Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ensuring Uptane explicitly references relevant standards #88

Open
jhdalek55 opened this issue Jan 15, 2021 · 6 comments
Open

Ensuring Uptane explicitly references relevant standards #88

jhdalek55 opened this issue Jan 15, 2021 · 6 comments
Milestone

Comments

@jhdalek55
Copy link
Collaborator

As new standards and regulations emerge, we need to be sure that Uptane references these text, and complies with what they stipulate. Therefore, we need to add text that references SAE J3101 (H/W Protected Security Environments, aka HSMs), ISO/SAE 21434 Road Vehicle Cybersecurity, ISO 24089 Vehicle S/W Update, and others. As @iramcdonald points out, these will be the core specs for security audits for UNECE WP29 regulations by 2022.

@jhdalek55
Copy link
Collaborator Author

@iramcdonald--please edit/revise as needed.

@jhdalek55
Copy link
Collaborator Author

@iramcdonald will we likely need to incorporate any of these references in V. 2.0.0? If so, where do we start?

@jhdalek55 jhdalek55 added this to the Future milestone Dec 17, 2021
@jhdalek55
Copy link
Collaborator Author

We should probably do a walk through the Standard to see where specific references to these regulations/standards are specifically warranted. We should also review and update https://github.com/uptane/deployment-considerations/blob/master/regulations_and_standards.md as well.

@jhdalek55
Copy link
Collaborator Author

If the work indicated in the comment above is addressed, I think we we can flag this for 2.1.0.

@iramcdonald
Copy link

Agreed that we should scan through the Standard (and Deployment Best Practices?) to see where we should be specific (for either ISO/SAE 21434:2021 or ISO 24089:2023) and flag this work for 2.1.0.

@jhdalek55
Copy link
Collaborator Author

@iramcdonald ...short of having to read through both ISO standards (even if I could access full text without paying an arm and a leg)...is there some type of short hand criteria that could help one evaluate which parts of the texts are relevant to Uptane? I would take on the review myself, but I don't have enough knowledge if the contents of the standards to know what to look for?

@jhdalek55 jhdalek55 modified the milestones: Future, 2.2.0 Apr 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants