A strong knowledge of the CSMS process is essential, including an overview of the UN-R155 and UN-R156 regulations, as well as awareness of ISO21434. Knowledge of Cyber Security Controls:
Familiarity with various Cyber Security Mitigations (Cyber Hygiene, Secure Boot, Signed SW, SecOC, Secure Diagnostics, Secure Debug, etc.) for ECUs and the network, along with knowledge of security controls found in SOTA, Mobile Communications, and Cloud for offboard aspects, is required. Knowledge of CSMS Process:
Understanding the CSMS process with awareness of ISO21434 is necessary. Experience in DIA/CIA, Cyber Security Plan, Item Definition, and TARA is expected. Understanding of Product's Architecture and Design:
To perform effective reviews, the reviewer should be aware of network architecture, communication protocols, ECU hardware, HSMs, etc. Strong Documentation and Communication Skills:
Strong documentation and communication skills are required when providing review support as Technical 2nd LoD. This includes the ability to clearly articulate findings and recommendations to both technical and non-technical stakeholders.
#J-18808-Ljbffr