Loading…
Tuesday October 6, 2026 16:50 - 17:05 CEST
Automotive software, including In-Vehicle Infotainment (IVI) systems, is developed through multi-tier supply chains involving OEMs, Tier-1 suppliers, and other stakeholders. Under automotive cybersecurity
regulations, OEMs bear responsibility for managing vulnerabilities across the entire supply chain, making the exchange and tracking of vulnerability impact assessments among suppliers a significant
challenge.

VEX has been identified as a promising mechanism that could distribute vulnerability impact assessments among suppliers in response to these challenges. Using IVI software development as a focus, we
verified whether suppliers at each tier can produce VEX documents for their own products, and whether those assessments can be transmitted and utilized through a multi-tier supply chain while preserving
their intended meaning.

In this session, we present practical design guidelines for applying VEX to multi-tier supply chains. We also introduce design and operational approaches that enable VEX-based vulnerability assessment
distribution across complex supply chains beyond the automotive domain.
Speakers
avatar for Yuta KIYOUMI

Yuta KIYOUMI

Assistant Chief Engineer, Honda Motor Co., Ltd.
Yuta Kiyoumi is the Security Architect for IVI software development at Honda Motor Co., Ltd. He also serves as a member of the Honda OSPO promoting secure OSS adoption, and participates as a member of the OpenSSF.
avatar for Akihiko Takahashi

Akihiko Takahashi

OpenSSF Community Member, Fujitsu
Linux distributors for Edge computing machines
Tuesday October 6, 2026 16:50 - 17:05 CEST
South Hall 3B-3C

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link