Roadmap Timeline

Security and Safety Co-Assessment

2021-2025

Problem description

Systems and services are increasingly relying on connectivity for operations, typically command and control. This means that if adequate counter-measures are not put in place, these systems may be vulnerable to cyber-attacks that can cause catastrophic events, e.g., human and environmental losses. In order to prevent these events, it is necessary to ensure that safety properties are not adversely impacted by a cyber-attack. Therefore, it becomes necessary to include cybersecurity properties in the specification and assessment of safety properties. In the automotive domain, the deployment of applications and services must include security and privacy requirements to protect critical functions such as driver assistance, collision warning, automatic energy braking, and vehicle safety communications. Cyber-attacks on these functions can cause accidents and therefore, shall be avoided, while still maintaining the safety of the system. This is a necessary step towards the deployment of trustworthy autonomous/automated vehicles.

Research aspect: Common languages for safety and security; detection and management of conflicting between safety and security requirements; tools for assessment and certification. Process(es) for safety and security co-engineering. Methods for gathering evidence supporting the compliance of safety and security assessment; Ensuring that security solutions are embedded in the system design to support the concept of ‘security by design’.

Industrial demand: All industrial/critical infrastructure and cyber-physical systems, in general.

Social aspect: Trust in components that are used daily, such as vehicles, building management systems, transportation, energy, telecommunication, health, manufacturing, etc.

Final goal: Development of Cybersecurity Cyber-physical systems, where security and safety are covered.

Benefits for EU: Develop trusted components for the Digital Society. Ensure that certifications schemes meet EU needs and values.

Domain (JRC Taxonomy): Theoretical Foundation, Human Aspects, Legal Aspects, Data Security

Sector (JRC Taxonomy): Transportation, Health, Energy, Financial, Government, etc.

Relation to emerging technologies: Connected vehicle, smart mobility (building, city, transportation), collaborative robots.

More details in the complete roadmap