This paper investigates the existence and systematic identification of baseline assets, threats, and mitigation measures for automotive cyber-physical systems (CPSs). It introduces the SCAR automotive model, a comprehensive registry integrating 18 high-level asset categories and 124 fine-grained assets across security and privacy domains. Threats are analysed using STRIDE and LINDDUN, while mitigations are grounded in ISO/IEC 27002:2022 and GDPR, ensuring regulatory alignment. The SCAR automotive model provides a well-grounded, scalable, and operationally actionable framework for the engineering of cybersecurity and privacy. It serves as a baseline control framework, bridging threat modelling with compliance. The model is constructed via the SCAR modelling methodology, a domain-agnostic, human-AI (HAI) approach with multi-level refinement, easily adaptable to other automotive sub-domains or other CPS areas such as healthcare and energy.

A baseline threat and mitigation model for automotive cybersecurity and privacy

Bella G.;Bonaventura D.;Castiglione G.;Esposito S.;Riccobene S.;Santamaria D. F.
2026-01-01

Abstract

This paper investigates the existence and systematic identification of baseline assets, threats, and mitigation measures for automotive cyber-physical systems (CPSs). It introduces the SCAR automotive model, a comprehensive registry integrating 18 high-level asset categories and 124 fine-grained assets across security and privacy domains. Threats are analysed using STRIDE and LINDDUN, while mitigations are grounded in ISO/IEC 27002:2022 and GDPR, ensuring regulatory alignment. The SCAR automotive model provides a well-grounded, scalable, and operationally actionable framework for the engineering of cybersecurity and privacy. It serves as a baseline control framework, bridging threat modelling with compliance. The model is constructed via the SCAR modelling methodology, a domain-agnostic, human-AI (HAI) approach with multi-level refinement, easily adaptable to other automotive sub-domains or other CPS areas such as healthcare and energy.
2026
Cyber-physical systems
GDPR
human-AI collaboration
ISO/IEC 27002
LINDDUN
STRIDE
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.11769/728789
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact