Product Understanding
Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.
Product Summary
Executive Interpretation
Classification: Inferred from Requirements
The package describes the Electric Clutch Actuator (ECA) Control ECU for the TRATON GW Automated Manual Transmission (AMT) Gearbox Platform. The clutch-actuation function (CAN/PWM-commanded engage/disengage with position control and error handling) is explicit in the requirements. The requirement set is dominated by cybersecurity obligations: diagnostic access security, secure communication/data protection, certificate/key handling, secure update or flash readiness, backend/tooling evidence, and customer/OEM approval of residual risk. The exact security-control bindings, key hierarchy, and final item definition are not yet confirmed by the extracted requirements.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ-AUTO-00004; REQ-AUTO-00005; REQ-AUTO-00006; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023 (showing 10 of 371)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11 (showing 8 of 139)
- Confidence level: Medium
- Classification: Inferred from Requirements
What the System Appears to Be
Classification: Inferred from Requirements
A supplier-delivered 24V electric clutch actuator ECU with its own embedded controller, common across the TRATON GW AMT driveline range, surrounded by offboard engineering, backend, and OEM/customer evidence flows.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ-AUTO-00004; REQ-AUTO-00005; REQ-AUTO-00006; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023 (showing 10 of 371)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11 (showing 8 of 139)
- Confidence level: Medium
- Classification: Inferred from Requirements
What the System Is Responsible For
Classification: Explicit Requirement / Inferred from Requirements
- Provide and document a cybersecurity concept, risk-assessment input, controls, validation, verification, and residual-risk evidence.
- Support secure diagnostic access, authentication, certificate/key handling, and protected vehicle data communication where required.
- Preserve ECU/software authenticity and integrity through update, flash, IVD, platform, and evidence mechanisms where the requirements imply those flows.
- Maintain traceability from requirements to controls, architecture elements, and human-review decisions.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023; REQ-AUTO-00011; REQ_SEC_0024; REQ_SEC_0004 (showing 10 of 557)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11 (showing 8 of 153)
- Confidence level: Medium
- Classification: Inferred from Requirements
What the System Is Not Confirmed To Be
Classification: Needs Customer Clarification
- The complete vehicle function, ECU variant, network topology, production backend, HSM/MCU selection, and final TARA results are not confirmed.
- This package does not claim a final risk assessment or customer-approved residual-risk position.
- This package does not prove exact protocol parameters, cryptographic algorithms, key hierarchy, certificate authority model, or diagnostic role model.
Evidence Basis:
- Requirement IDs: None directly confirm these details.
- Source Markdown sections/pages: extracted requirements contain related security controls but not final implementation details.
- Confidence level: Low
- Classification: Needs Customer Clarification
Evidence Basis
- Total Markdown-derived requirements: 1076
- Cybersecurity requirements: 109
- Feature clusters synthesized: 18
- Interfaces synthesized: 10
- Source rule: synthesis uses extracted requirements and generated mappings only; PDFs are not read by this phase.
Assumptions
- Expert Assumption: Product boundary is treated as the ECU/component and its supplier-owned security engineering package until customer confirms the exact item definition.
- Expert Assumption: Backend/cloud and security-operations elements are included as architecture actors where requirements imply update, evidence, monitoring, or vulnerability workflows.
Customer Clarifications Needed
- Needs Customer Clarification: Confirm the exact ECU product designation, variant scope, and vehicle-function allocation.
- Needs Customer Clarification: Confirm in-scope vehicle networks, diagnostic services, backend services, PKI ownership, and toolchain ownership.
- Needs Customer Clarification: Confirm whether secure update, IVD, SecOC/SDT, UDS Authentication 0x29, and certificate profiles are mandatory for this RFQ scope or reference-only standards.
System Boundary
Classification: Inferred from Requirements
The working boundary is the Electric Clutch Actuator ECU security scope plus supplier-controlled engineering evidence. It includes ECU hardware/software allocation, security services, diagnostic and communication protection, update/flash readiness, and the evidence needed for OEM/customer approval. It excludes unconfirmed vehicle functions, unconfirmed backend implementation details, and final customer risk acceptance.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ-AUTO-00004; REQ-AUTO-00005; REQ-AUTO-00006; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023 (showing 10 of 371)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11 (showing 8 of 139)
- Confidence level: Medium
- Classification: Inferred from Requirements
Boundary Elements
- Inside product boundary: ECU/application software, hardware platform, security services, diagnostics, update/flash handling where applicable.
- Adjacent vehicle boundary: other ECUs, vehicle network, SecOC/SDT-protected data flows.
- Offboard boundary: backend/cloud/IT, PKI/provisioning, development tooling, evidence repository, security operations.
- Customer boundary: OEM/vehicle manufacturer approval, residual-risk agreement, review of supplier methods and results.
System Context
Classification: Inferred from Requirements
The context is an automotive ECU/component security engineering scope embedded in a vehicle ecosystem and surrounded by supplier, OEM/customer, diagnostic, backend, tooling, and security-operations actors.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ-AUTO-00004; REQ-AUTO-00005; REQ-AUTO-00006; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023 (showing 10 of 371)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11 (showing 8 of 139)
- Confidence level: Medium
- Classification: Inferred from Requirements
See architecture/system_context.mmd for the rendered context view.
External Actors
OEM/customer cybersecurity approval and evidence interface
Classification: Explicit Requirement
- Actor/interface type: Customer
- Connected elements: Supplier security engineering -> vehicle manufacturer/OEM/customer
- Role: Exchange cybersecurity concept, method, results, residual-risk position, verification evidence, and approval decisions.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ-AUTO-00004; REQ-AUTO-00005; REQ-AUTO-00006; REQ_SEC_0003; REQ_SEC_0024; REQ_SEC_0004; REQ_SEC_0005 (showing 10 of 157)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11 (showing 8 of 74)
- Confidence level: Medium
- Classification: Explicit Requirement
Diagnostic/service tool to ECU interface
Classification: Explicit Requirement
- Actor/interface type: Diagnostic
- Connected elements: Diagnostic/service tool -> ECU diagnostic server/security services
- Role: Provide service, maintenance, programming, and authenticated diagnostic access.
Evidence Basis:
- Requirement IDs: REQ_SEC_0010; REQ_SEC_0011; req-6.20; REQ-AUTO-00282; REQ-AUTO-00284; REQ-AUTO-00290; REQ_UDS-0051; REQ_UDS-0051; REQ-AUTO-00297; REQ-AUTO-00298 (showing 10 of 385)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/3299216_1.md page 23; converted/markdown-cleaned/CVS123-2.md page 4; converted/markdown-cleaned/CVS123-2.md page 6; converted/markdown-cleaned/CVS123-2.md page 7; converted/markdown-cleaned/CVS123-2.md page 9; converted/markdown-cleaned/CVS123-2.md page 10; converted/markdown-cleaned/CVS123-2.md page 11 (showing 8 of 133)
- Confidence level: Medium
- Classification: Explicit Requirement
Vehicle network secure data communication interface
Classification: Inferred from Requirements
- Actor/interface type: Vehicle Network
- Connected elements: Other ECUs / vehicle network <-> product ECU/application
- Role: Exchange vehicle-function data, protected messages, counters, and stateful request/response traffic.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00066; REQ-AUTO-00141; req-6.3; REQ-AUTO-00146; REQ-AUTO-00173; REQ-AUTO-00193; REQ-AUTO-00196; REQ-AUTO-00199; REQ-AUTO-00310; REQ-AUTO-00334 (showing 10 of 127)
- Source Markdown sections/pages: converted/markdown-cleaned/3299216_1.md page 4; converted/markdown-cleaned/3299216_1.md page 22; converted/markdown-cleaned/3299216_1.md page 23; converted/markdown-cleaned/3299216_1.md page 27; converted/markdown-cleaned/3299216_1.md page 31; converted/markdown-cleaned/3299216_1.md page 33; converted/markdown-cleaned/CVS123-2.md page 9; converted/markdown-cleaned/CVS123-2.md page 12 (showing 8 of 49)
- Confidence level: Medium
- Classification: Inferred from Requirements
Secure update, flash, and IVD interface
Classification: Inferred from Requirements
- Actor/interface type: Backend
- Connected elements: Update/flash backend or programming tool -> ECU update/boot/security services
- Role: Deliver and verify software updates, flash programming content, and integrity validation data.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00203; REQ-AUTO-00279; REQ-AUTO-00284; REQ-AUTO-00290; REQ_UDS-0051; REQ-AUTO-00297; REQ-AUTO-00298; REQ-AUTO-00302; REQ-AUTO-00303; REQ-AUTO-00306 (showing 10 of 81)
- Source Markdown sections/pages: converted/markdown-cleaned/3299216_1.md page 34; converted/markdown-cleaned/CVS123-2.md page 1; converted/markdown-cleaned/CVS123-2.md page 4; converted/markdown-cleaned/CVS123-2.md page 6; converted/markdown-cleaned/CVS123-2.md page 7; converted/markdown-cleaned/CVS123-2.md page 9; converted/markdown-cleaned/CVS123-2.md page 10; converted/markdown-cleaned/CVS123-2.md page 11 (showing 8 of 47)
- Confidence level: Medium
- Classification: Inferred from Requirements
Certificate and key provisioning interface
Classification: Explicit Requirement
- Actor/interface type: Backend
- Connected elements: PKI/provisioning authority -> ECU security services / HSM
- Role: Provision, validate, and manage certificates, trust anchors, and cryptographic key material.
Evidence Basis:
- Requirement IDs: REQ_SEC_0016; REQ_SEC_0019; REQ-AUTO-00335; REQ-AUTO-00340; REQ-AUTO-00445; REQ_UDS-0038; REQ_UDS-0068; REQ_UDS-0070; REQ_UDS-0071; REQ_UDS-0072 (showing 10 of 69)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/CVS123-2.md page 14; converted/markdown-cleaned/CVS123-2.md page 16; converted/markdown-cleaned/CVS123-2.md page 37; converted/markdown-cleaned/CVS124.md page 22; converted/markdown-cleaned/CVS124.md page 34; converted/markdown-cleaned/CVS124.md page 40; converted/markdown-cleaned/CVS151.md page 11 (showing 8 of 29)
- Confidence level: Medium
- Classification: Explicit Requirement
Backend/cloud/IT operational interface
Classification: Inferred from Requirements
- Actor/interface type: Cloud
- Connected elements: Backend/cloud/IT systems <-> supplier/OEM/product lifecycle processes
- Role: Support offboard functions such as update coordination, evidence storage, monitoring, vulnerability handling, or supplier portals.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023; REQ-AUTO-00011; REQ_SEC_0024; REQ_SEC_0004 (showing 10 of 748)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11 (showing 8 of 218)
- Confidence level: Medium
- Classification: Inferred from Requirements
Development, ALM, and evidence tooling interface
Classification: Explicit Requirement
- Actor/interface type: Tooling
- Connected elements: Engineering tools / ALM / CI / test systems -> evidence and release artifacts
- Role: Create, verify, trace, review, and archive security engineering evidence and released artifacts.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0002; REQ-AUTO-00009; REQ_SEC_0023; REQ_SEC_0004; REQ_SEC_0005; REQ_SEC_0041; REQ_SEC_0008; REQ_SEC_0026; REQ_SEC_0027 (showing 10 of 192)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 12 (showing 8 of 110)
- Confidence level: Medium
- Classification: Explicit Requirement
Security operations and vulnerability reporting interface
Classification: Explicit Requirement
- Actor/interface type: Operational
- Connected elements: Product/backend/security monitoring -> supplier and OEM security operations
- Role: Move security events, vulnerabilities, penetration-test findings, and incident information into lifecycle handling.
Evidence Basis:
- Requirement IDs: REQ_SEC_0002; REQ-AUTO-00009; REQ_SEC_0040; REQ_SEC_0041; REQ_SEC_0044; REQ_SEC_0045; REQ_SEC_0046; REQ_SEC_0032; REQ_SEC_0033; REQ_SEC_0034 (showing 10 of 25)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 12; converted/markdown-cleaned/3299216_1.md page 27; converted/markdown-cleaned/3299216_1.md page 36 (showing 8 of 16)
- Confidence level: Medium
- Classification: Explicit Requirement
High-Level Interfaces
Classification: Inferred from Requirements
The main interfaces are diagnostic/service access, vehicle network data exchange, secure update/flash/IVD handling, certificate/key provisioning, backend/IT operations, development/evidence tooling, security operations, and OEM/customer approval.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ-AUTO-00004; REQ-AUTO-00005; REQ-AUTO-00006; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023 (showing 10 of 371)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11 (showing 8 of 139)
- Confidence level: Medium
- Classification: Inferred from Requirements
See interfaces/interface_catalog.md for the full interface catalog.
Main Product Features
System Capability Matrix
| Capability | Product Role | Architecture Component | Interfaces | Security Relevance | Evidence Status | Open Decision |
|---|---|---|---|---|---|---|
| Clutch Actuation Control | Core actuator control | Application Software / System Core | Vehicle Network Interface (CAN) | Safety-relevant command/status handling | Confirmed | Confirm final variant scope |
| Vehicle Integration and CAN Communication | Vehicle command/status exchange | External Interfaces / Application Software | Vehicle Network Interface (CAN), PWM wake-up | Message authenticity/freshness allocation | Confirmed | Confirm signal catalog and SecOC/SDT scope |
| Secure Diagnostics and Role-Based Access | Controlled service and engineering access | Diagnostic Server / Security Services | Diagnostic Tester Interface | Privileged access control | Inferred | Confirm roles, service list and lockout policy |
| Secure Software Update and Flash | Maintain trusted ECU software | Bootloader / Update Logic | Update / Flash Interface, Diagnostic Tester Interface | Software authenticity and integrity | Inferred | Confirm signing chain, rollback and ownership |
| Key and Certificate Handling | Trust-material lifecycle | Security Services / Hardware Platform | PKI / Provisioning Interface | Root of trust for diagnostics, update and secure communication | Inferred | Confirm HSM capability, key hierarchy and PKI ownership |
| Secure Data Transfer / Communication Boundary | Protected security-relevant data exchange | Security Services / External Interfaces | Vehicle Network Interface, Secure Data Transfer Interface | Authenticity, integrity and freshness | Inferred | Confirm protected signals and freshness model |
| Security Logging and Event Handling | Security evidence and response input | Security Services / Backend and IT Systems | Logging / Event Reporting Interface | Auditability and incident support | Inferred | Confirm event set, storage and reporting path |
| Cybersecurity Lifecycle and Evidence | Approval-ready security case | Compliance Process / Engineering Toolchain | Supplier Evidence, OEM Approval Interface | Traceable residual-risk argument | Confirmed | Confirm DIA split and approval authority |
Capability Cards
Detailed Feature Model
This feature model groups Markdown-derived requirement clusters into system-security architecture domains. It is not a flat requirement repeat.
Core Product Capabilities
Feature: Application software behavior
Feature ID: FEAT-X001
Purpose
Define supplier-controlled software behavior that realizes the extracted system and security requirements inside the ECU or application scope.
User/System Value
Gives the product a concrete software responsibility instead of treating the RFQ as only a document checklist.
Requirement Basis
- Related requirements: REQ-AUTO-00006; REQ_SEC_0007; REQ-AUTO-00129; REQ-AUTO-00178; REQ-AUTO-00180; REQ-AUTO-00238; REQ-AUTO-00244; REQ-AUTO-00266; REQ-AUTO-00277; REQ-AUTO-00286; REQ-AUTO-00287; REQ-AUTO-00288; REQ-AUTO-00289; REQ-AUTO-00291; REQ-AUTO-00296; REQ-AUTO-00300; REQ-AUTO-00302; REQ-AUTO-00304 (showing 18 of 179)
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/3299216_1.md page 19; converted/markdown-cleaned/3299216_1.md page 27; converted/markdown-cleaned/3299216_1.md page 40; converted/markdown-cleaned/3299216_1.md page 41; converted/markdown-cleaned/3299216_1.md page 50; converted/markdown-cleaned/3299216_1.md page 59 (showing 8 of 88)
Functional Scope
Application logic, protocol handling, state handling, error handling, and allocation of software-side requirements.
Out of Scope / Not Confirmed
The exact application function, user-facing behavior, timing budget, and production ECU variant are not confirmed.
Interfaces Involved
Vehicle network, internal security services, diagnostics, backend/tooling where called by requirements.
Data Handled
Application state, protocol messages, configuration, diagnostic responses, security-relevant processing results.
Security Relevance
Software behavior is where malformed input handling, authorization decisions, freshness checks, and protected data processing become enforceable.
Related Security Capabilities
- Authorization
- Secure communication
- Logging and audit
- Secure diagnostics
Impacted Architecture Elements
- Application Software
- System Core
- Security Services
Confidence Level
Medium
Classification
Inferred from Requirements
Open Questions
- Clarify ambiguous or incomplete source wording.
- Confirm whether this statement is a binding requirement.
- Review possible noise/boilerplate contamination.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00006; REQ_SEC_0007; REQ-AUTO-00129; REQ-AUTO-00178; REQ-AUTO-00180; REQ-AUTO-00238; REQ-AUTO-00244; REQ-AUTO-00266; REQ-AUTO-00277; REQ-AUTO-00286 (showing 10 of 179)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/3299216_1.md page 19; converted/markdown-cleaned/3299216_1.md page 27; converted/markdown-cleaned/3299216_1.md page 40; converted/markdown-cleaned/3299216_1.md page 41; converted/markdown-cleaned/3299216_1.md page 50; converted/markdown-cleaned/3299216_1.md page 59 (showing 8 of 88)
- Confidence level: Medium
- Classification: Inferred from Requirements
Feature: Secure communication
Feature ID: FEAT-X002
Purpose
Address the extracted requirement cluster named Secure communication.
User/System Value
Provides a traceable product capability from the current requirements.
Requirement Basis
- Related requirements: REQ-AUTO-00455
- Source sections/pages: converted/markdown-cleaned/CVS123-2.md page 40
Functional Scope
Scope is limited to requirements extracted from cleaned Markdown.
Out of Scope / Not Confirmed
Detailed behavior needs customer confirmation.
Interfaces Involved
Unknown until interface allocation is confirmed.
Data Handled
Unknown or requirement-specific data.
Security Relevance
Security relevance needs detailed review.
Related Security Capabilities
- Needs Customer Clarification
Impacted Architecture Elements
- System Core
Confidence Level
Medium
Classification
Needs Customer Clarification
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00455
- Source Markdown sections/pages: converted/markdown-cleaned/CVS123-2.md page 40
- Confidence level: Medium
- Classification: Needs Customer Clarification
Feature: System behavior
Feature ID: FEAT-X003
Purpose
Capture the expected behavior of the Electric Clutch Actuator ECU boundary before decomposing it into hardware, software, tooling, and operations.
User/System Value
Keeps the system-level intent visible while detailed requirements remain traceable.
Requirement Basis
- Related requirements: REQ-AUTO-00004; REQ-AUTO-00005; REQ-AUTO-00021; REQ_SEC_0020; REQ_SEC_0012; REQ_SEC_0013; REQ-AUTO-00028; REQ_SEC_0014; REQ-AUTO-00030; REQ_SEC_0028; REQ_SEC_0029; REQ_SEC_0006; REQ_SEC_0021; REQ_SEC_0044; REQ_SEC_0046; REQ_SEC_0032; REQ_SEC_0033; REQ-AUTO-00047 (showing 18 of 388)
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 12; converted/markdown-cleaned/3299216_1.md page 3 (showing 8 of 153)
Functional Scope
System behavior, stakeholder approvals, compliance obligations, timing/state requirements, and customer-facing deliverables.
Out of Scope / Not Confirmed
The package does not prove the complete vehicle function or end-user feature set.
Interfaces Involved
OEM/customer interface, vehicle network, supplier engineering flow, evidence flow.
Data Handled
Requirements, system states, approvals, evidence, release information.
Security Relevance
System behavior defines where security objectives attach and where residual risks must be agreed.
Related Security Capabilities
- Compliance and evidence management
- Vulnerability and incident handling
Impacted Architecture Elements
- System Core
- Compliance Process
Confidence Level
Medium
Classification
Inferred from Requirements
Open Questions
- Clarify ambiguous or incomplete source wording.
- Confirm whether this statement is a binding requirement.
- Review possible noise/boilerplate contamination.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00004; REQ-AUTO-00005; REQ-AUTO-00021; REQ_SEC_0020; REQ_SEC_0012; REQ_SEC_0013; REQ-AUTO-00028; REQ_SEC_0014; REQ-AUTO-00030; REQ_SEC_0028 (showing 10 of 388)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 12; converted/markdown-cleaned/3299216_1.md page 3 (showing 8 of 153)
- Confidence level: Medium
- Classification: Inferred from Requirements
Vehicle/ECU Integration Capabilities
Feature: Hardware platform support
Feature ID: FEAT-X004
Purpose
Represent ECU hardware, platform, connector, memory, and security hardware obligations implied by the source requirements.
User/System Value
Makes clear that the cybersecurity concept must be allocated across both hardware and software.
Requirement Basis
- Related requirements: REQ_SEC_0025; REQ_SEC_0010; REQ_SEC_0011; REQ_SEC_0026; REQ_SEC_0047; REQ_SEC_0049; REQ_SEC_0050; REQ-AUTO-00060; REQ-AUTO-00061; REQ-AUTO-00065; REQ-AUTO-00077; REQ-AUTO-00099; REQ-AUTO-00113; REQ-AUTO-00182; REQ-AUTO-00184; Req.ID-Connector-Requirements-7.5; REQ-AUTO-00187; REQ-AUTO-00227 (showing 18 of 45)
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 12; converted/markdown-cleaned/3299216_1.md page 4; converted/markdown-cleaned/3299216_1.md page 7; converted/markdown-cleaned/3299216_1.md page 11; converted/markdown-cleaned/3299216_1.md page 15 (showing 8 of 36)
Functional Scope
ECU platform support, hardware protection, debug/physical exposure concerns, and implementation allocation.
Out of Scope / Not Confirmed
The exact MCU, HSM, memory map, connector pinout, and production hardware variant are not confirmed.
Interfaces Involved
Internal hardware/software interface, diagnostic access boundary, physical/service access.
Data Handled
Keys, certificates, firmware, platform state, debug/service data.
Security Relevance
Hardware is part of key protection, secure boot, anti-tamper posture, and diagnostic attack resistance.
Related Security Capabilities
- Secure boot and platform integrity
- Key management
- Secure diagnostics
Impacted Architecture Elements
- Hardware Platform
- Security Services
Confidence Level
Medium
Classification
Inferred from Requirements
Open Questions
- Clarify ambiguous or incomplete source wording.
Evidence Basis:
- Requirement IDs: REQ_SEC_0025; REQ_SEC_0010; REQ_SEC_0011; REQ_SEC_0026; REQ_SEC_0047; REQ_SEC_0049; REQ_SEC_0050; REQ-AUTO-00060; REQ-AUTO-00061; REQ-AUTO-00065 (showing 10 of 45)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 12; converted/markdown-cleaned/3299216_1.md page 4; converted/markdown-cleaned/3299216_1.md page 7; converted/markdown-cleaned/3299216_1.md page 11; converted/markdown-cleaned/3299216_1.md page 15 (showing 8 of 36)
- Confidence level: Medium
- Classification: Inferred from Requirements
Communication and Connectivity Capabilities
Feature: External interfaces
Feature ID: FEAT-X005
Purpose
Identify communication touchpoints where the product exchanges data with vehicle, backend, customer, supplier, diagnostic, or tooling actors.
User/System Value
Creates the bridge from requirements to attack surface review.
Requirement Basis
- Related requirements: REQ_SEC_0036; REQ-AUTO-00066; REQ-AUTO-00078; REQ-AUTO-00138; REQ-AUTO-00139; REQ-AUTO-00141; REQ-AUTO-00143; REQ-AUTO-00145; REQ-AUTO-00146; REQ-AUTO-00177; REQ-AUTO-00193; REQ-AUTO-00195; REQ-AUTO-00196; REQ-AUTO-00199; REQ-AUTO-00200; REQ-AUTO-00201; REQ-AUTO-00202; REQ-AUTO-00204 (showing 18 of 44)
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11; converted/markdown-cleaned/3299216_1.md page 4; converted/markdown-cleaned/3299216_1.md page 8; converted/markdown-cleaned/3299216_1.md page 22; converted/markdown-cleaned/3299216_1.md page 23; converted/markdown-cleaned/3299216_1.md page 27; converted/markdown-cleaned/3299216_1.md page 31; converted/markdown-cleaned/3299216_1.md page 33 (showing 8 of 26)
Functional Scope
External message paths, data exchanged, interface purpose, and protection needs.
Out of Scope / Not Confirmed
Protocol stack, exact network topology, endpoint ownership, and message catalog are not fully confirmed.
Interfaces Involved
Vehicle network, diagnostic tool, backend/cloud, OEM/customer, development/evidence tooling.
Data Handled
Messages, signals, requests/responses, certificates, software packages, logs, security events.
Security Relevance
Interfaces are the main places where authentication, authorization, encryption, freshness, replay protection, and logging must be designed.
Related Security Capabilities
- Secure communication
- Authentication
- Certificate lifecycle
- Logging and audit
Impacted Architecture Elements
- External Interfaces
- Security Services
- Backend and IT Systems
Confidence Level
Medium
Classification
Explicit Requirement
Open Questions
- Review possible noise/boilerplate contamination.
Evidence Basis:
- Requirement IDs: REQ_SEC_0036; REQ-AUTO-00066; REQ-AUTO-00078; REQ-AUTO-00138; REQ-AUTO-00139; REQ-AUTO-00141; REQ-AUTO-00143; REQ-AUTO-00145; REQ-AUTO-00146; REQ-AUTO-00177 (showing 10 of 44)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11; converted/markdown-cleaned/3299216_1.md page 4; converted/markdown-cleaned/3299216_1.md page 8; converted/markdown-cleaned/3299216_1.md page 22; converted/markdown-cleaned/3299216_1.md page 23; converted/markdown-cleaned/3299216_1.md page 27; converted/markdown-cleaned/3299216_1.md page 31; converted/markdown-cleaned/3299216_1.md page 33 (showing 8 of 26)
- Confidence level: Medium
- Classification: Explicit Requirement
Feature: Secure communication and freshness protection
Feature ID: FEAT-X006
Purpose
Protect vehicle or client/server data exchanges against unauthorized origin, modification, replay, and stale state.
User/System Value
Turns SecOC/SDT-style requirements into a coherent communication security behavior.
Requirement Basis
- Related requirements: REQ-AUTO-00410; REQ-AUTO-00867; REQ-AUTO-00889; REQ-AUTO-00890; REQ-AUTO-00992; REQ-AUTO-00993; REQ-AUTO-00994; REQ-AUTO-00995; REQ-AUTO-00997; REQ-AUTO-00999; REQ-AUTO-01000; REQ-AUTO-01001; REQ-AUTO-01002; REQ-AUTO-01003; REQ-AUTO-01004; REQ-AUTO-01005; REQ-AUTO-01006; REQ-AUTO-01007 (showing 18 of 90)
- Source sections/pages: converted/markdown-cleaned/CVS123-2.md page 29; converted/markdown-cleaned/CVS154.md page 10; converted/markdown-cleaned/CVS31.md page 7; converted/markdown-cleaned/CVS32.md page 6; converted/markdown-cleaned/CVS32.md page 7; converted/markdown-cleaned/CVS32.md page 8; converted/markdown-cleaned/CVS32.md page 9; converted/markdown-cleaned/CVS32.md page 10 (showing 8 of 24)
Functional Scope
Authentication/encryption, verify/decrypt processing, counters, replay checks, and discard behavior for invalid traffic.
Out of Scope / Not Confirmed
Exact algorithms, key lengths, message IDs, and bus allocation need customer confirmation.
Interfaces Involved
Vehicle network, ECU-to-ECU communication, client/server SDT flows.
Data Handled
Protected signals, counters, request/response payloads, authentication tags.
Security Relevance
This feature directly protects integrity, authenticity, freshness, and in some cases confidentiality of vehicle data.
Related Security Capabilities
- Secure communication
- Cryptographic protection
- Key management
Impacted Architecture Elements
- External Interfaces
- Security Services
- Application Software
Confidence Level
Medium
Classification
Inferred from Requirements
Open Questions
- Confirm whether this statement is a binding requirement.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00410; REQ-AUTO-00867; REQ-AUTO-00889; REQ-AUTO-00890; REQ-AUTO-00992; REQ-AUTO-00993; REQ-AUTO-00994; REQ-AUTO-00995; REQ-AUTO-00997; REQ-AUTO-00999 (showing 10 of 90)
- Source Markdown sections/pages: converted/markdown-cleaned/CVS123-2.md page 29; converted/markdown-cleaned/CVS154.md page 10; converted/markdown-cleaned/CVS31.md page 7; converted/markdown-cleaned/CVS32.md page 6; converted/markdown-cleaned/CVS32.md page 7; converted/markdown-cleaned/CVS32.md page 8; converted/markdown-cleaned/CVS32.md page 9; converted/markdown-cleaned/CVS32.md page 10 (showing 8 of 24)
- Confidence level: Medium
- Classification: Inferred from Requirements
Diagnostic and Maintenance Capabilities
Feature: Diagnostic security
Feature ID: FEAT-X007
Purpose
Control diagnostic access so service and engineering tools cannot become an uncontrolled security bypass.
User/System Value
Allows maintenance while preserving ECU security goals.
Requirement Basis
- Related requirements: req-6.20; REQ-AUTO-00282; REQ-AUTO-00290; REQ-AUTO-00299; REQ-AUTO-00310; REQ-AUTO-00315; REQ-AUTO-00318; REQ-AUTO-00350; REQ-AUTO-00370; REQ-AUTO-00372; REQ-AUTO-00377; REQ-AUTO-00411; REQ-AUTO-00412; REQ-AUTO-00413; REQ-AUTO-00442; REQ-AUTO-00450; REQ-AUTO-00496; REQ_UDS-0040 (showing 18 of 30)
- Source sections/pages: converted/markdown-cleaned/3299216_1.md page 23; converted/markdown-cleaned/CVS123-2.md page 4; converted/markdown-cleaned/CVS123-2.md page 6; converted/markdown-cleaned/CVS123-2.md page 9; converted/markdown-cleaned/CVS123-2.md page 10; converted/markdown-cleaned/CVS123-2.md page 21; converted/markdown-cleaned/CVS123-2.md page 22; converted/markdown-cleaned/CVS123-2.md page 23 (showing 8 of 23)
Functional Scope
Diagnostic authentication, access control, request validation, negative responses, and secure sessions.
Out of Scope / Not Confirmed
Exact diagnostic roles, tester certificates, and service whitelist are not fully confirmed.
Interfaces Involved
Diagnostic tool, UDS services, ECU diagnostic server, security services.
Data Handled
Diagnostic requests, responses, session state, credentials, certificates, unlock state.
Security Relevance
Diagnostics can alter state, extract data, or trigger programming; it needs strong access control and audit.
Related Security Capabilities
- Secure diagnostics
- Authentication
- Authorization
- Logging and audit
Impacted Architecture Elements
- External Interfaces
- Security Services
- Application Software
Confidence Level
Medium
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: req-6.20; REQ-AUTO-00282; REQ-AUTO-00290; REQ-AUTO-00299; REQ-AUTO-00310; REQ-AUTO-00315; REQ-AUTO-00318; REQ-AUTO-00350; REQ-AUTO-00370; REQ-AUTO-00372 (showing 10 of 30)
- Source Markdown sections/pages: converted/markdown-cleaned/3299216_1.md page 23; converted/markdown-cleaned/CVS123-2.md page 4; converted/markdown-cleaned/CVS123-2.md page 6; converted/markdown-cleaned/CVS123-2.md page 9; converted/markdown-cleaned/CVS123-2.md page 10; converted/markdown-cleaned/CVS123-2.md page 21; converted/markdown-cleaned/CVS123-2.md page 22; converted/markdown-cleaned/CVS123-2.md page 23 (showing 8 of 23)
- Confidence level: Medium
- Classification: Explicit Requirement
Cybersecurity Capabilities
Feature: Authentication
Feature ID: FEAT-X008
Purpose
Prove the identity or validity of tools, communication partners, data sources, software, or ECU-related entities.
User/System Value
Prevents unauthenticated entities from driving privileged behavior.
Requirement Basis
- Related requirements: REQ_SEC_0008; REQ-AUTO-00333; REQ-AUTO-00334; REQ-AUTO-00832; REQ-AUTO-00892; REQ-AUTO-00895; REQ-AUTO-00907; REQ-AUTO-00933; REQ-AUTO-00934; REQ-AUTO-00935; REQ-AUTO-00937; REQ-AUTO-00938; REQ-AUTO-00939; REQ-AUTO-00940; REQ-AUTO-00942; REQ-AUTO-00943; REQ-AUTO-00944; REQ-AUTO-00950 (showing 18 of 30)
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/CVS123-2.md page 12; converted/markdown-cleaned/CVS151.md page 19; converted/markdown-cleaned/CVS31.md page 8; converted/markdown-cleaned/CVS31.md page 11; converted/markdown-cleaned/CVS31.md page 16; converted/markdown-cleaned/CVS31.md page 18; converted/markdown-cleaned/CVS31.md page 19 (showing 8 of 14)
Functional Scope
Entity authentication, message/source authentication, service authentication, and authentication failure handling.
Out of Scope / Not Confirmed
The final identity model and trust anchors require customer confirmation.
Interfaces Involved
Diagnostic, vehicle network, backend/update, certificate/key provisioning.
Data Handled
Credentials, certificates, authentication tags, session state.
Security Relevance
Authentication is a prerequisite for authorization, secure diagnostics, secure update, and protected communication.
Related Security Capabilities
- Identity and access control
- Certificate lifecycle
- Secure communication
Impacted Architecture Elements
- Security Services
Confidence Level
Medium
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ_SEC_0008; REQ-AUTO-00333; REQ-AUTO-00334; REQ-AUTO-00832; REQ-AUTO-00892; REQ-AUTO-00895; REQ-AUTO-00907; REQ-AUTO-00933; REQ-AUTO-00934; REQ-AUTO-00935 (showing 10 of 30)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/CVS123-2.md page 12; converted/markdown-cleaned/CVS151.md page 19; converted/markdown-cleaned/CVS31.md page 8; converted/markdown-cleaned/CVS31.md page 11; converted/markdown-cleaned/CVS31.md page 16; converted/markdown-cleaned/CVS31.md page 18; converted/markdown-cleaned/CVS31.md page 19 (showing 8 of 14)
- Confidence level: Medium
- Classification: Explicit Requirement
Feature: Certificate handling
Feature ID: FEAT-X009
Purpose
Manage certificate formats, validation, trust anchors, and certificate-related lifecycle behavior.
User/System Value
Supports scalable trust for diagnostics, update, backend, and vehicle communication.
Requirement Basis
- Related requirements: REQ-AUTO-00818; REQ-AUTO-00821; REQ-AUTO-00839; REQ-AUTO-00951; REQ-AUTO-00953
- Source sections/pages: converted/markdown-cleaned/CVS151.md page 11; converted/markdown-cleaned/CVS151.md page 12; converted/markdown-cleaned/CVS151.md page 26; converted/markdown-cleaned/CVS31.md page 19
Functional Scope
X.509/certificate handling, validation expectations, and certificate-based trust decisions.
Out of Scope / Not Confirmed
CA hierarchy, enrollment, revocation, storage, and renewal process need confirmation.
Interfaces Involved
PKI, diagnostic tools, backend/update services, ECU security services.
Data Handled
Certificates, chains, trust anchors, validity metadata.
Security Relevance
Incorrect certificate handling can defeat authentication and secure communication.
Related Security Capabilities
- Key and certificate management
- Identity and access control
- Secure communication
Impacted Architecture Elements
- Security Services
- Backend and IT Systems
Confidence Level
Medium
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00818; REQ-AUTO-00821; REQ-AUTO-00839; REQ-AUTO-00951; REQ-AUTO-00953
- Source Markdown sections/pages: converted/markdown-cleaned/CVS151.md page 11; converted/markdown-cleaned/CVS151.md page 12; converted/markdown-cleaned/CVS151.md page 26; converted/markdown-cleaned/CVS31.md page 19
- Confidence level: Medium
- Classification: Explicit Requirement
Feature: Key management
Feature ID: FEAT-X010
Purpose
Protect cryptographic keys across generation, storage, use, update, and retirement.
User/System Value
Keeps communication, diagnostics, update, and platform integrity controls trustworthy.
Requirement Basis
- Related requirements: REQ_SEC_0016; REQ_SEC_0019; REQ_UDS-0068; REQ_UDS-0070; REQ_UDS-0092; REQ-AUTO-00875; REQ-AUTO-00991; REQ-AUTO-01014; REQ-AUTO-01017; REQ-AUTO-01022; REQ-AUTO-01023; REQ-AUTO-01024; REQ-AUTO-01043
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/CVS124.md page 34; converted/markdown-cleaned/CVS124.md page 40; converted/markdown-cleaned/CVS154.md page 11; converted/markdown-cleaned/CVS32.md page 4; converted/markdown-cleaned/CVS32.md page 10; converted/markdown-cleaned/CVS32.md page 11; converted/markdown-cleaned/CVS32.md page 12 (showing 8 of 9)
Functional Scope
Key storage, use restrictions, provisioning assumptions, and cryptographic material handling.
Out of Scope / Not Confirmed
Key hierarchy, HSM APIs, rotation, ownership, and recovery are not fully confirmed.
Interfaces Involved
Security services, hardware platform/HSM, PKI/provisioning, backend/update.
Data Handled
Symmetric keys, private keys, public keys, certificates, key identifiers.
Security Relevance
Key compromise collapses multiple controls at once.
Related Security Capabilities
- Cryptographic protection
- Key and certificate management
Impacted Architecture Elements
- Security Services
- Hardware Platform
Confidence Level
Medium
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ_SEC_0016; REQ_SEC_0019; REQ_UDS-0068; REQ_UDS-0070; REQ_UDS-0092; REQ-AUTO-00875; REQ-AUTO-00991; REQ-AUTO-01014; REQ-AUTO-01017; REQ-AUTO-01022 (showing 10 of 13)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/CVS124.md page 34; converted/markdown-cleaned/CVS124.md page 40; converted/markdown-cleaned/CVS154.md page 11; converted/markdown-cleaned/CVS32.md page 4; converted/markdown-cleaned/CVS32.md page 10; converted/markdown-cleaned/CVS32.md page 11; converted/markdown-cleaned/CVS32.md page 12 (showing 8 of 9)
- Confidence level: Medium
- Classification: Explicit Requirement
Feature: Logging and audit trail
Feature ID: FEAT-X011
Purpose
Record security-relevant actions and decisions for investigation, compliance, and operational feedback.
User/System Value
Supports accountability and incident analysis.
Requirement Basis
- Related requirements: REQ_SEC_0051
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 12
Functional Scope
Security event capture, audit evidence, and traceability to requirements or validation results.
Out of Scope / Not Confirmed
Log format, storage, retention, privacy, and upload path require customer confirmation.
Interfaces Involved
ECU logging, backend/security operations, ALM/evidence flow.
Data Handled
Security events, diagnostic attempts, update results, audit records.
Security Relevance
Logging is how misuse, failed controls, and residual-risk evidence become visible.
Related Security Capabilities
- Logging and audit
- Security monitoring and detection
Impacted Architecture Elements
- Security Services
- Backend and IT Systems
Confidence Level
High
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ_SEC_0051
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 12
- Confidence level: High
- Classification: Explicit Requirement
Backend/IT/Tooling Capabilities
Feature: Backend and IT integration
Feature ID: FEAT-X012
Purpose
Represent backend, IT, server, portal, and offboard workflows referenced by the requirements.
User/System Value
Shows that security architecture extends beyond the ECU boundary where update, evidence, monitoring, or supplier workflows are involved.
Requirement Basis
- Related requirements: REQ-AUTO-00081; REQ-AUTO-00090; REQ-AUTO-00091; req.10.5; REQ-AUTO-00101; REQ-AUTO-00104; req-5.10; req-6.4; REQ-AUTO-00112; REQ-AUTO-00114; REQ-AUTO-00132; REQ-AUTO-00140; REQ-AUTO-00192; REQ-AUTO-00219; REQ-AUTO-00230; REQ-AUTO-00247; REQ-AUTO-00283; REQ-AUTO-00285 (showing 18 of 209)
- Source sections/pages: converted/markdown-cleaned/3299216_1.md page 9; converted/markdown-cleaned/3299216_1.md page 10; converted/markdown-cleaned/3299216_1.md page 11; converted/markdown-cleaned/3299216_1.md page 12; converted/markdown-cleaned/3299216_1.md page 13; converted/markdown-cleaned/3299216_1.md page 14; converted/markdown-cleaned/3299216_1.md page 15; converted/markdown-cleaned/3299216_1.md page 20 (showing 8 of 103)
Functional Scope
Backend connectivity, IT systems, supplier/OEM portals, storage of evidence or operational security data.
Out of Scope / Not Confirmed
Cloud provider, API contracts, hosting ownership, and network zones are not confirmed.
Interfaces Involved
Backend/cloud, supplier IT, OEM/customer systems, ECU/update path.
Data Handled
Software packages, certificates, logs, vulnerability data, evidence, configuration.
Security Relevance
Backend compromise can affect update integrity, certificate lifecycle, evidence integrity, and operational response.
Related Security Capabilities
- Backend/cloud security
- Secure update
- Logging and audit
Impacted Architecture Elements
- Backend and IT Systems
- External Interfaces
Confidence Level
Medium
Classification
Inferred from Requirements
Open Questions
- Clarify ambiguous or incomplete source wording.
- Review possible noise/boilerplate contamination.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00081; REQ-AUTO-00090; REQ-AUTO-00091; req.10.5; REQ-AUTO-00101; REQ-AUTO-00104; req-5.10; req-6.4; REQ-AUTO-00112; REQ-AUTO-00114 (showing 10 of 209)
- Source Markdown sections/pages: converted/markdown-cleaned/3299216_1.md page 9; converted/markdown-cleaned/3299216_1.md page 10; converted/markdown-cleaned/3299216_1.md page 11; converted/markdown-cleaned/3299216_1.md page 12; converted/markdown-cleaned/3299216_1.md page 13; converted/markdown-cleaned/3299216_1.md page 14; converted/markdown-cleaned/3299216_1.md page 15; converted/markdown-cleaned/3299216_1.md page 20 (showing 8 of 103)
- Confidence level: Medium
- Classification: Inferred from Requirements
Feature: Engineering tooling
Feature ID: FEAT-X013
Purpose
Capture engineering, build, test, and evidence tooling needed to produce and prove the cybersecurity work products.
User/System Value
Makes development and verification responsibilities visible in the architecture package.
Requirement Basis
- Related requirements: REQ-AUTO-00093; REQ-AUTO-00094; REQ-AUTO-00098
- Source sections/pages: converted/markdown-cleaned/3299216_1.md page 10; converted/markdown-cleaned/3299216_1.md page 11
Functional Scope
ALM, build/test tooling, verification evidence, traceability artifacts, review workflows.
Out of Scope / Not Confirmed
Tool names, integrations, access model, and retention policy are not confirmed.
Interfaces Involved
Supplier engineering, ALM, CI/test environment, OEM/customer evidence handoff.
Data Handled
Requirements, test reports, traceability, artifacts, build outputs.
Security Relevance
Toolchain integrity affects trust in delivered software and evidence.
Related Security Capabilities
- Development and toolchain security
- Compliance and evidence management
Impacted Architecture Elements
- Engineering Toolchain
- Compliance Process
Confidence Level
Medium
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00093; REQ-AUTO-00094; REQ-AUTO-00098
- Source Markdown sections/pages: converted/markdown-cleaned/3299216_1.md page 10; converted/markdown-cleaned/3299216_1.md page 11
- Confidence level: Medium
- Classification: Explicit Requirement
Operational and Lifecycle Capabilities
Feature: Incident response
Feature ID: FEAT-X014
Purpose
Provide a lifecycle path for handling confirmed or suspected cybersecurity incidents.
User/System Value
Connects product security signals to customer and supplier response obligations.
Requirement Basis
- Related requirements: REQ_SEC_0045
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10
Functional Scope
Incident identification, escalation, documentation, and customer communication assumptions.
Out of Scope / Not Confirmed
Severity model, reporting timelines, and operational owner are not confirmed.
Interfaces Involved
Security operations, OEM/customer, supplier support, backend/tooling.
Data Handled
Incident records, logs, evidence, mitigation status.
Security Relevance
Incident response limits damage and provides evidence after preventive controls fail.
Related Security Capabilities
- Vulnerability and incident handling
- Logging and audit
Impacted Architecture Elements
- Compliance Process
- Backend and IT Systems
Confidence Level
High
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ_SEC_0045
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10
- Confidence level: High
- Classification: Explicit Requirement
Feature: Secure software update and flash readiness
Feature ID: FEAT-X015
Purpose
Ensure software update, flash, and IVD-related flows preserve authenticity, integrity, and regulatory evidence.
User/System Value
Supports UNECE-style software update obligations and safe maintenance of E/E components.
Requirement Basis
- Related requirements: REQ-AUTO-00203; REQ-AUTO-00290; REQ_UDS-0051; REQ-AUTO-00297; REQ-AUTO-00302; REQ-AUTO-00303; REQ-AUTO-00306; REQ-AUTO-00307; REQ-AUTO-00311; REQ-AUTO-00312; REQ-AUTO-00313; REQ-AUTO-00322; REQ-AUTO-00323; REQ-AUTO-00324; REQ-AUTO-00326; REQ-AUTO-00329; REQ-AUTO-00330; REQ-AUTO-00331 (showing 18 of 121)
- Source sections/pages: converted/markdown-cleaned/3299216_1.md page 34; converted/markdown-cleaned/CVS123-2.md page 6; converted/markdown-cleaned/CVS124.md page 26; converted/markdown-cleaned/CVS123-2.md page 7; converted/markdown-cleaned/CVS123-2.md page 9; converted/markdown-cleaned/CVS123-2.md page 10; converted/markdown-cleaned/CVS123-2.md page 11; converted/markdown-cleaned/CVS123-2.md page 12 (showing 8 of 48)
Functional Scope
Update package handling, flash/programming paths, integrity validation data, and update evidence.
Out of Scope / Not Confirmed
Update transport, campaign management, rollback policy, and production signing chain need confirmation.
Interfaces Involved
Backend/update infrastructure, diagnostic/programming tool, ECU boot/update manager, PKI.
Data Handled
Software packages, signatures, IVD data, certificates, programming requests, update logs.
Security Relevance
Unauthorized or corrupted software undermines ECU authenticity and all data security goals.
Related Security Capabilities
- Secure software update
- Secure boot and platform integrity
- Key and certificate management
Impacted Architecture Elements
- Backend and IT Systems
- Security Services
- Hardware Platform
Confidence Level
High
Classification
Inferred from Requirements
Open Questions
- Clarify ambiguous or incomplete source wording.
- Confirm whether this statement is a binding requirement.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00203; REQ-AUTO-00290; REQ_UDS-0051; REQ-AUTO-00297; REQ-AUTO-00302; REQ-AUTO-00303; REQ-AUTO-00306; REQ-AUTO-00307; REQ-AUTO-00311; REQ-AUTO-00312 (showing 10 of 121)
- Source Markdown sections/pages: converted/markdown-cleaned/3299216_1.md page 34; converted/markdown-cleaned/CVS123-2.md page 6; converted/markdown-cleaned/CVS124.md page 26; converted/markdown-cleaned/CVS123-2.md page 7; converted/markdown-cleaned/CVS123-2.md page 9; converted/markdown-cleaned/CVS123-2.md page 10; converted/markdown-cleaned/CVS123-2.md page 11; converted/markdown-cleaned/CVS123-2.md page 12 (showing 8 of 48)
- Confidence level: High
- Classification: Inferred from Requirements
Feature: Vulnerability management
Feature ID: FEAT-X016
Purpose
Identify, assess, treat, verify, and communicate vulnerabilities and risks over releases.
User/System Value
Keeps the system secure beyond a single development milestone.
Requirement Basis
- Related requirements: REQ_SEC_0002; REQ-AUTO-00051
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11
Functional Scope
Risk assessment, vulnerability evaluation, penetration-test readiness, mitigation tracking, release impact review.
Out of Scope / Not Confirmed
Customer-specific vulnerability intake SLAs and tool workflow are not confirmed.
Interfaces Involved
OEM/customer, supplier security team, development tooling, incident process.
Data Handled
Vulnerability records, risk treatment decisions, mitigation evidence, release notes.
Security Relevance
Unmanaged vulnerabilities become residual risk without ownership.
Related Security Capabilities
- Vulnerability and incident handling
- Compliance and evidence management
Impacted Architecture Elements
- Compliance Process
- Engineering Toolchain
- Security Services
Confidence Level
High
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ_SEC_0002; REQ-AUTO-00051
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11
- Confidence level: High
- Classification: Explicit Requirement
Compliance and Evidence Capabilities
Feature: Cybersecurity requirement handling
Feature ID: FEAT-X017
Purpose
Maintain a verifiable chain from cybersecurity requirements to controls, implementation, validation, residual risk, and customer agreement.
User/System Value
Turns the RFQ into an auditable security engineering package instead of disconnected controls.
Requirement Basis
- Related requirements: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023; REQ-AUTO-00011; REQ_SEC_0024; REQ_SEC_0004; REQ_SEC_0005; REQ_SEC_0042; REQ_SEC_0009; REQ_SEC_0027; REQ_SEC_0015; REQ_SEC_0043; REQ_SEC_0030; REQ-AUTO-00169; REQ-AUTO-01058
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/3299216_1.md page 25 (showing 8 of 9)
Functional Scope
Cybersecurity concept, risk assessment input, control derivation, verification/validation evidence, residual risk documentation.
Out of Scope / Not Confirmed
Final TARA results and customer-approved risk treatment are not claimed.
Interfaces Involved
OEM/customer, supplier engineering, ALM/evidence repository, security review process.
Data Handled
Requirements, risks, controls, test reports, residual-risk decisions, review evidence.
Security Relevance
Evidence discipline is required to prove that controls exist and reduce risk sufficiently.
Related Security Capabilities
- Compliance and evidence management
- Vulnerability and incident handling
Impacted Architecture Elements
- Compliance Process
- Security Services
- Engineering Toolchain
Confidence Level
High
Classification
Explicit Requirement
Open Questions
- None identified from extracted requirements.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023; REQ-AUTO-00011; REQ_SEC_0024; REQ_SEC_0004; REQ_SEC_0005 (showing 10 of 18)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 7; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 8; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 9; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/3299216_1.md page 25 (showing 8 of 9)
- Confidence level: High
- Classification: Explicit Requirement
Feature: Security evidence and traceability
Feature ID: FEAT-X018
Purpose
Provide proof that requirements, controls, architecture decisions, verification, validation, and residual risk remain connected.
User/System Value
Gives reviewers a way to audit security decisions before accepting the architecture.
Requirement Basis
- Related requirements: REQ-AUTO-00001; REQ_SEC_0001; REQ-AUTO-00005; REQ_SEC_0024; REQ_SEC_0004; REQ_SEC_0005; REQ_SEC_0007; REQ-AUTO-00076; REQ-AUTO-00150; REQ-AUTO-00172; REQ-AUTO-00256; REQ-AUTO-00258; REQ-AUTO-00312; REQ-AUTO-00326; REQ-AUTO-00383; REQ-AUTO-00389; REQ-AUTO-00390; REQ-AUTO-00441 (showing 18 of 47)
- Source sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/3299216_1.md page 5; converted/markdown-cleaned/3299216_1.md page 23; converted/markdown-cleaned/3299216_1.md page 27; converted/markdown-cleaned/3299216_1.md page 50; converted/markdown-cleaned/CVS123-2.md page 10 (showing 8 of 31)
Functional Scope
Traceability matrices, evidence reports, human-review queues, quality gates, and open decisions.
Out of Scope / Not Confirmed
Customer acceptance workflow and evidence repository ownership are not confirmed.
Interfaces Involved
ALM/evidence repository, OEM/customer review, supplier security process.
Data Handled
Requirement IDs, source sections, controls, test reports, decisions, open questions.
Security Relevance
Without evidence traceability, control implementation cannot be credibly argued.
Related Security Capabilities
- Compliance and evidence management
- Development and toolchain security
Impacted Architecture Elements
- Compliance Process
- Engineering Toolchain
Confidence Level
Medium
Classification
Inferred from Requirements
Open Questions
- Confirm whether this statement is a binding requirement.
- Review possible noise/boilerplate contamination.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0001; REQ-AUTO-00005; REQ_SEC_0024; REQ_SEC_0004; REQ_SEC_0005; REQ_SEC_0007; REQ-AUTO-00076; REQ-AUTO-00150; REQ-AUTO-00172 (showing 10 of 47)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/3299216_1.md page 5; converted/markdown-cleaned/3299216_1.md page 23; converted/markdown-cleaned/3299216_1.md page 27; converted/markdown-cleaned/3299216_1.md page 50; converted/markdown-cleaned/CVS123-2.md page 10 (showing 8 of 31)
- Confidence level: Medium
- Classification: Inferred from Requirements
Operational Context
Classification: Inferred from Requirements
The operational picture spans development, release, service/diagnostics, update/flash handling, monitoring or vulnerability handling, and OEM/customer security review. The runtime product boundary is only one part of the package; the RFQ also requires a controlled lifecycle evidence flow.
Evidence Basis:
- Requirement IDs: REQ-AUTO-00001; REQ_SEC_0002; REQ_SEC_0004; REQ_SEC_0005; REQ_SEC_0044; REQ_SEC_0045; REQ_SEC_0046; REQ_SEC_0032; REQ_SEC_0033; REQ_SEC_0034 (showing 10 of 127)
- Source Markdown sections/pages: converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 3; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 5; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 6; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 10; converted/markdown-cleaned/1001379436_P10_000_01_RDDM-1140152501-1744.md page 11; converted/markdown-cleaned/3299216_1.md page 8; converted/markdown-cleaned/3299216_1.md page 12; converted/markdown-cleaned/3299216_1.md page 18 (showing 8 of 80)
- Confidence level: Medium
- Classification: Inferred from Requirements
Assumptions and Unknowns
Unknowns and Assumptions
- Needs Customer Clarification: Exact product name, ECU variant, and vehicle function allocation.
- Needs Customer Clarification: Exact vehicle network topology, messages, signals, and data classification.
- Needs Customer Clarification: Exact diagnostic role model, UDS service scope, certificates, and lockout/rate-limit behavior.
- Needs Customer Clarification: Exact update mechanism, signing chain, IVD ownership, rollback policy, and backend responsibilities.
- Needs Customer Clarification: Exact key hierarchy, HSM/protected-storage capability, certificate lifecycle, and PKI ownership.
- Needs Customer Clarification: Final TARA results, risk treatment decisions, and customer residual-risk acceptance.
- Expert Assumption: Until clarified, diagrams mark these elements as inferred or assumption-based rather than confirmed implementation.