JUCS - Journal of Universal Computer Science 32(7): 956-984, doi: 10.3897/jucs.175236
Assessment with ASPICE and ASPICE for Cybersecurity Processes
expand article infoChristian Schlager, Atif Mashkoor
‡ Johannes Kepler University, Linz, Austria
Open Access
Abstract
The automotive industry increasingly relies on complex embedded systems that inte-grate software, electronic hardware, electromechanical, and mechanical components. To ensure quality, the Automotive Software Process Improvement and Capability Determination (ASPICE) framework has been extended by cybersecurity, which has become a critical concern. Recognizing these risks, the United Nations Economic Commission for Europe (UNECE) introduced Regulation No. 155 in 2021, establishing mandatory provisions for vehicle type approval and cybersecurity management. To address these regulatory demands, ASPICE for Cybersecurity extends the standard ASPICE model with additional processes focused on identifying, analyzing, and mitigating security threats. While the combined assessment of ASPICE and ASPICE for Cybersecurity ensures both process maturity and security compliance, it presents significant challenges for organizations. Conducting separate assessments for ASPICE and ASPICE for Cybersecurity increases time, cost, and organizational workload, as many process areas overlap in scope and evidence. This paper proposes a unified assessment approach designed to evaluate compliance with both ASPICE and ASPICE for Cybersecurity in a single, integrated process. The approach involves systematically mapping equivalent or related process areas across the two models. This approach was applied in an industry case study, demonstrating a reduction in total assessment time and minimizing disruption to development teams. The results indicate that integrated assessments can maintain the rigor and comprehensiveness of separate evaluations while improving efficiency and reducing operational burden.
Keywords
Development Process, ASPICE, ASPICE for Cybersecurity, ISO/IEC 33020
login to comment