Open Decisions

Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.

Last updated: 2026-06-29 11:49
RTRFQX Review TeamWorkspace

Open Decisions

Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.

Open Decisions

Classification: Needs Customer Clarification

These decisions block customer-ready architecture approval because the extracted requirements do not confirm enough implementation detail.

Customer Clarification Points

  • Confirm exact ECU item definition, product designation, variants, and vehicle-function allocation.
  • Confirm in-scope interfaces: diagnostic, vehicle network, backend/update, PKI, tooling, and security operations.
  • Confirm assets, trust boundaries, TARA scope, risk treatment, and residual-risk approval workflow.
  • Confirm mechanism details for authentication, certificates, key storage, secure update, secure boot, logging, and monitoring.

Requirement-Level Human Review Items

  • RFQX-1001379436-P10-000-01-0001 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-1001379436-P10-000-01-0002 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-1001379436-P10-000-01-0003 (High): Review possible noise/boilerplate contamination.
  • RFQX-1001379436-P10-000-01-0004 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-1001379436-P10-000-01-0006 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-1001379436-P10-000-01-0011 (Medium): Review possible noise/boilerplate contamination.
  • RFQX-1001379436-P10-000-01-0020 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-1001379436-P10-000-01-0023 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0003 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0005 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0006 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0020 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0023 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0046 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0048 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0053 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0080 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0095 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0098 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0099 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0100 (Low): Confirm whether this statement is a binding requirement. | Review possible noise/boilerplate contamination.
  • RFQX-3299216-1-0108 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0127 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0128 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0129 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0130 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0133 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0141 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0147 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0151 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0152 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0155 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0156 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0157 (Low): Confirm whether this statement is a binding requirement. | Clarify ambiguous or incomplete source wording.
  • RFQX-3299216-1-0158 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0159 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0173 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0197 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0222 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0223 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0224 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0225 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0226 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0227 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0229 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0230 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0231 (Low): Confirm whether this statement is a binding requirement. | Clarify ambiguous or incomplete source wording.
  • RFQX-3299216-1-0232 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0233 (Low): Confirm whether this statement is a binding requirement. | Clarify ambiguous or incomplete source wording.
  • RFQX-3299216-1-0234 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0235 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0236 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0237 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0238 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0239 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0240 (Low): Confirm whether this statement is a binding requirement. | Clarify ambiguous or incomplete source wording.
  • RFQX-3299216-1-0241 (Low): Confirm whether this statement is a binding requirement. | Clarify ambiguous or incomplete source wording.
  • RFQX-3299216-1-0242 (Low): Confirm whether this statement is a binding requirement. | Clarify ambiguous or incomplete source wording.
  • RFQX-3299216-1-0243 (Low): Confirm whether this statement is a binding requirement. | Clarify ambiguous or incomplete source wording.
  • RFQX-3299216-1-0244 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0246 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0247 (Low): Confirm whether this statement is a binding requirement. | Clarify ambiguous or incomplete source wording.
  • RFQX-3299216-1-0248 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0249 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0250 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0251 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0252 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0253 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0254 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0255 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0257 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0258 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0259 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0260 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0261 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0262 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0263 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0264 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0265 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0266 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0267 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0268 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0269 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0270 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0271 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0272 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0273 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0274 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0275 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0276 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0277 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0278 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0284 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0301 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0307 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0308 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-3299216-1-0309 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0001 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0004 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0005 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0006 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0007 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0008 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0009 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0012 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0013 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0015 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0016 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0017 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0018 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0025 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0026 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0027 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0028 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0031 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0032 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0033 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0038 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0045 (Low): Confirm whether this statement is a binding requirement.
  • RFQX-CVS123-2-0054 (Low): Confirm whether this statement is a binding requirement.
  • Remaining review items are listed in analysis/source document (showing 120 of 810 here).

Architecture Open Decisions

  • Needs Customer Clarification: Confirm exact ECU item definition, product designation, and variants.
  • Needs Customer Clarification: Confirm vehicle network topology, SecOC/SDT applicability, signals, and protection profiles.
  • Needs Customer Clarification: Confirm diagnostic service list, UDS Authentication 0x29 role model, certificate use, lockout, and audit expectations.
  • Needs Customer Clarification: Confirm secure update/flash/IVD mechanism, signing chain, backend ownership, and rollback behavior.
  • Needs Customer Clarification: Confirm key hierarchy, HSM/protected storage capability, PKI ownership, revocation, renewal, and provisioning process.
  • Needs Customer Clarification: Confirm security monitoring, incident response handoff, and vulnerability reporting channels.
  • Needs Customer Clarification: Confirm final TARA results and customer residual-risk acceptance workflow.

Security Open Decisions

  • Needs Customer Clarification: Confirm ownership and control allocation for Electric Clutch Actuator ECU boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Vehicle/network boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Diagnostic access boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Backend/cloud boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Development/tooling boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Customer/OEM approval boundary.
  • Needs Customer Clarification: Confirm ownership and control allocation for Unknown assumed deployment boundary.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Cryptographic Protection.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Secure Communication.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Secure Boot and Platform Integrity.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Secure Software Update.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Security Monitoring and Detection.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Development and Toolchain Security.
  • Inferred from Requirements: Confirm concrete mechanism and verification evidence for Backend/Cloud Security.

Interface Open Questions

  • Inferred from Requirements: Vehicle network secure data communication interface needs customer confirmation for exact topology, ownership, and mechanism details.
  • Inferred from Requirements: Secure update, flash, and IVD interface needs customer confirmation for exact topology, ownership, and mechanism details.
  • Inferred from Requirements: Backend/cloud/IT operational interface needs customer confirmation for exact topology, ownership, and mechanism details.
  • Inferred from Requirements: Application software to security services interface needs customer confirmation for exact topology, ownership, and mechanism details.
  • Inferred from Requirements: Hardware platform and key storage interface needs customer confirmation for exact topology, ownership, and mechanism details.

Product Unknowns and Assumptions

Unknowns and Assumptions

  • Needs Customer Clarification: Exact product name, ECU variant, and vehicle function allocation.
  • Needs Customer Clarification: Exact vehicle network topology, messages, signals, and data classification.
  • Needs Customer Clarification: Exact diagnostic role model, UDS service scope, certificates, and lockout/rate-limit behavior.
  • Needs Customer Clarification: Exact update mechanism, signing chain, IVD ownership, rollback policy, and backend responsibilities.
  • Needs Customer Clarification: Exact key hierarchy, HSM/protected-storage capability, certificate lifecycle, and PKI ownership.
  • Needs Customer Clarification: Final TARA results, risk treatment decisions, and customer residual-risk acceptance.
  • Expert Assumption: Until clarified, diagrams mark these elements as inferred or assumption-based rather than confirmed implementation.