Product Security

The Cyber Security regulations, e.g., as laid down in AMC 20-42 from EASA, concern themselves with showing that the security is sustained even under cyber-attacks on products and is good enough as not to have an unacceptable effect on safety. In contrast, the information security regulations address the organisational aspects of security.

Accepted industry standards (EUROCAE/RTCA ED-202B/DO-326B, ED-203A/DO-356A and ED-204A/DO-355) are the guideline for implementing product cyber security.

TSSC can support you with the successfully adaptation of these standards in your organisation or project.

TSSC can support you for setting up the necessary processes in your organisation and/or project that are tailored to your setup and situation. These processes will be compliant with the requirements from ED-202B, using methods following the suggestions in ED-203A. Also, the Continued Airworthiness of your products will be incorporated in the processes (ED-204A). As the concrete definition of processes always depends on the environment, the role of your organisation, we can support with our experience to define processes that are tailored to your needs, efficient for your organisations and useable in practice. Templates for the artefacts needed, e.g., PSecAC or SSD document, can be provided as well.

PSecAc Creation Support

The Plan for Security Aspects of Certification (PSecAC) is the central document for the cyber security aspects for a product, defining or referencing the activities to be performed, interfaces, with stakeholders, how compliance is to be shown, etc. TSSC can support you in creating this document and also the accompanying PSecAC Summary document in the course of the product development.

Training

For training information see Training