Objective
This training provides a comprehensive introduction to the Automotive SPICE® for Cybersecurity
model extension and conveys the knowledge and practical skills needed to assess
development processes from a cybersecurity perspective.
Upon completing the course, participants will be able to:
-
→
interpret and apply the Automotive SPICE® for Cybersecurity processes
-
→
integrate cybersecurity aspects into process assessments
-
→
conduct assessments that meet the requirements of the model extension
Certified intacs® assessors who successfully complete the training and exam are
authorized to lead official assessments under the Automotive SPICE® for Cybersecurity
framework.
Training Content
The content follows the official intacs® curriculum and is delivered using the
standard intacs® training material for accredited training providers.
Cybersecurity Fundamentals
- →Motivation and goals of cybersecurity in vehicle systems
- →Comparison: cybersecurity vs. functional safety
- →Relevant standards and regulations (e.g., UNECE R155, ISO/SAE 21434)
- →Threat Analysis and Risk Assessment (TARA)
- →Implementing cybersecurity in the development process
- →Cybersecurity test methods, including penetration testing
Automotive SPICE® for Cybersecurity – New Processes in Detail
Detailed coverage of the new process extensions, including base practices, typical work products, methods, and rating guidelines:
- →ACQ.2 – Supplier Request and Selection
- →MAN.7 – Cybersecurity Risk Management
- →SEC.1 – Cybersecurity Requirements Elicitation
- →SEC.2 – Cybersecurity Implementation
- →SEC.3 – Risk Treatment Verification
- →SEC.4 – Risk Treatment Validation
Cybersecurity Aspects of Existing Automotive SPICE® v3.1 Processes
- →Acquisition: ACQ.3, ACQ.4, ACQ.14, ACQ.15
- →System Engineering: SYS.2, SYS.3, SYS.4, SYS.5
- →Software Engineering: SWE.1 through SWE.6
- →Supporting Processes: SUP.1, SUP.8
- →Management Processes: MAN.3 (Project Management), MAN.5 (Risk Management)
Capability Levels & Exam Preparation
- →Interpreting and applying Capability Levels 2 and 3 in the context of cybersecurity-relevant processes
- →Application-oriented exercises for key process areas
- →Focused preparation for the official certification exam
Target Audience
-
→
Primarily: intacs® certified Automotive SPICE® assessors who want to extend their qualification to cybersecurity assessments
-
→
Professionals in cybersecurity-relevant development projects with a solid foundation in Automotive SPICE®
Prerequisites
-
→
Ideal: Valid intacs® Automotive SPICE® assessor certification
-
→
Required: Solid understanding of the current version of the Automotive SPICE® process assessment model
-
→
Several years of professional experience in the IT or automotive industry (e.g., software/systems development, project management, quality management)
Framework & Exam
-
→
Maximum of 12 participants per course
-
→
Passing the exam is a prerequisite for participating in the VDA-QMC certification process