TUHH Open Research
Help
  • Log In
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publications
  4. Managing security evidence in safety-critical organizations
 
Options

Managing security evidence in safety-critical organizations

Citation Link: https://doi.org/10.15480/882.9611
Publikationstyp
Journal Article
Date Issued
2024-08-01
Sprache
English
Author(s)
Mohamad, Mazen  
Steghöfer, Jan-Philipp  
Knauss, Eric
Scandariato, Riccardo  
Software Security E-22  
TORE-DOI
10.15480/882.9611
TORE-URI
https://hdl.handle.net/11420/47643
Journal
The journal of systems and software  
Volume
214
Article Number
112082
Citation
Journal of Systems and Software 214: 112082 (2024)
Publisher DOI
10.1016/j.jss.2024.112082
Scopus ID
2-s2.0-85191939777
Publisher
Elsevier
With the increasing prevalence of open and connected products, cybersecurity has become a serious issue in safety-critical domains such as the automotive industry. As a result, regulatory bodies have become more stringent in their requirements for cybersecurity, necessitating security assurance for products developed in these domains. In response, companies have implemented new or modified processes to incorporate security into their product development lifecycle, resulting in a large amount of evidence being created to support claims about the achievement of a certain level of security. However, managing evidence is not a trivial task, particularly for complex products and systems. This paper presents a qualitative interview study conducted in six companies on the maturity of managing security evidence in safety-critical organizations. We find that the current maturity of managing security evidence is insufficient for the increasing requirements set by certification authorities and standardization bodies. Organizations currently fail to identify relevant artifacts as security evidence and manage this evidence on an organizational level. One part of the reason are educational gaps, the other a lack of processes. The impact of AI on the management of security evidence is still an open question.
Subjects
Assurance
Evidence
Safety-critical
Security
DDC Class
004: Computer Sciences
005: Computer Programming, Programs, Data and Security
620.1: Engineering Mechanics and Materials Science
Publication version
publishedVersion
Lizenz
https://creativecommons.org/licenses/by/4.0/
Loading...
Thumbnail Image
Name

1-s2.0-S0164121224001274-main.pdf

Size

1.01 MB

Format

Adobe PDF

TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback