Autoliv integrates cybersecurity throughout the product lifecycle in accordance with ISO/SAE 21434. Our Cybersecurity Management System (CSMS), secure engineering practices, and Product Security Incident Response Team (PSIRT) work together to identify, assess, and manage cybersecurity risks from concept and development through production, operation, and decommissioning. This approach supports the delivery and maintenance of secure products while enabling compliance with applicable regulatory requirements, such as UNECE UN R155 and GB/T 44495.
Product Cybersecurity at Autoliv
Autoliv's product cybersecurity program is built on four key pillars:
Governance
- A Cybersecurity Management System (CSMS) establishes the governance framework, roles, responsibilities, policies, and oversight needed to manage cybersecurity risks and drive continuous improvement.
Lifecycle
- Cybersecurity is integrated throughout the product lifecycle, from concept and development to production, operation, and decommissioning, ensuring risks are addressed at every stage.
Engineering
- Risk-based security engineering practices, including Threat Analysis and Risk Assessment (TARA), cybersecurity concept development, requirements management, verification, and validation, are applied to develop secure products.
Response
- The Product Security Incident Response Team (PSIRT) manages vulnerability intake, assessment, coordinated disclosure, remediation, and communication with stakeholders to support continuous security of deployed products.
How we manage Product Cybersecurity

ISO/SAE 21434 provides a framework for managing cybersecurity risks throughout the automotive product lifecycle. The standard promotes a risk-based approach to cybersecurity and supports the integration of security activities from concept and development through production, operation, and decommissioning. At Autoliv, ISO/SAE 21434 serves as a foundation for our product cybersecurity program and supports compliance with applicable regulations, including such as UN R155 and GB/T 44495
Autoliv's Cybersecurity Management System (CSMS) establishes the governance framework for managing product cybersecurity risks across the organization. The management system defines roles and responsibilities, supports the implementation of cybersecurity policies and processes, and promotes continuous improvement through management oversight, monitoring, and periodic reviews.
Cybersecurity is integrated throughout the product lifecycle, from concept and development to production, operation, and decommissioning. A risk-based approach is applied to identify, assess, and manage cybersecurity risks, ensuring that security considerations are incorporated into product design, implementation, validation, and ongoing support activities.
Lifecycle Stages
- Concept – Identification of cybersecurity objectives and risks.
- Development – Definition and implementation of cybersecurity requirements and controls.
- Production – Secure manufacturing and release processes.
- Operation – Monitoring, maintenance, and management of cybersecurity issues throughout the product's operational life.
Autoliv applies security engineering practices throughout product development to address cybersecurity risks and support secure product design. These activities include cybersecurity concept (including Threat Analysis and Risk Assessment (TARA)) to identify technical controls, product development & verification.
Autoliv's Product Security Incident Response Team (PSIRT) manages the intake, assessment, and coordinated handling of product cybersecurity vulnerabilities. The PSIRT collaborates with internal teams, customers and suppliers to support responsible disclosure, vulnerability remediation, and continuous cybersecurity improvement throughout the product lifecycle.