Governing security in the product organisation
Where product security decisions are actually taken: the decision rights, the risk assessment they run on, and the conformity evidence they leave behind.
Governance5 Sept 20265 min read
On this page
Scope
A product organisation ships what the law treats as regulated products: vehicles, industrial components, products with digital elements. Their duties fall on the manufacturer, not the corporate security function, so governance must reach the teams that build and release.
One loop runs through it. Governance sets the decision rights: who signs a threat analysis and risk assessment, who accepts a residual product risk, who rules a change a substantial modification. Risk supplies the instrument — the product risk assessment, which paragraph 7.2.2.2 asks be kept current by a process 1. Compliance is what those decisions leave an authority to read.
In scope: decision rights, the risk instrument, the supplier interface, the evidence trail.
Out of scope: engineering method, the approval decision, and building the management system — the sibling pattern.
Phases
| Phase | Purpose | Planning horizon | Closes when |
|---|---|---|---|
| 1. Duty map | Which instruments bind which line | 3–5 weeks | Each line has a duty holder |
| 2. Decision rights | Who signs, accepts and escalates, at which gate | 4–8 weeks | One table carries all three |
| 3. Instrument | Make the risk assessment what decisions run on | 3–5 months | Each decision cites a dated assessment |
| 4. Evidence and review | Wire conformity output into oversight | 6–10 weeks | Governance reads the authority's file |
Deliverables
Paragraphs are UN Regulation No. 155 [2025/5] 2; articles are Regulation (EU) 2024/2847 3.
| Deliverable | Required by | Maintained by |
|---|---|---|
| Product security authority table | ISO/SAE 21434:2021 clause 5.4.1 | Governance owner |
| Product risk assessment, kept current | Paragraph 7.3.3; Articles 13(2), 13(3) | Product security owner |
| Residual risk acceptance record | Paragraph 7.2.2.2(c) | The accepting role |
| Cybersecurity case | Clause 6.4.7 4 | Cybersecurity manager |
| Supplier interface agreement | Paragraph 7.2.2.5; clause 7.4.3 | Procurement, engineering |
| Modification decision record | Paragraph 8.1; Article 22 | Change authority |
| Technical documentation and conformity declaration | Articles 13(4), 13(12), 13(13) | Compliance owner |
Roles
| Role | Side | Accountable for |
|---|---|---|
| Executive sponsor | Organisation | The authority table and the review reading it |
| Governance owner | Organisation | Decision rights, escalation, the calendar |
| Product security owner | Organisation | The risk assessment and its currency |
| Change authority | Organisation | Whether a change re-opens approval or conformity |
| Suppliers | Contracted third parties | Their share of the assessment and agreed activities |
| Adviser | External | Method, the table's design, rehearsal |
What the auditor or authority asks
Failure modes
Frameworks
| Instrument | What it asks of governance | Where it lands |
|---|---|---|
| UN Regulation No. 155 [2025/5] | Processes to manage, assess, categorise and treat product risk | Paragraph 7.2.2.2(a), (c) |
| Regulation (EU) 2024/2847 | A current risk assessment inside the technical file; a conformity route | Articles 13(2)–13(4), 13(12) |
| ISO/SAE 21434:2021 | Policy and responsibilities; an independent audit; project responsibilities; a supplier agreement | Clauses 5.4.1, 5.4.7, 6.4.1, 7.4.3 5 |
| IEC 62443-4-1:2018 | Eight practices: Security management; Specification of security requirements; Secure by design; Secure implementation; Security verification and validation testing; Management of security-related issues; Security update management; Security guidelines | Practices 1 to 8 6 |
| ISO/IEC 27001:2022, 27002:2022 | Authorities, operational control, security in projects and development | Clauses 5.3, 8.1 7; controls 5.8, 8.25, 8.27 8 |
| NIST CSF 2.0 | Supply chain risk, risk assessment and platform security | GV.SC, ID.RA, PR.PS 9 |
The boundary with the enterprise ISMS
Clause 5.3 of ISO/IEC 27001:2022 is Organizational roles, responsibilities and authorities, where enterprise authority is written down. Control 5.8, Information security in project management, carries it into a project, asking for early and periodic risk assessment 10. The seam: the ISMS holds the corporate decision, the product programme the regulated one. No ISMS certificate discharges a product duty. Paragraph 7.3.1 asks for a valid certificate of compliance for the cyber security management system, covering the vehicle type approved 11. What the programme borrows is machinery: control ownership, the operating model, Product CSMS, CRA duties by class and IEC 62443 for governance people.
References
- UNECE. UN Regulation No. 155 [2025/5]. OJ L, 2025/5, 10.1.2025 12.
- European Parliament and Council. Regulation (EU) 2024/2847. OJ L, 2024/2847, 20.11.2024 13.
- ISO and SAE International. ISO/SAE 21434:2021.
https://www.iso.org/standard/70918.html. Clause numbers and titles from a licensed copy, 2026-09-05. - IEC. IEC 62443-4-1:2018.
https://webstore.iec.ch/en/publication/33615. Practice names from a licensed copy, 2026-09-05. - ISO/IEC. ISO/IEC 27002:2022.
https://www.iso.org/standard/75652.html. Control numbers and titles from a licensed copy, 2026-09-05. ISO/IEC 27001:2022 clause titles: ISO Online Browsing Platform. - NIST. NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0.
https://doi.org/10.6028/NIST.CSWP.29. Category names from Appendix A.
Sources
- 1EU Publications Office CELEX 42025X0005 para. 7.2.2.2 · verified 2026-09-05
- 2EU Publications Office CELEX 42025X0005 paras. 7.2.2.2, 7.2.2.5, 7.3.3 and 8.1 · verified 2026-09-05
- 3EU Publications Office CELEX 32024R2847 Art. 13(2) to 13(4), 13(12), 13(13) and 22 · verified 2026-09-05
- 4ISO/SAE 21434:2021 clause 6.4.7, licensed copy · verified 2026-09-05
- 5ISO/SAE 21434:2021 clauses 5.4.1, 5.4.7, 6.4.1 and 7.4.3, licensed copy · verified 2026-09-05
- 6IEC 62443-4-1:2018 practices 1 to 8, licensed copy · verified 2026-09-05
- 7ISO/IEC 27001:2022 clauses 5.3 and 8.1, iso.org/obp · verified 2026-09-03
- 8ISO/IEC 27002:2022 controls 5.8, 8.25 and 8.27, licensed copy · verified 2026-09-05
- 9NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-05
- 10ISO/IEC 27002:2022 control 5.8, licensed copy · verified 2026-09-05
- 11EU Publications Office CELEX 42025X0005 para. 7.3.1 · verified 2026-09-05
- 12EU Publications Office CELEX 42025X0005, full text · verified 2026-09-05
- 13EU Publications Office CELEX 32024R2847, full text · verified 2026-09-05