0% found this document useful (0 votes)
28 views5 pages

Cybersecurity Requirement Compliance Checklist

The document contains requirements for supplier cybersecurity specifications for a new AC system. It asks if the supplier ensures Renault's cybersecurity requirements are received and analyzed, and the status of applicable requirements is provided. It also asks if the supplier maintains traceability of cybersecurity requirements between documents, provides justifications for compliance, and specifies requirements at the system, software and hardware levels based on a cybersecurity analysis.

Uploaded by

en zia
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
28 views5 pages

Cybersecurity Requirement Compliance Checklist

The document contains requirements for supplier cybersecurity specifications for a new AC system. It asks if the supplier ensures Renault's cybersecurity requirements are received and analyzed, and the status of applicable requirements is provided. It also asks if the supplier maintains traceability of cybersecurity requirements between documents, provides justifications for compliance, and specifies requirements at the system, software and hardware levels based on a cybersecurity analysis.

Uploaded by

en zia
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
  • Requirement Specifications Overview
  • Comments and Actions
  • Specifications and Integration

Requirement Specification

New AC Criteria

Does Supplier ensure that the CS requirement is received from Renault Along with the RFQ Package?
Does the Supplier analysed the R/N requirement for any of the appliciability?

Does the status is provided for the applicability Requirement?


Whether any NOK ,Pending and Not applicable Requirement is available?
if yes,Whether the Rationale provided by Supplier for NOK,Pending and NA Requirement

Whether the unique Requirement ID from the R/N Spec is mapped with the Supplier Requirement ID
in this Document ?
Does the Supplier provide the traceability reference between the Technical Cybersecurity Concept ->
Design Definition ->Design Verification Document

Does the Supplier provided the detailed Justification of the Compliance with each cybersecurity
Requirement in accordance with the Cybersecurity Plan
Is the Cybersecurity requirements for decommissioning specified?
Does the Supplier confirms the application of techincal cyberseurity Requirement that is concerning
the SW ?
If yes whether it is justified taking it in account by considering any of the Alliance SW Quality
Assurance standard
Whether Supplier has implemented System level cybersecurity Requirement defined in [TS1]?
Does Supplier has specified and implemented appropriate cybersecurity related Robustness
mechanism and associated reliability requirement at SW and HW Level (if Applicbale)
whether this SW and HW requirement is specified based on the Cybersecurity analysis result at
System,software and hardware levels?
Whether R/N Cybersecurity Requirement and Architectural Design Comply with CS
Requirement with High Level
Whether Supplier confirms the implementation of selected cybersecurity controls in the `R/N
cybersecurity requirement?

whether Supplier has included the specification of interfaces between the sub components of the
defined architectural Design including their usage ,static and dynamic aspects? (In case of applicable)
While defining Cybersecurity Specification Whether the Cybersecurity implications of post
Development phases was considered ?
Whether the Cybersecurity Specification include the identification of calibration and Configuration
parameters relevant for fulfiling the Cybersecurity requirement?
Whether cybersecurity requirements allocated to components of the architectural design?

_x000D_ Confidential C
#
Is the shared Requirement File is the Final baselined version?
If this is not the Final Baselined Version, when will be the Baselined version file will be shared and
confirmed by Supplier?
Whether the shared file is reviewed and validated?
In case of Open Points , Is the due date/action Plan/ is provided

_x000D_ Confidential C
#
ment Specification
Comments

the document (SEC1/SEC2) ,

Is the Requirement File shared ensures the Project Specific Requirement , Does it was
Confirmed By Renault Architect
0 = no flexibility, requirement has to be met
1 = low flexibility, requirement barely negotiable
To be check with Architect

Example :FRQ_FMW_SBO_011
supplier maintain traceability between CS requirements and their source requirements,
in a bidirectional manner at all steps of refinement?
Traceability should be established for
Customer Requirements ->System Requirements-> CS Requirements -> CS Components
Does the Supplier maintain traceability between CS requirements and linked CS work
products (e.g. test specification or verification criteria) and Cybersecurity activities?

To be check in the Renault "Contract" Milestone SOW

Before Contract Milestone - HW Cybersecurity Requirement


Before VC Milestone - Other Cybersecurity Requirement SOW
SOW

SOW

Referance document [SQA1] [SQA2][SQA3] SOW


Technical Specification (Supplier Document) SOW

To be confirmed with Architect SOW

To be confirmed with Architect SOW

To be confirmed with Architect


Cybersecurity controls can be selected from trusted catalogues
Design Document to be checked as well

To be confirmed with Architect


To confirm the fulfilment of defined Cybersecurity Requirement
Example : Secure Management of the key store,deactiviation of debug interfaces,
procedure to delete personally identifiable information

Example : The correct configuration for the integration of the Hardware security module
To be confirmed with Architect

_x000D_ Confidential C
#
Architect to be confirmed

_x000D_ Confidential C
#
Concept AC

NA

_x000D_ Confidential C
#

_x000D_# Confidential C
Requirement Specification 
New AC Criteria 
Does Supplier ensure that the CS requirement is received
_x000D_# Confidential C
Is the shared Requirement File is the Final baselined version?
Whether the shared file is reviewed an
_x000D_# Confidential C
ment Specification 
Comments
the document (SEC1/SEC2) ,
To be check with Architect
To be check in the
_x000D_# Confidential C
Architect to be confirmed
_x000D_# Confidential C
Concept AC
NA

You might also like