ISO/SAE 21434
Evidence request list. 50 controls, 50 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Component Development
Hardware and software components implement allocated cybersecurity requirements with secure coding practices and verification.
- Component cybersecurity requirements allocated and traceable
- Secure coding standard adopted (for example MISRA C plus security)
- Static analysis results
- Fuzz testing results for protocol stacks
- Hardware security feature configuration evidence
- MISRA compliance enforced but security rules excluded
- Fuzzing limited to one protocol
- Hardware security features available but not enabled
- Static analysis findings suppressed without justification
Concept Phase
The item under cybersecurity consideration is defined including its boundary, interfaces, operating environment, and assumptions.
- Item definition document
- Boundary diagrams with internal and external interfaces
- Operating environment description
- Assumptions log
- Dependencies on other items
- Boundary informal, leading to scope disputes during TARA
- External interfaces enumerated but not characterised
- Assumptions not revisited when environment changes
- Dependencies ignored leading to gaps
Cybersecurity goals and claims are derived from the TARA and provide the basis for cybersecurity requirements at item level.
- Cybersecurity goals derived from threat scenarios
- Cybersecurity claims with rationale
- Cybersecurity Assurance Level (CAL) determinations
- Traceability from TARA to goals
- Review record by independent assessor
- Goals stated as features not protections
- CAL not justified or treated as one-size-fits-all
- Traceability matrix incomplete
- Independent review skipped
Development
System-level cybersecurity requirements are derived from cybersecurity goals and verified through design, integration, and testing.
- System cybersecurity requirements specification
- Architecture documentation with security mechanisms
- Verification plan and execution records
- Trust boundary diagrams
- Cryptographic mechanism selection rationale
- Requirements duplicate goals without decomposition
- Cryptographic choices outdated or unjustified
- Verification focuses on positive cases only
- Trust boundaries not maintained as architecture evolves
ISO/SAE 21434: Access Control
Access control policy and enforcement. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
User access management and provisioning. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Authentication and password management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Privileged access management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Access review and recertification. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
ISO/SAE 21434: Asset Management
Asset inventory and ownership. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Acceptable use of assets. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Information classification and labeling. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Asset handling procedures. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Media management and disposal. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
ISO/SAE 21434: Communications Security
Network security management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Network service security. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Segregation in networks. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Information transfer policies. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Secure messaging. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
ISO/SAE 21434: Cryptography
Cryptographic policy and key management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Encryption of data at rest. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Encryption of data in transit. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Certificate management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Key lifecycle management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
ISO/SAE 21434: Information Security Policies
Information security policy framework. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Management direction and commitment. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Policy review and update procedures. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Roles and responsibilities definition. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Contact with authorities and special interest groups. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
ISO/SAE 21434: Operations Security
Operational procedures and responsibilities. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Protection from malware. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Backup and recovery procedures. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Logging and monitoring. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Technical vulnerability management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Audit considerations. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.
- Vehicle cybersecurity policy and roles matrix
- Asset and threat catalogue
- Cybersecurity case and TARA report
- Cryptographic key management plan
- Vulnerability and incident response playbook
- Cybersecurity not integrated with functional safety lifecycle
- Threat models missing for in-vehicle networks
- Key management for ECUs lacks rotation
- Field monitoring and incident response are immature
Lifecycle
The organisation defines and communicates end of cybersecurity support and decommissioning conditions for items including data destruction.
- End-of-support policy by item or model year
- Customer communication templates
- Decommissioning procedure including key destruction
- Data sanitisation evidence on returned units
- Records of items past end of support
- End of support not communicated to customers
- Vehicles in service past stated date without explicit risk acceptance
- Sanitisation absent on returned hardware
- Keys remain valid after end of support
Operations
Cybersecurity is maintained through operations including vulnerability management, incident response, and over-the-air updates.
- Vulnerability management procedure aligned to ISO/IEC 30111
- Incident response plan with automotive-specific playbooks
- Over-the-air update mechanism with integrity protection
- Field monitoring data flows
- Customer notification procedures
- OTA mechanism lacks rollback to known-good
- Incident response untested for safety-related cyber events
- No field monitoring telemetry
- Customer notification reactive only
The organisation performs continuous monitoring of cybersecurity information sources, internal events, and triggers to inform vulnerability and incident management.
- List of monitored sources (Auto-ISAC, CVE, supplier feeds)
- Daily triage log of cybersecurity events
- Defined triggers for further cybersecurity activities
- Escalation matrix from monitoring to response
- Periodic effectiveness review
- Monitoring relies on ad hoc engineer attention
- No formal trigger definitions, judgement calls only
- Auto-ISAC membership but no integration into workflows
- Effectiveness not measured
Organisational
The organisation establishes cybersecurity governance for road vehicle development including policy, accountability, and integration with quality management and functional safety.
- Cybersecurity policy signed by executive sponsor
- Organisational chart showing cybersecurity function
- Integration plan with ASPICE and ISO 26262 processes
- Annual management review minutes
- Resource and competence plan
- Cybersecurity function under-resourced compared to functional safety
- Policy exists but not enforced in supplier contracts
- No integration with safety, only parallel processes
- Management review focused on schedule not cybersecurity posture
People
The organisation fosters a cybersecurity culture and ensures personnel involved in vehicle cybersecurity have the required competence.
- Competence matrix for cybersecurity roles
- Training curriculum specific to automotive cybersecurity
- Annual training completion records
- Awareness campaigns evidence
- Performance objectives including cybersecurity
- Generic IT security training substituted for automotive
- Competence matrix exists but gaps unaddressed
- Awareness limited to engineering staff
- No competence requirements for suppliers
Production
Cybersecurity controls are maintained through production processes including provisioning of keys, identifiers, and configurations.
- Production cybersecurity plan
- Key provisioning procedures and HSM usage records
- Anti-counterfeiting measures
- Production network segregation evidence
- Audit logs of provisioning events
- Keys generated outside HSM and exported
- Production network shared with corporate IT
- Counterfeit detection absent
- Provisioning logs not retained
Risk
The organisation applies defined methods for asset identification, threat scenario identification, impact rating, attack path analysis, and risk determination.
- Documented risk assessment method aligned to Clause 15
- Asset register per item or component
- Threat scenario library covering STRIDE or equivalent
- Impact rating scheme covering safety, financial, operational, privacy
- Method validation records
- Method documented but applied inconsistently across teams
- Asset register limited to ECUs, missing data flows
- Impact scheme heavily weighted to safety, privacy ignored
- No calibration of analysts producing similar ratings
Risk Treatment
Risk treatment decisions are made for each threat scenario and Cybersecurity Assurance Levels (CAL 1-4) are determined to scale rigour of cybersecurity activities.
- Risk treatment plan covering avoid, reduce, share, retain
- CAL determination per cybersecurity goal
- Justification for higher CAL choices
- Residual risk register
- Senior sign-off on retained risks
- CAL defaulted to CAL 2 across items without analysis
- Treatment plan incomplete for retained risks
- Residual risk not communicated to OEM customer
- No senior sign-off on acceptance
Supply Chain
Cybersecurity activities distributed between OEM, Tier 1, and lower-tier suppliers are managed through cybersecurity interface agreements (CIA) and joint assessments.
- Cybersecurity interface agreements with each tier supplier
- RASIC matrix for distributed activities
- Supplier capability assessments
- Joint TARA workshops where applicable
- Supplier deliverables review records
- CIA signed but not maintained as scope changes
- Lower-tier suppliers not in scope of supplier programme
- Joint TARA absent for shared assets
- Deliverables accepted without independent review
TARA
Assets and their cybersecurity properties (confidentiality, integrity, availability, authenticity, authorisation, non-repudiation) are identified as the basis for threat analysis.
- Asset register with cybersecurity properties per asset
- Mapping of assets to architecture
- Property rationale documentation
- Review record of asset list
- Update procedure for asset changes
- Asset list limited to ECUs, missing data and credentials
- Properties asserted without rationale
- Asset list static across model years
- No link between asset register and TARA outputs
Threat scenarios are identified that could compromise the cybersecurity properties of assets including direct and indirect attack paths.
- Threat scenario library reused across projects
- Project-specific threat scenarios with rationale
- Coverage analysis against asset properties
- Workshop notes from threat identification sessions
- Independent review of scenario completeness
- Reused library without project tailoring
- Scenarios written only for known attacks
- No coverage tracking
- Single analyst with no peer review
The impact of threat scenarios is rated against safety, financial, operational, and privacy damage categories.
- Damage scenario descriptions per threat
- Impact rating scale and calibration
- Rated impact per scenario across SFOP categories
- Linkage to functional safety hazard assessments
- Quality review of ratings
- SFOP applied as four labels without calibrated scales
- Privacy systematically rated low without analysis
- No linkage to ISO 26262 hazard ratings
- Ratings inconsistent across analysts
Attack paths leading to threat scenarios are analysed to understand feasibility and inform risk treatment.
- Attack tree or attack path diagrams per scenario
- Identified entry points (cellular, Wi-Fi, Bluetooth, OBD, USB, charging)
- Mitigation mapping along the path
- Feasibility inputs (elapsed time, expertise, knowledge, opportunity, equipment)
- Validation against known attacks
- Attack paths narrative only, no diagrams
- Entry points incomplete (vehicle to grid often missed)
- Mitigations claimed without verification
- Feasibility inputs assumed not researched
Attack feasibility is rated and combined with impact to determine cybersecurity risk levels per threat scenario.
- Feasibility rating with documented inputs per scenario
- Risk matrix combining impact and feasibility
- Risk determination per scenario
- Threshold for acceptable risk
- Risk treatment decision records
- Feasibility tied to vendor judgement without external benchmarks
- Risk matrix biases towards low ratings
- Acceptable risk threshold unstated
- Treatment decisions without sign-off
Validation
Cybersecurity validation confirms cybersecurity goals are achieved at item level under representative operating conditions.
- Validation plan covering all cybersecurity goals
- Test environment representative of vehicle operation
- Penetration test reports by independent team
- Defect tracking and closure records
- Validation sign-off by responsible person
- Validation overlaps verification rather than confirming goals
- Pen testing internal only, no third party
- Test environment not representative
- Open defects carried into release without justification
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.