Overview
ISO/SAE 21434:2021 - Road vehicles - Cybersecurity engineering - provides an engineering framework and requirements for managing cybersecurity risk across the full lifecycle of automotive electrical and electronic (E/E) systems. The standard defines a common vocabulary, process requirements and work products for cybersecurity risk management covering concept, product development, production, operation, maintenance and decommissioning. It applies to series-production road vehicle E/E systems (and their components and interfaces) whose development or modification began after publication. ISO/SAE 21434 does not mandate specific technologies or solutions.
Key topics and technical requirements
- Cybersecurity risk management: Defines risk as a combination of attack feasibility and impact, and requires structured processes to identify, assess and treat risks.
- Lifecycle coverage: Requirements span concept, product development, production, operations & maintenance, and end-of-support/decommissioning.
- Organizational and project-level management: Specifies organizational cybersecurity policies and project-dependent activities (roles, responsibilities, planning).
- Distributed activities & supply-chain coordination: Requires agreements and allocation of cybersecurity responsibilities between OEMs, suppliers and other stakeholders.
- Threat analysis & risk assessment (TARA): Provides modular methods for threat scenarios, vulnerability analysis and prioritization.
- Vulnerability and incident management: Ongoing vulnerability analysis, triage, incident response and update/patch processes until end of cybersecurity support.
- Cybersecurity validation & verification: Evidence-based confirmation that cybersecurity goals are adequate and achieved (cybersecurity case).
- Terminology & work products: Standardizes terms (assets, attack paths, cybersecurity goals, cybersecurity controls) and defines required work products for traceability.
- Testing techniques: Includes guidance for penetration testing and validation activities (to confirm achievement of cybersecurity goals).
Practical applications & users
ISO/SAE 21434 is intended for:
- OEMs and tier suppliers building or integrating automotive E/E systems and ECUs.
- Systems and software engineers designing secure architectures and implementing cybersecurity controls.
- Product managers and project leads who must establish cybersecurity requirements and contractual cybersecurity interface agreements.
- Safety, compliance and security teams responsible for lifecycle processes, vulnerability management and evidence for regulatory or customer assurance.
Practical uses include establishing a cybersecurity management system, performing TARA, defining cybersecurity requirements/specifications, coordinating supplier responsibilities and operating an incident response and update process.
Related standards
- ISO 26262 (functional safety) - referenced for concept-phase alignment.
- SAE J3061 - predecessor to ISO/SAE 21434; ISO/SAE 21434 supersedes it.
Keywords: ISO/SAE 21434:2021, road vehicle cybersecurity engineering, automotive cybersecurity standard, E/E systems, TARA, cybersecurity risk management, penetration testing, OEM suppliers.