurity concept

Page

page 5

Feature / Interface

None / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0026Needs Clarification2.2.3 Cryptographic librariespage 7

Methods shall be proposed to and approved by the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.2.3 Cryptographic libraries

Page

page 7

Feature / Interface

None / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0033Needs Clarification2.4 Information securitypage 8

Methods shall be proposed and approved by the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.4 Information security

Page

page 8

Feature / Interface

None / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0052Needs Clarification2.6.3 Vulnerability managementpage 10

The report shall include information needed to identify the affected vehicles/products.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.6.3 Vulnerability management

Page

page 10

RFQX-1001379436-P10-000-01-0053Needs Clarification2.6.3 Vulnerability managementpage 10

Methods including the stipulation of a reasonable notification time shall be proposed to and approved by the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.6.3 Vulnerability management

Page

page 10

Feature / Interface

None / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0057Needs Clarification2.6.4 Product lifecyclepage 11

Methods including the stipulation of a reasonable reporting time shall be proposed to and approved by the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.6.4 Product lifecycle

Page

page 11

Feature / Interface

None / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0064Needs Clarification2.6.5 Loggingpage 12

End-of-life and decommissioning shall be specifically considered.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.6.5 Logging

Page

page 12

RFQX-1001379436-P10-000-01-0065Needs Clarification2.6.5 Loggingpage 12

Notes: a) It shall not be possible for a third party to reuse an ECU without system support from the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.6.5 Logging

Page

page 12

Feature / Interface

None / OEM/Customer Review Interface

RFQX-1001379436-P10-000-01-0066Needs Clarification2.6.5 Loggingpage 12

b) Decommissioning of an ECU shall not have the potential of causing unacceptable risk to the road user or the vehicle manufacturer.

Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.

Open point OP-011
Details
Section

2.6.5 Logging

Page

page 12

Feature / Interface

None / OEM/Customer Review Interface

Information / descriptive (1)

Descriptive or contextual statements with a customer ID but no binding (shall/must) wording.

INFO_SEC_001RFQX-1001379436-P10-000-01-0006Information2.1.3 Cybersecurity conceptpage 5

Cybersecurity principles are high level requirements that drive development and refinement of functional and technical cybersecurity requirements.

1 tables · 0 diagrams
Details
Section

General cybersecurity requirements

Page

page 5

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-1001379436P1000001RDDM11-0002 Table: Table 2: Abbreviated terms page 3
    Security protocol or cryptographic context Image available: no View artifact

Reference / document information (1)

Definitions, abbreviations, document history, scope and other boilerplate. Not customer requirements.

1.3RFQX-1001379436-P10-000-01-0003Reference1.4 Abbreviated termspage 3

Abbreviated terms

Term Definition Shall This word, or the term "Required", means that the definition is an absolute requirement of the specification. Threat Analysis and Risk Assessment A structured approach to identify possible threats and evaluate risks with respect to the potential damages and the effort needed for successful attack. Cybersecurity concept A cybersecurity concept is a work product that documents cybersecurity relevant aspects of the product. The cybersecurity concept shall describe the scope of the risk analysis, risks that were identified during the risk analysis, cybe rsecurity goals, cybersecurity requirements, mitigation strategies, validation, and verification strategies, etc. Table 1: Definition of terms The cybersecurity concept shall describe the scope of the risk analysis, risks that were identified during the risk analysis, cybe rsecurity goals, cybersecurity requirements, mitigation strategies, validation, and verification strategies, etc. This document contains general cybersecurity requirements. The requirements specified in this document are applicable to all ECUs. The supplier of ECU is responsible to take all the necessary measures and steps to comply with the requirements listed in this document. The target readers of this specification are ECU suppliers, which can be either internal or external in relation to the vehicle manufacturer. In both cases, whenever the term “ECU supplier” or just “supplier” is used in this specification it refers to the company and organization which is responsible for the implementation and delivery of the ECU according to the requirements in this specification. And in both cases, whenever the term “vehicle manufacturer” is used in this specification this term refers to the system owner (responsible receiver) at the vehicle manufacturer. Abbreviation Description ECU Electronic Control Unit Table 2: Abbreviated terms

1 tables · 0 diagrams
Details
Section

1.4 Abbreviated terms

Page

page 3

Feature / Interface

Security evidence and traceability / OEM/Customer Review Interface

Security capability

Cybersecurity requirement handling

Related Tables / Diagrams

Linked tables: 1 | Linked diagrams: 0

  • TABLE-1001379436P1000001RDDM11-0001 Table: Table 1: Definition of terms page 3
    Table source context Image available: no View artifact

Derived Supplier System Requirements

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

SSRStatement / TraceFeatureSecurity CapabilityInterfaceResponsibilityStatusVerification
SSR-COM-001OEM/Customer Review Interface — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for OEM/Customer Review Interface, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (Hardware domain; allocated to Hardware Platform; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0036. OEM/Customer Review InterfaceNoneOEM/Customer Review InterfaceSharedReady for Customer AlignmentReview + Test
SSR-COM-002Secure Communication and Boundary Control — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (System domain; allocated to System Core).From this PDF: RFQX-1001379436-P10-000-01-0031; RFQX-1001379436-P10-000-01-0034. Secure Communication and Boundary ControlNoneNoneSupplier-OwnedCandidateReview + Test + table/diagram context review
SSR-COM-003OEM/Customer Review Interface — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for OEM/Customer Review Interface, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (System domain; allocated to System Core; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0032. OEM/Customer Review InterfaceNoneOEM/Customer Review InterfaceSupplier-OwnedCandidateReview + Test
SSR-CON-001Security evidence and traceability — Cybersecurity Concept and EvidenceThe supplier shall produce and maintain the cybersecurity concept and verification evidence covering Security evidence and traceability (Cybersecurity domain; allocated to Security Services; security capability: Cybersecurity requirement handling; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019. Security evidence and traceabilityCybersecurity requirement handlingOEM/Customer Review InterfaceSupplier-OwnedCandidateReview + Test + table/diagram context review
SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceThe supplier shall produce and maintain the cybersecurity concept and verification evidence covering Cybersecurity Concept and Evidence (Cybersecurity domain; allocated to Security Services; security capability: Cybersecurity requirement handling; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0027; RFQX-1001379436-P10-000-01-0037; RFQX-1001379436-P10-000-01-0044; RFQX-1001379436-P10-000-01-0045; RFQX-1001379436-P10-000-01-0046. Cybersecurity Concept and EvidenceCybersecurity requirement handlingOEM/Customer Review InterfaceSharedReady for Customer AlignmentReview + Test + table/diagram context review
SSR-CON-003Security evidence and traceability — Cybersecurity Concept and EvidenceThe supplier shall produce and maintain the cybersecurity concept and verification evidence covering Security evidence and traceability (Software domain; allocated to Application Software; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0021. Security evidence and traceabilityNoneOEM/Customer Review InterfaceSupplier-OwnedCandidateReview + Test
SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (Cybersecurity domain; allocated to Security Services; security capability: Authentication; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0025. Data Authenticity and Integrity VerificationAuthenticationOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageThe ECU hardware shall provide the platform and secure-storage capabilities required for Hardware / HSM / Secure Storage (Hardware domain; allocated to Hardware Platform; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0022; RFQX-1001379436-P10-000-01-0060; RFQX-1001379436-P10-000-01-0063. Hardware / HSM / Secure StorageNoneOEM/Customer Review InterfaceSharedReady for Customer AlignmentReview + Test + table/diagram context review
SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (Cybersecurity domain; allocated to Security Services; security capability: Certificate handling; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042. Key and Certificate HandlingCertificate handlingOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test + table/diagram context review
SSR-LIFE-001Lifecycle / Field Return / Decommissioning — Lifecycle / Field Return / DecommissioningThe ECU and supplier process shall handle lifecycle, field return and decommissioning for Lifecycle / Field Return / Decommissioning, including secure data and key handling (Hardware domain; allocated to Hardware Platform).From this PDF: RFQX-1001379436-P10-000-01-0062. Lifecycle / Field Return / DecommissioningNoneNoneSupplier-OwnedReady for Internal ReviewReview + Test
SSR-LOG-001Security Logging and Event Handling — Security Logging and Event HandlingThe ECU shall record bounded security-relevant events for Security Logging and Event Handling with sufficient integrity and context for diagnostics and incident evidence (Cybersecurity domain; allocated to Security Services; security capability: Logging and audit trail).From this PDF: RFQX-1001379436-P10-000-01-0067. Security Logging and Event HandlingLogging and audit trailNoneSupplier-OwnedCandidateReview + Test
SSR-PROD-001Supplier Development and Production Hardening — Supplier Development and Production HardeningThe ECU and production process shall enforce development/production hardening for Supplier Development and Production Hardening, including debug lock and protected access (Hardware domain; allocated to Hardware Platform).From this PDF: RFQX-1001379436-P10-000-01-0029. Supplier Development and Production HardeningNoneNoneSupplier-OwnedCandidateReview + Test
SSR-SYS-001System Function — System FunctionThe ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (System domain; allocated to System Core; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0028; RFQX-1001379436-P10-000-01-0038; RFQX-1001379436-P10-000-01-0039; RFQX-1001379436-P10-000-01-0040; RFQX-1001379436-P10-000-01-0043; RFQX-1001379436-P10-000-01-0051; RFQX-1001379436-P10-000-01-0059; RFQX-1001379436-P10-000-01-0061. System FunctionNoneOEM/Customer Review InterfaceSupplier-OwnedCandidateTest + table/diagram context review
SSR-VIH-001Vulnerability and Incident Handling — Vulnerability and Incident HandlingThe supplier shall support vulnerability monitoring and incident handling for Vulnerability and Incident Handling over the defined lifecycle, including field updates (Cybersecurity domain; allocated to Security Services; security capability: Vulnerability management; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0048. Vulnerability and Incident HandlingVulnerability managementOEM/Customer Review InterfaceSupplier-OwnedCandidateReview + Test + table/diagram context review
SSR-VIH-002Vulnerability and Incident Handling — Vulnerability and Incident HandlingThe supplier shall support vulnerability monitoring and incident handling for Vulnerability and Incident Handling over the defined lifecycle, including field updates (Process / compliance domain; allocated to Compliance Process; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050. Vulnerability and Incident HandlingNoneOEM/Customer Review InterfaceSupplier-OwnedCandidateReview + Test
SSR-VIH-003Vulnerability and Incident Handling — Vulnerability and Incident HandlingThe supplier shall support vulnerability monitoring and incident handling for Vulnerability and Incident Handling over the defined lifecycle, including field updates (System domain; allocated to System Core; interface: OEM/Customer Review Interface).From this PDF: RFQX-1001379436-P10-000-01-0054; RFQX-1001379436-P10-000-01-0055. Vulnerability and Incident HandlingNoneOEM/Customer Review InterfaceSharedReady for Customer AlignmentReview + Test
SSR-VIH-004Vulnerability and Incident Handling — Vulnerability and Incident HandlingThe supplier shall support vulnerability monitoring and incident handling for Vulnerability and Incident Handling over the defined lifecycle, including field updates (Interface domain; allocated to External Interfaces; interface: External Interfaces).From this PDF: RFQX-1001379436-P10-000-01-0058. Vulnerability and Incident HandlingNoneExternal InterfacesSupplier-OwnedCandidateReview + Test

System / Security Design Impact

Impact AreaEvidence From This PDF
Impacted system featuresSecurity evidence and traceability
Impacted interfacesExternal Interfaces; OEM/Customer Review Interface; OEM/Customer Review Interface
Impacted security capabilitiesAuthentication; Cybersecurity requirement handling; Incident response; Key management; Logging and audit trail; Vulnerability management
Impacted architecture elementsApplication Software; OEM/Customer Review Interface; Compliance Process; Compliance Process; OEM/Customer Review Interface; External Interfaces; OEM/Customer Review Interface; Hardware Platform; Hardware Platform; OEM/Customer Review Interface; Security Services; Security Services; OEM/Customer Review Interface; System Core; System Core; OEM/Customer Review Interface
Impacted work productsCybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; System/architecture design
Tools / IT / hardware / testHigh/Low/Low; Low/High/Low; Low/Low/High; Low/Low/Low; Low/Low/Medium; Medium/Low/High; Medium/Low/Low; Medium/Low/Medium
Design assumptions introducedSecurity-relevant requirement the ECU can own once responsibility/method is confirmed. Linked source table/diagram context was considered for interpretation.; Security-relevant requirement the ECU can own once responsibility/method is confirmed.
Design decisions requiredConfirm with customer whether this is a binding requirement and assign a customer ID.

Estimation / Resource / Tooling Impact

ImpactStatus
Estimation impactyes
Resource/tool/IT/HW/test impactHigh/Low/Low; Low/High/Low; Low/Low/High; Low/Low/Low; Low/Low/Medium; Medium/Low/High; Medium/Low/Low; Medium/Low/Medium

Document Impact Diagram

Document Impact

Generated from document-specific requirement, traceability, SSR, and open-point evidence.

flowchart LR doc["1001379436_P10_000_01_RDDM-1140152501-1744.pdf"] d0["Authentication"] doc --> d0 d1["Cybersecurity requirement handling"] doc --> d1 d2["Incident response"] doc --> d2 f0["Feature: Security evidence and traceability"] doc --> f0 i0["Interface: External Interfaces; OEM/Customer Review Interface"] doc --> i0 i1["Interface: OEM/Customer Review Interface"] doc --> i1 s0["SSR: SSR-COM-001"] doc --> s0 s1["SSR: SSR-COM-002"] doc --> s1 s2["SSR: SSR-COM-003"] doc --> s2 o0["Open point: OP-003"] doc --> o0 o1["Open point: OP-006"] doc --> o1 o2["Open point: OP-008"] doc --> o2
Mermaid source
flowchart LR
  doc["1001379436_P10_000_01_RDDM-1140152501-1744.pdf"]
  d0["Authentication"]
  doc --> d0
  d1["Cybersecurity requirement handling"]
  doc --> d1
  d2["Incident response"]
  doc --> d2
  f0["Feature: Security evidence and traceability"]
  doc --> f0
  i0["Interface: External Interfaces; OEM/Customer Review Interface"]
  doc --> i0
  i1["Interface: OEM/Customer Review Interface"]
  doc --> i1
  s0["SSR: SSR-COM-001"]
  doc --> s0
  s1["SSR: SSR-COM-002"]
  doc --> s1
  s2["SSR: SSR-COM-003"]
  doc --> s2
  o0["Open point: OP-003"]
  doc --> o0
  o1["Open point: OP-006"]
  doc --> o1
  o2["Open point: OP-008"]
  doc --> o2

Source Traceability

Source document

1001379436_P10_000_01_RDDM-1140152501-1744.pdf

Document type

Cybersecurity Requirement Standard

Domain

Cybersecurity

Generated records

46 requirements, 1 information, 17 SSRs

Linked artifacts

4 tables, 0 diagrams

Evidence basis

Markdown-derived requirements and registers; OCR disabled; no downstream PDF analysis

Requirement to SSR Traceability

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Customer RequirementSSRDispositionConfidenceReason
RFQX-1001379436-P10-000-01-0001NoneInformational Onlyn/aNon-binding; not derived.
RFQX-1001379436-P10-000-01-0002NoneInformational Onlyn/aNon-binding; not derived.
RFQX-1001379436-P10-000-01-0003NoneNeeds Internal Reviewn/aLow confidence / human review before derivation.
RFQX-1001379436-P10-000-01-0004NoneCovered by Existing Supplier System Requirementn/aAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0005NoneCovered by Existing Supplier System Requirementn/aAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0006NoneInformational Onlyn/aNon-binding; not derived.
RFQX-1001379436-P10-000-01-0007SSR-CON-001Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0008SSR-VIH-001Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0009NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0010NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0011NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0012SSR-CON-002Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0013SSR-CON-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0014NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0015SSR-CON-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0016NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0017SSR-CON-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0018SSR-CON-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0019SSR-CON-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0020NoneInformational Onlyn/aNon-binding; not derived.
RFQX-1001379436-P10-000-01-0021SSR-CON-003Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0022SSR-HW-001Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0023NoneInformational Onlyn/aNon-binding; not derived.
RFQX-1001379436-P10-000-01-0024SSR-CON-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0025SSR-DAI-001Derive Supplier System RequirementLowAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0026NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0027SSR-CON-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0028SSR-SYS-001Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0029SSR-PROD-001Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0030SSR-COM-001Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0031SSR-COM-002Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0032SSR-COM-003Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0033NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0034SSR-COM-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0035NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0036SSR-COM-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-1001379436-P10-000-01-0037SSR-CON-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0038SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0039SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0040SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0041SSR-KEY-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-1001379436-P10-000-01-0042SSR-KEY-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0043SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0044SSR-CON-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0045SSR-CON-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0046SSR-CON-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0047SSR-VIH-002Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0048SSR-VIH-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0049SSR-VIH-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0050SSR-VIH-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0051SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0052NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0053NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0054SSR-VIH-003Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-1001379436-P10-000-01-0055SSR-VIH-003Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0056NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0057NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0058SSR-VIH-004Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0059SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0060SSR-HW-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0061SSR-SYS-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
RFQX-1001379436-P10-000-01-0062SSR-LIFE-001Derive Supplier System RequirementHighAccepted requirement; seed of its SSR cluster.
RFQX-1001379436-P10-000-01-0063SSR-HW-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
RFQX-1001379436-P10-000-01-0064NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0065NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0066NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
RFQX-1001379436-P10-000-01-0067SSR-LOG-001Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.

Next Actions

Resolve 4 open clarification point(s) with the customer

Blocks the agreement baseline until confirmed.

Confirm 20 critical requirement(s) with the customer

High impact on concept, design, estimation, or SSR derivation.

Review derived supplier system requirements

Validate allocation, responsibility, and verification intent.

Detailed Evidence

Document intelligence markdown

1001379436_P10_000_01_RDDM-1140152501-1744

  • Source PDF: 1001379436_P10_000_01_RDDM-1140152501-1744.pdf
  • Converted Markdown: converted/markdown/source document
  • Document type: Cybersecurity Requirement Standard
  • Domain: Cybersecurity
  • Confidence: High
  • Evidence basis: Markdown-derived requirements and generated RFQX registers; no downstream PDF analysis.

Executive Summary

Scope: this cybersecurity requirement standard specifies requirement, covering 2.1 Development process; 2.1.3 Cybersecurity concept; 2.1.5 Documentation; 2.2 System requirements; 2.2.3 Cryptographic libraries; 2.4 Information security. System boundary and interfaces: the document constrains 2 interface(s) - OEM/Customer Review Interface; External Interfaces; OEM/Customer Review Interface; principal functions in scope are Security evidence and traceability.

Engineering obligations: 46 confirmed customer requirement(s) carry an explicit ID and normative wording and must be implemented and verified; 15 further requirement-like statement(s) have no customer ID and must be clarified before they can be baselined; 1 informational and 5 reference item(s) were separated out as non-binding. Design and security impact: affects Security evidence and traceability; security capabilities touched: Cybersecurity requirement handling; Vulnerability management; Authentication; Key management (sample: 4 of 6); 17 supplier system requirement(s) were derived from this document.

Open for the customer: 4 document-linked open point(s) - mainly Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.; Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy). (sample: 3 of 4) - plus 15 unidentified requirement-like statement(s). Do not baseline these until the customer confirms. Confidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used.

Document Abstract

FieldInterpretation
Document PurposeScope: this cybersecurity requirement standard specifies requirement, covering 2.1 Development process; 2.1.3 Cybersecurity concept; 2.1.5 Documentation; 2.2 System requirements; 2.2.3 Cryptographic libraries; 2.4 Information security.
Engineering InterpretationSystem boundary and interfaces: the document constrains 2 interface(s) - OEM/Customer Review Interface; External Interfaces; OEM/Customer Review Interface; principal functions in scope are Security evidence and traceability.
Supplier Proposal ImpactEngineering obligations: 46 confirmed customer requirement(s) carry an explicit ID and normative wording and must be implemented and verified; 15 further requirement-like statement(s) have no customer ID and must be clarified before they can be baselined; 1 informational and 5 reference item(s) were separated out as non-binding.
System / Security ImpactDesign and security impact: affects Security evidence and traceability; security capabilities touched: Cybersecurity requirement handling; Vulnerability management; Authentication; Key management (sample: 4 of 6); 17 supplier system requirement(s) were derived from this document.
Customer Clarification ImpactOpen for the customer: 4 document-linked open point(s) - mainly Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.; Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.; Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy). (sample: 3 of 4) - plus 15 unidentified requirement-like statement(s). Do not baseline these until the customer confirms.
Confidence and LimitsConfidence and limits: High confidence. Categorisation is derived from the converted Markdown (customer IDs, normative wording, and section context); no OCR or downstream PDF analysis is used.

Main Requirement Themes

ThemeSummaryRequirement CountRepresentative Requirements
RequirementGroups related document requirements into a single engineering theme.46RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012
Responsibility and customer approval modelCreates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk.46RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005
Core ECA system behaviorDefines actuator ECU behavior, drivetrain integration, electrical/mechanical constraints, and verification scope.38RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0008
System architecture designGroups related document requirements into a single engineering theme.37RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0009
Cybersecurity concept and evidenceDrives cybersecurity concept, risk treatment, verification evidence, and traceability obligations.32RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005
CybersecurityGroups related document requirements into a single engineering theme.26RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005
Cybersecurity verification reportGroups related document requirements into a single engineering theme.26RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005
Security servicesGroups related document requirements into a single engineering theme.24RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007

Document Content Structure

SectionRequirementsInformationUnknownExcludedTotal ItemsCriticalOpen PointsSSR Links
1 Introduction00005100
-- 1.4 Abbreviated terms00005100
-- 2.1 Development process1010016514
-- -- 2.1.3 Cybersecurity concept31007313
-- -- 2.1.5 Documentation70009213
-- 2.2 System requirements60007114
-- -- 2.2.3 Cryptographic libraries60007114
-- 2.4 Information security70009325
-- 2.6 Cybersecurity lifecycle230003010310
-- -- 2.6.1 Security updates80008113
-- -- 2.6.3 Vulnerability management70009325
-- -- 2.6.4 Product lifecycle60008225
-- -- 2.6.5 Logging20005412

Tables and Diagrams

ArtifactTypeCaptionPageRelated RequirementsImpact
TABLE-1001379436P1000001RDDM11-0001TableTable 1: Definition of termspage 3RFQX-1001379436-P10-000-01-0003Table source context
TABLE-1001379436P1000001RDDM11-0002TableTable 2: Abbreviated termspage 3RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008Security protocol or cryptographic context
TABLE-1001379436P1000001RDDM11-0003TableTable 3: Bibliographypage 15NoneTable source context
TABLE-1001379436P1000001RDDM11-0004TableTable 4: History of the documentpage 16NoneTable source context

What this document does not confirm

Customer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.

Critical Requirements

IDScoreCategoryReasonStatement
RFQX-1001379436-P10-000-01-001081High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationDocumentation on the method and results shall be provided to the vehicle manufacturer.
RFQX-1001379436-P10-000-01-001181High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationNote: The vehicle manufacturer and supplier shall collaboratively define the context of the system or function to enable the supplier performing the risk assessment.
RFQX-1001379436-P10-000-01-001481High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationFor each risk identified in the cybersecurity risk analyses, a risk treatment decision shall be made to avoid, reduce, share, or retain the risk.
RFQX-1001379436-P10-000-01-001681High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationIt shall be possible to verify which cybersecurity controls were derived from which requirements.
RFQX-1001379436-P10-000-01-003581High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationThe details shall be agreed upon between the vehicle manufacturer and the supplier.
RFQX-1001379436-P10-000-01-005681High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationThe information shall contain • the version(s) of affected hardware or software components, • nature of the vulnerability, • description of the affected cybersecurity goal, • technical conditions to exploit the vulnerability, • impact of the exploitation and • possibilities to remove the vulnerability.
RFQX-1001379436-P10-000-01-004177High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactIt shall be possible for the vehicle manufacturer to securely inject key material and other data used for cybersecurity controls into the ECU according to the specification of the vehicle manufacturer.
RFQX-1001379436-P10-000-01-000966High risk due to unclear OEM/supplier responsibilityarchitecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationMethod and scope shall be proposed to and approved by the vehicle manufacturer.
RFQX-1001379436-P10-000-01-002666High risk due to unclear OEM/supplier responsibilityarchitecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationMethods shall be proposed to and approved by the vehicle manufacturer.
RFQX-1001379436-P10-000-01-003366High risk due to unclear OEM/supplier responsibilityarchitecture relevant; Needs Customer Clarification; linked open point; blocks SSR derivationMethods shall be proposed and approved by the vehicle manufacturer.

Open Points

Open PointPriorityQuestionImpactStatus
OP-003Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.Open
OP-006Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier.Lifecycle effort and field-response capability stay unbounded; risk of an R155 compliance gap.Open
OP-008Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy).Hardware fusing and EOL process design stay open; risk of an exposed debug/production interface.Open
OP-011Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.Open

Supplier System Requirements

SSRTitleStatementReqs From This PDFOther PDFsStatus
SSR-COM-001OEM/Customer Review Interface — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for OEM/Customer Review Interface, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (Hardware domain; allocated to Hardware Platform; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0036noReady for Customer Alignment
SSR-COM-002Secure Communication and Boundary Control — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure Communication and Boundary Control, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (System domain; allocated to System Core).RFQX-1001379436-P10-000-01-0031; RFQX-1001379436-P10-000-01-0034noCandidate
SSR-COM-003OEM/Customer Review Interface — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for OEM/Customer Review Interface, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals (System domain; allocated to System Core; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0032noCandidate
SSR-CON-001Security evidence and traceability — Cybersecurity Concept and EvidenceThe supplier shall produce and maintain the cybersecurity concept and verification evidence covering Security evidence and traceability (Cybersecurity domain; allocated to Security Services; security capability: Cybersecurity requirement handling; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019noCandidate
SSR-CON-002Cybersecurity Concept and Evidence — Cybersecurity Concept and EvidenceThe supplier shall produce and maintain the cybersecurity concept and verification evidence covering Cybersecurity Concept and Evidence (Cybersecurity domain; allocated to Security Services; security capability: Cybersecurity requirement handling; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0027; RFQX-1001379436-P10-000-01-0037; RFQX-1001379436-P10-000-01-0044; RFQX-1001379436-P10-000-01-0045; RFQX-1001379436-P10-000-01-0046noReady for Customer Alignment
SSR-CON-003Security evidence and traceability — Cybersecurity Concept and EvidenceThe supplier shall produce and maintain the cybersecurity concept and verification evidence covering Security evidence and traceability (Software domain; allocated to Application Software; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0021noCandidate
SSR-DAI-001Data Authenticity and Integrity Verification — Data Authenticity and Integrity VerificationThe ECU shall verify the authenticity and integrity of Data Authenticity and Integrity Verification data and reject manipulated or unauthenticated data (Cybersecurity domain; allocated to Security Services; security capability: Authentication; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0025noBlocked by Customer Clarification
SSR-HW-001Hardware / HSM / Secure Storage — Hardware / HSM / Secure StorageThe ECU hardware shall provide the platform and secure-storage capabilities required for Hardware / HSM / Secure Storage (Hardware domain; allocated to Hardware Platform; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0022; RFQX-1001379436-P10-000-01-0060; RFQX-1001379436-P10-000-01-0063noReady for Customer Alignment
SSR-KEY-001Key and Certificate Handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key and Certificate Handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle (Cybersecurity domain; allocated to Security Services; security capability: Certificate handling; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0041; RFQX-1001379436-P10-000-01-0042noBlocked by Customer Clarification
SSR-LIFE-001Lifecycle / Field Return / Decommissioning — Lifecycle / Field Return / DecommissioningThe ECU and supplier process shall handle lifecycle, field return and decommissioning for Lifecycle / Field Return / Decommissioning, including secure data and key handling (Hardware domain; allocated to Hardware Platform).RFQX-1001379436-P10-000-01-0062noReady for Internal Review
SSR-LOG-001Security Logging and Event Handling — Security Logging and Event HandlingThe ECU shall record bounded security-relevant events for Security Logging and Event Handling with sufficient integrity and context for diagnostics and incident evidence (Cybersecurity domain; allocated to Security Services; security capability: Logging and audit trail).RFQX-1001379436-P10-000-01-0067noCandidate
SSR-PROD-001Supplier Development and Production Hardening — Supplier Development and Production HardeningThe ECU and production process shall enforce development/production hardening for Supplier Development and Production Hardening, including debug lock and protected access (Hardware domain; allocated to Hardware Platform).RFQX-1001379436-P10-000-01-0029noCandidate
SSR-SYS-001System Function — System FunctionThe ECU shall implement the System Function behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing (System domain; allocated to System Core; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0028; RFQX-1001379436-P10-000-01-0038; RFQX-1001379436-P10-000-01-0039; RFQX-1001379436-P10-000-01-0040; RFQX-1001379436-P10-000-01-0043; RFQX-1001379436-P10-000-01-0051; RFQX-1001379436-P10-000-01-0059; RFQX-1001379436-P10-000-01-0061noCandidate
SSR-VIH-001Vulnerability and Incident Handling — Vulnerability and Incident HandlingThe supplier shall support vulnerability monitoring and incident handling for Vulnerability and Incident Handling over the defined lifecycle, including field updates (Cybersecurity domain; allocated to Security Services; security capability: Vulnerability management; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0048noCandidate
SSR-VIH-002Vulnerability and Incident Handling — Vulnerability and Incident HandlingThe supplier shall support vulnerability monitoring and incident handling for Vulnerability and Incident Handling over the defined lifecycle, including field updates (Process / compliance domain; allocated to Compliance Process; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050noCandidate
SSR-VIH-003Vulnerability and Incident Handling — Vulnerability and Incident HandlingThe supplier shall support vulnerability monitoring and incident handling for Vulnerability and Incident Handling over the defined lifecycle, including field updates (System domain; allocated to System Core; interface: OEM/Customer Review Interface).RFQX-1001379436-P10-000-01-0054; RFQX-1001379436-P10-000-01-0055noReady for Customer Alignment
SSR-VIH-004Vulnerability and Incident Handling — Vulnerability and Incident HandlingThe supplier shall support vulnerability monitoring and incident handling for Vulnerability and Incident Handling over the defined lifecycle, including field updates (Interface domain; allocated to External Interfaces; interface: External Interfaces).RFQX-1001379436-P10-000-01-0058noCandidate

Design Impact

  • Impacted System Features: Security evidence and traceability
  • Impacted Interfaces: External Interfaces; OEM/Customer Review Interface; OEM/Customer Review Interface
  • Impacted Security Capabilities: Authentication; Cybersecurity requirement handling; Incident response; Key management; Logging and audit trail; Vulnerability management
  • Impacted Architecture Elements: Application Software; OEM/Customer Review Interface; Compliance Process; Compliance Process; OEM/Customer Review Interface; External Interfaces; OEM/Customer Review Interface; Hardware Platform; Hardware Platform; OEM/Customer Review Interface; Security Services; Security Services; OEM/Customer Review Interface (sample: 8 of 10)
  • Impacted Work Products: Cybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; System/architecture design
  • Impacted Document Artifacts: TABLE-1001379436P1000001RDDM11-0001; TABLE-1001379436P1000001RDDM11-0002
  • Impacted Tools It Hardware Test: High/Low/Low; Low/High/Low; Low/Low/High; Low/Low/Low; Low/Low/Medium; Medium/Low/High; Medium/Low/Low; Medium/Low/Medium
  • Impacted Supplier System Requirements: SSR-COM-001; SSR-COM-002; SSR-COM-003; SSR-CON-001; SSR-CON-002; SSR-CON-003; SSR-DAI-001; SSR-HW-001 (sample: 8 of 17)
  • Design Assumptions Introduced: Security-relevant requirement the ECU can own once responsibility/method is confirmed. Linked source table/diagram context was considered for interpretation.; Security-relevant requirement the ECU can own once responsibility/method is confirmed.
  • Design Decisions Required: Confirm with customer whether this is a binding requirement and assign a customer ID.