21434-10 | Product Development at System Level | 0 |
21434-10.4 | Hardware and Software Component Requirements | 0 |
21434-11 | Cybersecurity Validation | 0 |
21434-12 | Production | 3 |
21434-13 | Operations and Maintenance | 0 |
21434-14 | End of Cybersecurity Support and Decommissioning | 0 |
21434-15.3 | Asset Identification (TARA Step 1) | 0 |
21434-15.5 | Threat Scenario Identification (TARA Step 2) | 0 |
21434-15.6 | Impact Rating (TARA Step 3) | 0 |
21434-15.7 | Attack Path Analysis (TARA Step 4) | 0 |
21434-15.8 | Attack Feasibility and Risk Determination (TARA Step 5) | 0 |
21434-15.9 | Cybersecurity Assurance Level (CAL) and Risk Treatment | 0 |
21434-5 | Cybersecurity Governance | 0 |
21434-6 | Cybersecurity Culture and Competence | 0 |
21434-7 | Continuous Cybersecurity Activities | 0 |
21434-8 | Risk Assessment Methods | 4 |
21434-9.3 | Item Definition | 0 |
21434-9.4 | Cybersecurity Goals and Claims | 0 |
21434-Annex-E | Distributed Cybersecurity Activities and Supplier Management | 0 |
ISO21434-01 | Information security policy framework | 0 |
ISO21434-02 | Management direction and commitment | 0 |
ISO21434-03 | Policy review and update procedures | 0 |
ISO21434-04 | Roles and responsibilities definition | 136 |
ISO21434-05 | Contact with authorities and special interest groups | 2 |
ISO21434-06 | Asset inventory and ownership | 0 |
ISO21434-07 | Acceptable use of assets | 24 |
ISO21434-08 | Information classification and labeling | 51 |
ISO21434-09 | Asset handling procedures | 24 |
ISO21434-10 | Media management and disposal | 0 |
ISO21434-11 | Access control policy and enforcement | 1 |
ISO21434-12 | User access management and provisioning | 110 |
ISO21434-13 | Authentication and password management | 69 |
ISO21434-14 | Privileged access management | 123 |
ISO21434-15 | Access review and recertification | 98 |
ISO21434-16 | Cryptographic policy and key management | 112 |
ISO21434-17 | Encryption of data at rest | 112 |
ISO21434-18 | Encryption of data in transit | 99 |
ISO21434-19 | Certificate management | 112 |
ISO21434-20 | Key lifecycle management | 0 |
ISO21434-21 | Operational procedures and responsibilities | 3 |
ISO21434-22 | Protection from malware | 32 |
ISO21434-23 | Backup and recovery procedures | 69 |
ISO21434-24 | Logging and monitoring | 51 |
ISO21434-25 | Technical vulnerability management | 56 |
ISO21434-26 | Audit considerations | 0 |
ISO21434-27 | Network security management | 58 |
ISO21434-28 | Network service security | 0 |
ISO21434-29 | Segregation in networks | 1 |
ISO21434-30 | Information transfer policies | 4 |
ISO21434-31 | Secure messaging | 0 |
ANNEXES | Annexes A to H | 0 |
CLAUSES-1-4 | Clauses 1 to 4: scope, normative references, terms, general considerations | 0 |
Clause 10 | 10 Product development | 0 |
Clause 11 | 11 Cybersecurity validation | 0 |
Clause 12 | 12 Production | 0 |
Clause 13 | 13 Operations and maintenance | 0 |
Clause 14 | 14 End of cybersecurity support and decommissioning | 0 |
Clause 15 | 15 Threat analysis and risk assessment methods | 0 |
Clause 5 | 5 Organizational cybersecurity management | 0 |
Clause 6 | 6 Project dependent cybersecurity management | 0 |
Clause 7 | 7 Distributed cybersecurity activities | 0 |
Clause 8 | 8 Continual cybersecurity activities | 0 |
Clause 9 | 9 Concept | 0 |
PM-06-08 | [PM-06-08] Omitting conformity for risk value 1 | 0 |
PM-06-13 | [PM-06-13] Tailoring permitted | 0 |
PM-06-29 | [PM-06-29] Assessment against the objectives | 0 |
PM-15-07 | [PM-15-07] Omitting further impact analysis | 0 |
RC-05-10 | [RC-05-10] Aligned management of shared information | 0 |
RC-05-13 | [RC-05-13] Production cybersecurity management system | 0 |
RC-05-15 | [RC-05-15] Reproducible remediation environment | 0 |
RC-05-16 | [RC-05-16] Work products managed under the management system | 0 |
RC-07-02 | [RC-07-02] Cybersecurity capability record | 0 |
RC-07-05 | [RC-07-05] Agreement before activities start | 0 |
RC-07-08 | [RC-07-08] Responsibility assignment matrix | 0 |
RC-10-06 | [RC-10-06] Established design and implementation principles | 0 |
RC-10-12 | [RC-10-12] Testing for remaining weaknesses | 0 |
RC-15-11 | [RC-15-11] Attack feasibility method | 0 |
RC-15-12 | [RC-15-12] Attack-potential-based approach | 0 |
RC-15-13 | [RC-15-13] CVSS-based approach | 0 |
RC-15-14 | [RC-15-14] Attack-vector-based approach | 0 |
RQ-05-01 | [RQ-05-01] Cybersecurity policy | 0 |
RQ-05-02 | [RQ-05-02] Organizational rules and processes | 0 |
RQ-05-03 | [RQ-05-03] Responsibilities and authority | 0 |
RQ-05-04 | [RQ-05-04] Resources | 0 |
RQ-05-05 | [RQ-05-05] Interaction with related disciplines | 0 |
RQ-05-06 | [RQ-05-06] Cybersecurity culture | 0 |
RQ-05-07 | [RQ-05-07] Competence and awareness | 0 |
RQ-05-08 | [RQ-05-08] Continuous improvement | 0 |
RQ-05-09 | [RQ-05-09] Information sharing circumstances | 0 |
RQ-05-11 | [RQ-05-11] Quality management system supporting cybersecurity engineering | 0 |
RQ-05-12 | [RQ-05-12] Configuration information available until end of support | 0 |
RQ-05-14 | [RQ-05-14] Tool management | 0 |
RQ-05-17 | [RQ-05-17] Organizational cybersecurity audit | 0 |
RQ-06-01 | [RQ-06-01] Assignment of project cybersecurity responsibilities | 0 |
RQ-06-02 | [RQ-06-02] Cybersecurity relevance and planning analysis | 0 |
RQ-06-03 | [RQ-06-03] Cybersecurity plan contents | 0 |
RQ-06-04 | [RQ-06-04] Responsibility for the plan and progress | 0 |
RQ-06-05 | [RQ-06-05] Plan referenced in the project plan | 0 |
RQ-06-06 | [RQ-06-06] Plan specifies the concept and development activities | 0 |
RQ-06-07 | [RQ-06-07] Plan updated on change or refinement | 0 |
RQ-06-09 | [RQ-06-09] Work products kept accurate to release | 0 |
RQ-06-10 | [RQ-06-10] Plans in distributed activities | 0 |
RQ-06-11 | [RQ-06-11] Plan under configuration and documentation management | 0 |
RQ-06-12 | [RQ-06-12] Work products under management | 0 |
RQ-06-14 | [RQ-06-14] Rationale for tailoring | 0 |
RQ-06-15 | [RQ-06-15] Reuse analysis triggers | 0 |
RQ-06-16 | [RQ-06-16] Reuse analysis content | 0 |
RQ-06-17 | [RQ-06-17] Reuse analysis for components | 0 |
RQ-06-18 | [RQ-06-18] Assumptions of out-of-context components | 0 |
RQ-06-19 | [RQ-06-19] Requirements based on the assumptions | 0 |
RQ-06-20 | [RQ-06-20] Validating the assumptions at integration | 0 |
RQ-06-21 | [RQ-06-21] Off-the-shelf component analysis | 0 |
RQ-06-22 | [RQ-06-22] Activities when documentation is insufficient | 0 |
RQ-06-23 | [RQ-06-23] Cybersecurity case | 0 |
RQ-06-24 | [RQ-06-24] Decision on cybersecurity assessment | 0 |
RQ-06-25 | [RQ-06-25] Independent review of the decision | 0 |
RQ-06-26 | [RQ-06-26] Assessment judges cybersecurity | 0 |
RQ-06-27 | [RQ-06-27] Independent assessor appointed | 0 |
RQ-06-28 | [RQ-06-28] Assessor access and cooperation | 0 |
RQ-06-30 | [RQ-06-30] Assessment scope | 0 |
RQ-06-31 | [RQ-06-31] Assessment recommendation | 0 |
RQ-06-32 | [RQ-06-32] Conditions of a conditional acceptance | 0 |
RQ-06-33 | [RQ-06-33] Work products available before release | 0 |
RQ-06-34 | [RQ-06-34] Release conditions | 0 |
RQ-07-01 | [RQ-07-01] Supplier capability evaluation | 0 |
RQ-07-03 | [RQ-07-03] Request for quotation content | 0 |
RQ-07-04 | [RQ-07-04] Cybersecurity interface agreement | 0 |
RQ-07-06 | [RQ-07-06] Agreed actions on vulnerabilities | 0 |
RQ-07-07 | [RQ-07-07] Notification of unclear or conflicting requirements | 0 |
RQ-08-01 | [RQ-08-01] Sources of cybersecurity information | 0 |
RQ-08-02 | [RQ-08-02] Triggers for triage | 0 |
RQ-08-03 | [RQ-08-03] Collection and triage into events | 0 |
RQ-08-04 | [RQ-08-04] Event assessment for weaknesses | 0 |
RQ-08-05 | [RQ-08-05] Vulnerability analysis | 0 |
RQ-08-06 | [RQ-08-06] Rationale when not a vulnerability | 0 |
RQ-08-07 | [RQ-08-07] Vulnerability management | 0 |
RQ-08-08 | [RQ-08-08] Incident response when required | 0 |
RQ-09-01 | [RQ-09-01] Item definition | 0 |
RQ-09-02 | [RQ-09-02] Operational environment description | 0 |
RQ-09-03 | [RQ-09-03] Risk analysis of the item | 0 |
RQ-09-04 | [RQ-09-04] Risk treatment decision per threat scenario | 0 |
RQ-09-05 | [RQ-09-05] Cybersecurity goals | 0 |
RQ-09-06 | [RQ-09-06] Cybersecurity claims | 0 |
RQ-09-07 | [RQ-09-07] Verification of goals and claims | 0 |
RQ-09-08 | [RQ-09-08] Description of cybersecurity controls | 0 |
RQ-09-09 | [RQ-09-09] Cybersecurity requirements and requirements on the operational environment | 0 |
RQ-09-10 | [RQ-09-10] Allocation of cybersecurity requirements | 0 |
RQ-09-11 | [RQ-09-11] Verification of the cybersecurity concept | 0 |
RQ-10-01 | [RQ-10-01] Cybersecurity specification | 0 |
RQ-10-02 | [RQ-10-02] Allocation to architectural components | 0 |
RQ-10-03 | [RQ-10-03] Post-development procedures | 0 |
RQ-10-04 | [RQ-10-04] Criteria for design, modelling and programming languages | 0 |
RQ-10-05 | [RQ-10-05] Guidelines covering the language's gaps | 0 |
RQ-10-07 | [RQ-10-07] Analysis of the architectural design for weaknesses | 0 |
RQ-10-08 | [RQ-10-08] Verification of the cybersecurity specification | 0 |
RQ-10-09 | [RQ-10-09] Integration and verification against the specification | 0 |
RQ-10-10 | [RQ-10-10] Specifying integration and verification | 0 |
RQ-10-11 | [RQ-10-11] Test coverage metrics | 0 |
RQ-10-13 | [RQ-10-13] Rationale when testing is not performed | 0 |
RQ-11-01 | [RQ-11-01] Validation of the item at vehicle level | 0 |
RQ-11-02 | [RQ-11-02] Rationale for the validation activities | 0 |
RQ-12-01 | [RQ-12-01] Production control plan | 0 |
RQ-12-02 | [RQ-12-02] Production control plan contents | 0 |
RQ-12-03 | [RQ-12-03] Implementing the production control plan | 0 |
RQ-13-01 | [RQ-13-01] Cybersecurity incident response plan | 0 |
RQ-13-02 | [RQ-13-02] Executing the incident response plan | 0 |
RQ-13-03 | [RQ-13-03] Updates developed under this document | 0 |
RQ-14-01 | [RQ-14-01] Communicating the end of cybersecurity support | 0 |
RQ-14-02 | [RQ-14-02] Post-development requirements for decommissioning | 0 |
RQ-15-01 | [RQ-15-01] Damage scenarios | 0 |
RQ-15-02 | [RQ-15-02] Assets with cybersecurity properties | 0 |
RQ-15-03 | [RQ-15-03] Threat scenarios | 0 |
RQ-15-04 | [RQ-15-04] Impact rating in four categories | 0 |
RQ-15-05 | [RQ-15-05] Impact rating levels | 0 |
RQ-15-06 | [RQ-15-06] Safety impact from ISO 26262 | 0 |
RQ-15-08 | [RQ-15-08] Attack path analysis | 0 |
RQ-15-09 | [RQ-15-09] Attack paths associated with threat scenarios | 0 |
RQ-15-10 | [RQ-15-10] Attack feasibility rating | 0 |
RQ-15-15 | [RQ-15-15] Risk value determination | 0 |
RQ-15-16 | [RQ-15-16] Risk value scale | 0 |
RQ-15-17 | [RQ-15-17] Risk treatment decision | 0 |
STANDARD | ISO/SAE 21434:2021: the standard and what is held | 0 |
STATUS | Edition status: first edition in force, second edition development starting 2026 | 0 |