conference paper review

Securing the Road Ahead: Supporting Decision Making in Automotive Cybersecurity Risk Treatment

Abstract

In the automotive industry, as in most other sectors, risk management is essential for maintaining a balanced security posture while ensuring reasonable cybersecurity spending. ISO 21434 clearly defines the process for automotive Threat Analysis and Risk Assessment (TARA) for identifying cybersecurity risks. However, it lacks detailed guidance on subsequent risk treatment decision-making, leading to a lack of reproducibility and transparency in automotive projects. To address this issue, we propose a framework that defines a structured decision-making process and provides guidance for experts on suitable cybersecurity control sets. Our framework evaluates all potential control options based on their cost-effectiveness, aiming to mitigate high risks to an acceptable level. Through a case study and interviews with six industry experts, we assessed its feasibility and iteratively refined the framework based on the experts’ feedback

Similar works

Full text

thumbnail-image

University of Regensburg Publication Server

redirect
Last time updated on 24/08/2025

This paper was published in University of Regensburg Publication Server.

Having an issue?

Is data on this page outdated, violates copyrights or anything else? Report the problem now and we will take corresponding actions after reviewing your request.