Micron Document
Livres et Wikis | Archives | Info


Cyber Security Management System
layout: Wide Β· Narrow Β· Centered
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
top
A Cyber Security Management System is a form of Information security management system, particularly focussed on protecting automation and transport systems.cite-ref-1[1] The EU Cybersecurity Act, of 2019, led to the creation of UNECE working groups which developed the Cyber Security Management Systems (CSMS) concept (and also an approach for securing over-the-air updates of vehicle systems), which were formalised in UN Regulation 155.cite-ref-2[2]

Contents

β€’ Context
β€’ Framework
β€’ See also
β€’ References

──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────

Context

Security technologies, and threats, can evolve much more quickly than regulatory bodies; so the CSMS emphasises a system of technologies and processes which can adapt more quickly, without relying on a narrowly-defined list of technical controls in a standard.cite-ref-3[3] Consequently, the CSMS is intended to be technology-neutral, much like ISO 27001, unlike detailed technical security standards such as PCI DSS.

Framework

See also

β€’ IEC 62443
β€’ ISO/SAE 21434

References

cite-note-11. ↑ "Automotive".
cite-note-22. ↑ "UN Regulations on Cybersecurity and Software Updates to pave the way for mass roll out of connected vehicles | UNECE".
cite-note-33. ↑ "UNECE Recommendation on Software Update Processes - Argus". 26 May 2020.

Further reading

β€’ Draft Recommendation on Cyber Security of the Task Force on Cyber Security and Over-the-air issues of UNECE WP.29 GRVA