What is a CSMS?
A Cyber Security Management System (CSMS) provides a structured framework for managing cybersecurity throughout an organization. In the automotive context, it is mandated by UNECE Regulation No. 155 and supports compliance with ISO/SAE 21434.
Key Components
- Governance: Cybersecurity policies, roles, and responsibilities
- Risk management: Continuous identification and treatment of cyber risks
- Development processes: Secure development lifecycle integration
- Production and operations: Security during manufacturing and post-production
- Supply chain management: Cybersecurity requirements for suppliers
- Incident response: Detection, response, and recovery capabilities
- Monitoring and improvement: Ongoing evaluation and enhancement
Regulatory Context
UNECE WP.29 R155 requires vehicle manufacturers to demonstrate an approved CSMS before obtaining type approval for new vehicles. This requirement cascades through the supply chain, affecting all automotive suppliers.
Relationship to IEC 62443
In the OT context, IEC 62443-2-1 defines requirements for establishing a CSMS for industrial automation and control systems. The principles are similar but tailored to industrial environments.
Back to Glossary