{"id":{"repo_id":"emich","oai_identifier":"oai:commons.emich.edu:theses-2639"},"canonical_url":"https://search.dev.ndltd.org/etd/emich/oai:commons.emich.edu:theses-2639","repository":{"repo_id":"emich","name":"Eastern Michigan University","base_url":"https://commons.emich.edu/do/oai/"},"display":{"title":"Integration of agile approach into the implementation of the ISO/SAE 21434 on top of the V-model to enable continuous secure-by-design automotive cybersecurity development","abstract":"<p>The rapid evolution of technology is revolutionizing the automotive industry, with connected and autonomous vehicles at the forefront. These vehicles rely on complex digital ecosystems to enhance safety and efficiency but are increasingly vulnerable to cybersecurity threats. Addressing these challenges requires following robust development methodologies, while complying with cybersecurity standards. This study introduces a framework that merges the widely used agile methodology practices with the ISO/SAE 21434 standard to support secure-by-design automotive product development. Traditional development approaches like the V-model provide structured and linear project phases, but they often lack the flexibility and the ability to adapt to evolving security needs. By incorporating agile principles, the framework promotes iterative, adaptive, and collaborative processes, ensuring timely identification and mitigation of risks. This research highlights the critical role of integrating agile methodologies with the established cybersecurity standards to meet the growing demands of connected vehicle security, offering valuable contributions to both academic and industry practices. The study also demonstrates how iterative threat analysis and risk assessments can be performed to refine cybersecurity goals and prioritize risks. It also provides a practical case study, which implements the above integration, showing how techniques, such as continuous testing of the tool, were applied within every agile sprints to verify the tool's effectiveness by shifting verification and validation earlier in the development process. This approach improved risk management efficiency and ensured compliance with ISO/SAE 21434 requirements. The study highlights the framework’s practicality, showing how it can streamline cybersecurity processes in a dynamic automotive development environment. By adopting this agile-driven methodology, organizations can better manage cybersecurity risks, align with industry standards, and foster a culture of continuous improvement.</p>","abstract_html":"&lt;p&gt;The rapid evolution of technology is revolutionizing the automotive industry, with connected and autonomous vehicles at the forefront. These vehicles rely on complex digital ecosystems to enhance safety and efficiency but are increasingly vulnerable to cybersecurity threats. Addressing these challenges requires following robust development methodologies, while complying with cybersecurity standards. This study introduces a framework that merges the widely used agile methodology practices with the ISO/SAE 21434 standard to support secure-by-design automotive product development. Traditional development approaches like the V-model provide structured and linear project phases, but they often lack the flexibility and the ability to adapt to evolving security needs. By incorporating agile principles, the framework promotes iterative, adaptive, and collaborative processes, ensuring timely identification and mitigation of risks. This research highlights the critical role of integrating agile methodologies with the established cybersecurity standards to meet the growing demands of connected vehicle security, offering valuable contributions to both academic and industry practices. The study also demonstrates how iterative threat analysis and risk assessments can be performed to refine cybersecurity goals and prioritize risks. It also provides a practical case study, which implements the above integration, showing how techniques, such as continuous testing of the tool, were applied within every agile sprints to verify the tool&#x27;s effectiveness by shifting verification and validation earlier in the development process. This approach improved risk management efficiency and ensured compliance with ISO/SAE 21434 requirements. The study highlights the framework’s practicality, showing how it can streamline cybersecurity processes in a dynamic automotive development environment. By adopting this agile-driven methodology, organizations can better manage cybersecurity risks, align with industry standards, and foster a culture of continuous improvement.&lt;/p&gt;","abstract_has_math":false,"creators":["Patil, Pooja"],"institution":null,"degree_name":"Doctor of Philosophy (PhD)","degree_level":"Open Access Dissertation","degree_discipline":"College of Engineering and Technology","degree_department":null,"school":null,"contributors":["Samir Tout, PhD","Suleiman Ashur, PhD","William Sverdlik, PhD"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-01-01T08:00:00Z","date_published":"2025-01-01T08:00:00Z","updated_at":"2026-07-24T02:17:53Z","subjects":["Automotive Engineering","Computer Sciences"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://commons.emich.edu/theses/1293","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Samir Tout, PhD","Suleiman Ashur, PhD","William Sverdlik, PhD"]},{"key":"dc:creator","label":"Author","values":["Patil, Pooja"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2025-06-19T07:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["College of Engineering and Technology"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Open Access Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy (PhD)"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Automotive Engineering","Computer Sciences"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://commons.emich.edu/theses/1293"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>The rapid evolution of technology is revolutionizing the automotive industry, with connected and autonomous vehicles at the forefront. These vehicles rely on complex digital ecosystems to enhance safety and efficiency but are increasingly vulnerable to cybersecurity threats. Addressing these challenges requires following robust development methodologies, while complying with cybersecurity standards. This study introduces a framework that merges the widely used agile methodology practices with the ISO/SAE 21434 standard to support secure-by-design automotive product development. Traditional development approaches like the V-model provide structured and linear project phases, but they often lack the flexibility and the ability to adapt to evolving security needs. By incorporating agile principles, the framework promotes iterative, adaptive, and collaborative processes, ensuring timely identification and mitigation of risks. This research highlights the critical role of integrating agile methodologies with the established cybersecurity standards to meet the growing demands of connected vehicle security, offering valuable contributions to both academic and industry practices. The study also demonstrates how iterative threat analysis and risk assessments can be performed to refine cybersecurity goals and prioritize risks. It also provides a practical case study, which implements the above integration, showing how techniques, such as continuous testing of the tool, were applied within every agile sprints to verify the tool's effectiveness by shifting verification and validation earlier in the development process. This approach improved risk management efficiency and ensured compliance with ISO/SAE 21434 requirements. The study highlights the framework’s practicality, showing how it can streamline cybersecurity processes in a dynamic automotive development environment. By adopting this agile-driven methodology, organizations can better manage cybersecurity risks, align with industry standards, and foster a culture of continuous improvement.</p>"]},{"key":"dc:title","label":"Title","values":["Integration of agile approach into the implementation of the ISO/SAE 21434 on top of the V-model to enable continuous secure-by-design automotive cybersecurity development"]}]}],"canonical_facts":{"dc:contributor":["Samir Tout, PhD","Suleiman Ashur, PhD","William Sverdlik, PhD"],"dc:creator":["Patil, Pooja"],"dc:date.available":["2025-06-19T07:00:00Z"],"dc:description.abstract":["<p>The rapid evolution of technology is revolutionizing the automotive industry, with connected and autonomous vehicles at the forefront. These vehicles rely on complex digital ecosystems to enhance safety and efficiency but are increasingly vulnerable to cybersecurity threats. Addressing these challenges requires following robust development methodologies, while complying with cybersecurity standards. This study introduces a framework that merges the widely used agile methodology practices with the ISO/SAE 21434 standard to support secure-by-design automotive product development. Traditional development approaches like the V-model provide structured and linear project phases, but they often lack the flexibility and the ability to adapt to evolving security needs. By incorporating agile principles, the framework promotes iterative, adaptive, and collaborative processes, ensuring timely identification and mitigation of risks. This research highlights the critical role of integrating agile methodologies with the established cybersecurity standards to meet the growing demands of connected vehicle security, offering valuable contributions to both academic and industry practices. The study also demonstrates how iterative threat analysis and risk assessments can be performed to refine cybersecurity goals and prioritize risks. It also provides a practical case study, which implements the above integration, showing how techniques, such as continuous testing of the tool, were applied within every agile sprints to verify the tool's effectiveness by shifting verification and validation earlier in the development process. This approach improved risk management efficiency and ensured compliance with ISO/SAE 21434 requirements. The study highlights the framework’s practicality, showing how it can streamline cybersecurity processes in a dynamic automotive development environment. By adopting this agile-driven methodology, organizations can better manage cybersecurity risks, align with industry standards, and foster a culture of continuous improvement.</p>"],"dc:identifier":["https://commons.emich.edu/theses/1293"],"dc:subject":["Automotive Engineering","Computer Sciences"],"dc:title":["Integration of agile approach into the implementation of the ISO/SAE 21434 on top of the V-model to enable continuous secure-by-design automotive cybersecurity development"],"thesis:degree_discipline":["College of Engineering and Technology"],"thesis:degree_level":["Open Access Dissertation"],"thesis:degree_name":["Doctor of Philosophy (PhD)"]},"updated_at":"2026-07-24T02:17:53Z"}