Responsible use of Open-source Software from the Automotive SPICE & Cybersecurity perspective
Alexander Much - Safionyx GmbH & Co KGThe qualification of proprietary software in embedded system is understood and well-established. In the meantime, the portion of open-source software increases also in embedded systems. The established processes audit models cannot be applied without creative thinking to open-source software.
The context in the automotive domain is given by quality standards such as Automotive SPICE and currently applicable functional safety and cybersecurity standards such as the ISO 26262, UNECE R155, ISO 21434 or the CRA.
Given this context the use of open-source software needs to be done responsibly, considering:
■ qualification, integration and validation,
■ roles and responsibilites, and
■ a defined approach to long-term maintenance and security monitoring.
The EU Cyber Resilience Act gives a new perspective on responsibilites and roles in open-source projects that support an auditor in the judgement of a project. After all the project is the temperature wheras the audit model is only the thermometer. We need to learn
to measure the temperature in open-source projects adequatly.
The presentation tries to share experiences and ideas from the view of a principal automotive SPICE assessor and gives suggestions on what is acceptable and what might be problematic in a project.
Short Bio:
Alexander Much, Founder of Safionyx, helps automotive and embedded organizations with Functional Safety, Cybersecurity and Software Compliance. Previously 22 years at Elektrobit, most recently Director of Quality, Functional Safety, Cybersecurity and Open Source,
and co-architect of the first automotive HPC platform now in series production. INTACS Principal Assessor and Cambridge mathematician.