Requirement Specification
New AC Criteria
Does Supplier ensure that the CS requirement is received from Renault Along with the RFQ Package?
Does the Supplier analysed the R/N requirement for any of the appliciability?
Does the status is provided for the applicability Requirement?
Whether any NOK ,Pending and Not applicable Requirement is available?
if yes,Whether the Rationale provided by Supplier for NOK,Pending and NA Requirement
Whether the unique Requirement ID from the R/N Spec is mapped with the Supplier Requirement ID
in this Document ?
Does the Supplier provide the traceability reference between the Technical Cybersecurity Concept ->
Design Definition ->Design Verification Document
Does the Supplier provided the detailed Justification of the Compliance with each cybersecurity
Requirement in accordance with the Cybersecurity Plan
Is the Cybersecurity requirements for decommissioning specified?
Does the Supplier confirms the application of techincal cyberseurity Requirement that is concerning
the SW ?
If yes whether it is justified taking it in account by considering any of the Alliance SW Quality
Assurance standard
Whether Supplier has implemented System level cybersecurity Requirement defined in [TS1]?
Does Supplier has specified and implemented appropriate cybersecurity related Robustness
mechanism and associated reliability requirement at SW and HW Level (if Applicbale)
whether this SW and HW requirement is specified based on the Cybersecurity analysis result at
System,software and hardware levels?
Whether R/N Cybersecurity Requirement and Architectural Design Comply with CS
Requirement with High Level
Whether Supplier confirms the implementation of selected cybersecurity controls in the `R/N
cybersecurity requirement?
whether Supplier has included the specification of interfaces between the sub components of the
defined architectural Design including their usage ,static and dynamic aspects? (In case of applicable)
While defining Cybersecurity Specification Whether the Cybersecurity implications of post
Development phases was considered ?
Whether the Cybersecurity Specification include the identification of calibration and Configuration
parameters relevant for fulfiling the Cybersecurity requirement?
Whether cybersecurity requirements allocated to components of the architectural design?
_x000D_ Confidential C
#
Is the shared Requirement File is the Final baselined version?
If this is not the Final Baselined Version, when will be the Baselined version file will be shared and
confirmed by Supplier?
Whether the shared file is reviewed and validated?
In case of Open Points , Is the due date/action Plan/ is provided
_x000D_ Confidential C
#
ment Specification
Comments
the document (SEC1/SEC2) ,
Is the Requirement File shared ensures the Project Specific Requirement , Does it was
Confirmed By Renault Architect
0 = no flexibility, requirement has to be met
1 = low flexibility, requirement barely negotiable
To be check with Architect
Example :FRQ_FMW_SBO_011
supplier maintain traceability between CS requirements and their source requirements,
in a bidirectional manner at all steps of refinement?
Traceability should be established for
Customer Requirements ->System Requirements-> CS Requirements -> CS Components
Does the Supplier maintain traceability between CS requirements and linked CS work
products (e.g. test specification or verification criteria) and Cybersecurity activities?
To be check in the Renault "Contract" Milestone SOW
Before Contract Milestone - HW Cybersecurity Requirement
Before VC Milestone - Other Cybersecurity Requirement SOW
SOW
SOW
Referance document [SQA1] [SQA2][SQA3] SOW
Technical Specification (Supplier Document) SOW
To be confirmed with Architect SOW
To be confirmed with Architect SOW
To be confirmed with Architect
Cybersecurity controls can be selected from trusted catalogues
Design Document to be checked as well
To be confirmed with Architect
To confirm the fulfilment of defined Cybersecurity Requirement
Example : Secure Management of the key store,deactiviation of debug interfaces,
procedure to delete personally identifiable information
Example : The correct configuration for the integration of the Hardware security module
To be confirmed with Architect
_x000D_ Confidential C
#
Architect to be confirmed
_x000D_ Confidential C
#
Concept AC
NA
_x000D_ Confidential C
#