Requirements

Requirements, i.e., legal, functional, and non-functional requirements, as well as constraints, are the basis for item definition and security analysis.

Please follow the link to a video presenting integration with, for example, Intland codebeamer: SOX-CB Synchronization.

Requirements can be classified as security-related after security goals and their associated ASILs have been defined.


System Design and Item Definition

With Eclipse PapyrusTM, SOX provides a full functional system modeling tool based on UML 2.5 and SysML 1.6.

Define the item and describe its functionality:


TARA and ATA

With the TARA module you analyze damage and threat scenarios related to the cybersecurity assets of your
item. This module has now migrated to the new web-based C-SOX interface. To discover the working method, kindly refer to new TARA.


With the ATA module you further analyze a threat scenario in order to rate the attack feasibility of that threat.

References:

ATA (Attack Tree Analysis)

Attack Tree Analysis


Security Concept

Based on your security goals, derive cybersecurity requirements and model your cybersecurity concept (CSC).


Further Analysis: FMEA and FTA

A Failure Mode and Effects Analysis (FMEA) or Failure Tree Analysis (FTA) might be used to further analyze the effects of an cyber attack.

FMEA: Derive FMEA from a system element by right-clicking on it in model explorer. As described in section [Link] model information is used to set up FMEA structure as well as function and failure net. A detailed description of the SOX FMEA module is given in the guise of the FMEA User Guide (PDF). Kindly visit: SOX Tutorials.

References:

FMEA (Failure Mode and Effects Analysis)

FMEA

FTA: Malfunctions available in the model can be used in FTA. If a malfunction net is created in FMEA or system design, a complete failure tree can be added to an FTA document. A new FTA document can also be created on a malfunction being the root element of the failure tree.

References:

FTA

FTA (Fault Tree Analysis)


Report Designer

Create templates for your reports and use them in your SOX projects. You can also create reports from scratch. SOX content can be added to reports easily by dragging and dropping. 

Kindly refer to:

Report Designer in C-SOX

C-SOX: Report Designer (Generation of, Inter Alia, FSC / TSC Documentation)