Discussions
Categories
Groups
Documentation
Knowledge base
Developer portal
App catalog
The Hub
GitHub
Home
Newly Imported
User Forums
How it Works
Cybersecurity: How is CAL of Cybersecurity Goal be calculated
medini_1053872515
The current BestPractice Template ISO21434 seems to calculate the CAL for each Cybersecurity Goal. What is the formula or algo behind this calculation ?? Thanks, Timo
Find more posts tagged with
medini
medini legacy
Accepted answers
All comments
medini_1024098885
Hello Mr. Bruderek; I based the calculation on Annex E of the ISO/SAE21434 and especially on table E.1 (whereby the attack vector values are replaced with the respective feasibility levels). Thus I take the highest impact level from Safety, Financial, Operational, Privacy and relate it to the unmitigated feasibility level. The resulting CAL is assigned to the Cybersecurity Goal. If a Cybersecurity Goal is assigned to multiple threat scenarios with different CALs then the highest CAL out of those is assigned to the Cybersecurity Goal. I know that this approach is arguable but I also know that there is still a working group in charge to clarify this matter. Best regards Mario Winkler
medini_1053872515
Hello Mr. Winkler, sound like a good idea. As far as i know, there is also a property "Category" with each attack object. Maybe this can be used to determine the attack vector of an threat via the attack tree ? This will also work, even if attack potentiel based approach is used for rating an attack .. Best regards, Timo Bruderek
Quick Links
All Categories
Recent Posts
Activity
Unanswered
Groups
Help
Best Of