“Security” is a constantly moving target. You only need to test functional safety once per component. But with new threats, exploits and vulnerabilities emerging every day, cybersecurity testing is anything but a "one-and-done" proposition.
That is where a CSMS comes in. A good CSMS requires applicable threats to be evaluated extensively -- which is accomplished via a Threat Analysis and Risk Assessment (TARA).
Following a TARA, automakers can identify, implement and verify mitigations, before pushing them out to components and systems via software update.
With an efficient CSMS, automakers can re-evaluate and mitigate emerging threats in a timely manner -- all while ensuring their fixes don't inadvertently expose other components or systems to attack.
How can automakers fight back against cybercriminals?
It all comes down to thinking like the enemy.
Where a cybercriminal would seek to exploit system and component vulnerabilities, automakers can perform controlled cyberattacks to accurately test vehicular security in accordance with their CSMS.
Sometimes referred to as automotive penetration testing, this practice encompasses multiple test types -- including functional cybersecurity testing, fuzz testing, and vulnerability testing.
Not only do these tests need to cover a comprehensive suite of potential threat vectors, but they also need to account for the various points of ingress an attacker can take. That means testing across all the interfaces a modern car uses.
But that's only half the battle. Software updates -- the preferred method to mitigate vulnerabilities across automotive components and systems -- require extensive reverification.
This process is painstakingly iterative, and automation is key to making this a reality.
At the end of the day, compliance with UN R155 demands a repeatable, scalable and well-documented testing approach. And between sprawling attack surfaces, emerging threats and mandatory compliance processes, integration and automation aren't luxuries -- they are essentials.
Protect what matters most
By its very nature, the world of cybersecurity is in a near-continuous state of change.
In the coming years, we will likely see a mass proliferation of new attack vectors, component threats, and system vulnerabilities.
It should come as no surprise, then, that the automakers who respond the swiftest will emerge as the most protected, the most secure and the safest choice for discerning customers.