ECE R155
Overview
Automotive Network Security and Data Protection: UNECE R155 CSMS (Cyber Security Management System)
The United Nations R155 will be binding on new cars on the ECE market until July 2022. Japan announced in January 2022 that it will implement this policy. For old cars, this regulation will take effect before 2024. This puts enormous pressure on original equipment manufacturers and their supply chains, as the release of cars in the market as part of the ECE requires certification. In addition, demonstrating the ability to manage network security can provide customers with mutual trust.
The United Nations R 155 rule divides the type approval of original equipment manufacturers into two
1. The original equipment manufacturer must implement a network Safety management system (CSMS).
2. Display auditable evidence of original equipment manufacturers executing decisions regarding safety in CSMS. The regulation even provides examples of threats, threat mitigation, and security control projects. In other words, the regulation clearly shows what should be done. But it does not provide guidance.