Automotive software, including In-Vehicle Infotainment (IVI) systems, is developed through multi-tier supply chains involving OEMs, Tier-1 suppliers, and other stakeholders. Under automotive cybersecurity regulations, OEMs bear responsibility for managing vulnerabilities across the entire supply chain, making the exchange and tracking of vulnerability impact assessments among suppliers a significant challenge.
VEX has been identified as a promising mechanism that could distribute vulnerability impact assessments among suppliers in response to these challenges. Using IVI software development as a focus, we verified whether suppliers at each tier can produce VEX documents for their own products, and whether those assessments can be transmitted and utilized through a multi-tier supply chain while preserving their intended meaning.
In this session, we present practical design guidelines for applying VEX to multi-tier supply chains. We also introduce design and operational approaches that enable VEX-based vulnerability assessment distribution across complex supply chains beyond the automotive domain.
Yuta Kiyoumi is the Security Architect for IVI software development at Honda Motor Co., Ltd. He also serves as a member of the Honda OSPO promoting secure OSS adoption, and participates as a member of the OpenSSF.