Standard

BS ISO/SAE 21434:2021

Road vehicles. Cybersecurity engineering

Current

Published:

What is ISO/SAE 21434 about?  

ISO/SAE 21434 specifies engineering requirements for cybersecurity risk management regarding the concept, product development, production, operation, maintenance, and decommissioning of electrical and electronic (E/E) systems in road vehicles, including their components and interfaces. 

A framework is defined that includes requirements for cybersecurity processes and a common language for communicating and managing concerns relating to cybersecurity. 

ISO/SAE 21434 is applicable to series production road vehicle E/E systems, including their components and interfaces, whose development or modification began after the publication of ISO/SAE 21434

Note- ISO/SAE 21434 does not prescribe specific technology or solutions related to cybersecurity. 

Who is ISO/SAE 21434 for? 

ISO/SAE 21434 on cybersecurity engineering is useful for: 

  • Vehicle manufacturers 
  • Tier one suppliers of electrical and electronic devices for vehicles connectivity, safety, and driving functionality 
  • Tier two suppliers - processing chip, CAN BUS devices, and sensor devices 
  • Software developers  
  • Cyber security consultants 
  • Formal training suppliers for the automotive industry 
  • Certification agencies 
  • Vehicle regulatory authorities 
  • Academia 

Why should you use ISO/SAE 21434?  

ISO/SAE 21434 on cybersecurity engineering is being cited in UNECE WP29 vehicle type approval regulations, making it a requirement for the industry to comply with the standard as part of vehicle type approval. Coupling standardization with regulation will build the cybersecurity resilience that is needed in the automotive product domain. 

ISO/SAE 21434 addresses the cybersecurity perspective in engineering of electrical and electronic (E/E) systems within road vehicles. By ensuring appropriate consideration of cybersecurity, this document aims to enable the engineering of E/E systems to keep up with state-of-the-art technology and evolving attack methods. 

ISO/SAE 21434 provides vocabulary, objectives, requirements and guidelines related to cybersecurity engineering as a foundation for common understanding throughout the supply chain. This enables organizations to: 

  • Define cybersecurity policies and processes 
  • Manage cybersecurity risk 
  • Foster a cybersecurity culture 

ISO/SAE 21434 can be used to implement a cybersecurity management system including cybersecurity risk management. 

What’s changed since the last update?  

BS ISO/SAE 21434:2021 is the first edition of ISO/SAE 21434 that cancels and supersedes SAE J3061: 2016[37]

The main changes are as follows: 

  • Complete rework of contents and structure. 
Product Details
Descriptors
Road vehicles
Security
Data security
Road vehicle engineering
Management
ICS Codes
43.040.15 Car informatics. On board computer systems
Committee
AUE/32
International relationships
Identical to:

ISO 21434

ISBN
978 0 580 96112 0
Publisher
BSI