ISO/TR 23786:2019 PDF
Road vehicles — Solutions for remote access to vehicle — Criteria for risk assessment
Road vehicles — Solutions for remote access to vehicle — Criteria for risk assessment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 12
- Дата публикации:
- 15 ноября 2019 г.
- Издание:
- ISO TR 23786 edition 1 version 1
- ICS:
- 43.040.15
This document identifies criteria that can be considered for assessing the risks related to solutions for remote access to road vehicles, including extended vehicles (ExVe) and their implementation. Internal communication within the vehicle or the ExVe is out of the scope of this document. Cybersecurity risks related to the VM infrastructure (except the elements that are part of the extended vehicle) and the road-side equipment are out of the scope of this document. The criteria identified in this document are also applicable in the case of a risk assessment related to the specification of remote communication solutions, for example a technical standard. The list of criteria that is provided can be considered as sufficiently comprehensive but not exhaustive, from a global point of view, to allow coherent risk mitigation, if such mitigation is necessary. This document does not suggest nor specify any methodology for performing a risk assessment. It does not aim at replacing any methodology, technical specification or standard relative to one or other specific type of risks (for example cyber security risks).
Abstract
Overview
ISO/TR 23786:2019 - Road vehicles - Solutions for remote access to vehicle - Criteria for risk assessment is an ISO Technical Report that identifies criteria to assess risks arising from remote access solutions for road vehicles, including extended vehicles (ExVe). It provides a consolidated checklist of risk criteria for use by standardizers, vehicle manufacturers, implementers and stakeholders without prescribing a specific risk assessment methodology. The report is intended to support coherent mitigation where necessary, while clarifying several explicit scope exclusions.
Key topics and technical focus
- Risk categories covered: safety risks, cybersecurity (security) risks, competition risks, responsibility and liability risks, and data protection (resource/data owner) risks.
- Scope limits: internal in-vehicle communications, VM infrastructure components outside the ExVe, and road-side equipment cybersecurity are explicitly out of scope.
- Criteria for RCS-specifications: the criteria are applicable both to concrete implementations and to Remote Communication Solution (RCS) specifications (for example technical standards). The document helps answer whether an RCS or its implementation presents risks for specific use cases.
- Safety risk examples: potential overload of vehicle electronic systems (numerous, frequent or unexpected requests), illicit/malicious remote control, incompatibility with existing systems, failures in remote communication components, and incomplete vehicle life-cycle consideration.
- Guidance, not a methodology: ISO/TR 23786:2019 does not define a risk-assessment method or replace domain-specific standards (for example detailed cybersecurity standards); it offers a sufficiently comprehensive-but not exhaustive-list of assessment criteria.
- Supplementary tools: includes a template proposal (Annex A) to help structure risk assessments and cross-reference with related ISO design methodologies (e.g., ISO 20077 series).
Practical applications and users
Who will use ISO/TR 23786:2019:
- Vehicle Manufacturers (VMs) evaluating remote access features and ExVe implementations.
- Standards developers and ISO working groups creating or updating RCS-specifications.
- System integrators and service providers designing remote vehicle services, telematics, or back-end systems.
- Cybersecurity analysts, safety engineers and compliance teams conducting risk reviews, gap analyses and requirements traceability.
- Legal, privacy and product managers assessing liability, data protection and competition impacts of remote access solutions.
Practical uses:
- Scoping risk assessment checklists for design reviews and specifications.
- Identifying non-technical risks such as market dominance or data-owner concerns.
- Supporting requirements and test-case definition when developing remote-access standards or implementations.
Related standards
- ISO 20077 (ExVe terminology and design guidance)
- ISO 20078-1 (ExVe web services / RCS-specification examples)
- ISO/TC 22/SC 31 and related ISO work on vehicle data communication and cybersecurity
Keywords: ISO/TR 23786:2019, remote access to vehicle, extended vehicle, ExVe, risk assessment, vehicle cybersecurity, safety risks, data protection, RCS-specification.
Технические детали
- Технический комитет
- ISO/TC 22/SC 31 - Data communication
- SKU
- ISO/TR 23786:2019
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 20077-2:2018
ДействующийRoad Vehicles — Extended vehicle (ExVe) methodology — Part 2: Methodology for designing the extended vehicle
Overview - ISO 20077-2:2018 (Extended Vehicle / ExVe design methodology) ISO 20077-2:2018 defines a methodology for designing the extended vehicle (ExVe). It provides general rules, basic principles…
BS ISO 20078-1:2019
ОтменёнRoad vehicles. Extended vehicle (ExVe) web services - Content
What is about ISO 20078 ‑ 1 - Extended vehicle (ExVe) web services ? ISO 20078 ‑ 1 is the first part of the multi-series standard that defines the different concepts, entities and roles involved in i…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…