Automotive Security & ISO 21434
Riscure Academy - Online Group TrainingFor architects, designers, and developers to better understand automotive security and become aware of.
Duration
4 courses
4 weeks
16 hours self-paced eLearning and practical exercise
4 hours Live Mentoring
Certificate
70% or higher on final assessment
Interactive
Exercises
Assignments
Quizzes
Live mentoring
Scalable
Self-paced eLearning
Scheduled live mentoring
Spaced for efficiency & effectiveness
Scale to multiple groups
After this program participants will be able to
Security Engineering
Recognize security assets in a TOE
Understand how to apply the attack tree method
Rate and select attack paths
Describe main methods of defence
Embedded Systems
Use open source tooling to identify PCB interfaces
Determine relevance of a component for security
Understand relevance of a component to an attacker
Create and apply countermeasures
Defence & Countermeasures
Evaluate required security properties of an asset
Understand modern threats: implementation attacks, SCA, FI
Understand the role of team work in implementation of security primitives
Understand how modern countermeasures can protect against modern threats
Automotive Security & ISO 21434
This program helps architects, designers, and developers of bootloaders become aware of common security mistakes and teaches how to correct or avoid these in a highly practical way.
An automotive E/E solution that does not protect from an adversarial action cannot be considered state-ofthe-art. Breached security of a safety-critical component leads to potential liability and may result in a costly delay in production because you cannot meet your functional safety requirements any longer. Based on years of experience developing and certifying secure devices and software across various industries, Riscure has created a dedicated interactive Automotive Security Training.
What makes this program unique?
In this learning path we bridge the gap between formalized safety frameworks such as ISO 26262, SAE J3061-20161 and ISO/SAE 21434 (draft version) and the best practices in security
Architects, designers, and developers of bootloaders
Analyze implementation trade-offs
Implement a secure bootloader
Harden a bootloader
Fast Track Your Security
- Introduction to automotive security events that shaped the
- industry and a comparison with other industries.
- Security terminology and key concepts.
- Industry security practices from payment to content protection.
- Safety ≠ Security and how to integrate security in automotive development processes.
Security Requirements Engineering
- The role of security requirements and why they are issued (based on SAEJ3061)
- Implementation challenges (e.g. unrealistic requirements), how to work with assumptions, expectations, and processes.
- Threat modelling: compare/contrast MITRE TARA, EVITA, STRIDE/DREAD, HEAVENS and Common Criteria
- Case: Mock-up case study (TARA)
Secure Code Development
- Why MISRA-C compliant code may not be secure code.
- Secure coding best practices based on 15+ years of code reviews.
- Understanding costs and trade-offs of secure coding during early development
- Real world challenges: hunting vulnerabilities, linked vulnerabilities, and inherited vulnerabilities.
Understanding ISO/SAE 21434
- Recent events in cybersecurity domain: who is affected? ISO/SAE 21434, SAE J3101 and UN ECE regulations and how safety and security contrast
- Understanding ISO/SAE 21434 changes. Explore Cyber Assurance Levels (CALs) and map ISO21434 (w.r.t ISO26262) to useful resources.
Lead developer
Name Here
Actionable and indispensable knowledge of security in Embedded Systems and IoT devices. Training on hardware and software security in a classroom setting, online or hosted in your own knowledge program.
Let’s schedule a digital meeting
What people say
“Very interesting learning approach and material across different aspects of state-of-the-art SoC development with Security in mind. I really want to thank Riscure for offering such good trainings, and the their trainers who make amazing use of their skills, experiences and kindness to easily communicate complex concepts to the audience.”
– Qualcomm
Get Started Today
Don’t let your organization’s embedded systems become an easy target. Invest in the security and success of your business by partnering with Riscure Academy. Contact us today to discuss your training needs and explore our approach. Together, we’ll empower your team to secure your organization’s future.
Frequently asked questions
Do you do individual training?
What is the minimum group size for your expert-led training program?
Are your programs delivered online or as classroom ?
customer's location. Our online programs blend self-paced e-learning, exercises, assessments, and in certain cases expert-sessions (like Q&A webinars or Group Exercises) with Riscure experts.
When can we start with the training/ what do the training schedules look like?
Does customer have access to the training materials after the program?
For expert-led group training, including online/hybrid and classroom formats, access to relevant training materials remains available after the training period. The formal training schedule with deadlines is coordinated between Riscure and the customer.