Back to engagement patterns
    Engagement pattern

    Governing security in the product organisation

    Where product security decisions are actually taken: the decision rights, the risk assessment they run on, and the conformity evidence they leave behind.

    Governance5 Sept 20265 min read

    IEC 62443-4-1:2018ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/SAE 21434:2021NIST CSWP 29Regulation (EU) 2024/2847UN Regulation No. 155 [2025/5]
    On this page

    Scope

    A product organisation ships what the law treats as regulated products: vehicles, industrial components, products with digital elements. Their duties fall on the manufacturer, not the corporate security function, so governance must reach the teams that build and release.

    One loop runs through it. Governance sets the decision rights: who signs a threat analysis and risk assessment, who accepts a residual product risk, who rules a change a substantial modification. Risk supplies the instrument — the product risk assessment, which paragraph 7.2.2.2 asks be kept current by a process 1. Compliance is what those decisions leave an authority to read.

    In scope: decision rights, the risk instrument, the supplier interface, the evidence trail.

    Out of scope: engineering method, the approval decision, and building the management system — the sibling pattern.

    Phases

    PhasePurposePlanning horizonCloses when
    1. Duty mapWhich instruments bind which line3–5 weeksEach line has a duty holder
    2. Decision rightsWho signs, accepts and escalates, at which gate4–8 weeksOne table carries all three
    3. InstrumentMake the risk assessment what decisions run on3–5 monthsEach decision cites a dated assessment
    4. Evidence and reviewWire conformity output into oversight6–10 weeksGovernance reads the authority's file
    Horizons are planning input, not elapsed time.

    Deliverables

    Paragraphs are UN Regulation No. 155 [2025/5] 2; articles are Regulation (EU) 2024/2847 3.

    DeliverableRequired byMaintained by
    Product security authority tableISO/SAE 21434:2021 clause 5.4.1Governance owner
    Product risk assessment, kept currentParagraph 7.3.3; Articles 13(2), 13(3)Product security owner
    Residual risk acceptance recordParagraph 7.2.2.2(c)The accepting role
    Cybersecurity caseClause 6.4.7 4Cybersecurity manager
    Supplier interface agreementParagraph 7.2.2.5; clause 7.4.3Procurement, engineering
    Modification decision recordParagraph 8.1; Article 22Change authority
    Technical documentation and conformity declarationArticles 13(4), 13(12), 13(13)Compliance owner

    Roles

    RoleSideAccountable for
    Executive sponsorOrganisationThe authority table and the review reading it
    Governance ownerOrganisationDecision rights, escalation, the calendar
    Product security ownerOrganisationThe risk assessment and its currency
    Change authorityOrganisationWhether a change re-opens approval or conformity
    SuppliersContracted third partiesTheir share of the assessment and agreed activities
    AdviserExternalMethod, the table's design, rehearsal

    What the auditor or authority asks

    Failure modes

    Frameworks

    InstrumentWhat it asks of governanceWhere it lands
    UN Regulation No. 155 [2025/5]Processes to manage, assess, categorise and treat product riskParagraph 7.2.2.2(a), (c)
    Regulation (EU) 2024/2847A current risk assessment inside the technical file; a conformity routeArticles 13(2)–13(4), 13(12)
    ISO/SAE 21434:2021Policy and responsibilities; an independent audit; project responsibilities; a supplier agreementClauses 5.4.1, 5.4.7, 6.4.1, 7.4.3 5
    IEC 62443-4-1:2018Eight practices: Security management; Specification of security requirements; Secure by design; Secure implementation; Security verification and validation testing; Management of security-related issues; Security update management; Security guidelinesPractices 1 to 8 6
    ISO/IEC 27001:2022, 27002:2022Authorities, operational control, security in projects and developmentClauses 5.3, 8.1 7; controls 5.8, 8.25, 8.27 8
    NIST CSF 2.0Supply chain risk, risk assessment and platform securityGV.SC, ID.RA, PR.PS 9
    What each instrument puts on governance.

    The boundary with the enterprise ISMS

    Clause 5.3 of ISO/IEC 27001:2022 is Organizational roles, responsibilities and authorities, where enterprise authority is written down. Control 5.8, Information security in project management, carries it into a project, asking for early and periodic risk assessment 10. The seam: the ISMS holds the corporate decision, the product programme the regulated one. No ISMS certificate discharges a product duty. Paragraph 7.3.1 asks for a valid certificate of compliance for the cyber security management system, covering the vehicle type approved 11. What the programme borrows is machinery: control ownership, the operating model, Product CSMS, CRA duties by class and IEC 62443 for governance people.

    References

    1. UNECE. UN Regulation No. 155 [2025/5]. OJ L, 2025/5, 10.1.2025 12.
    2. European Parliament and Council. Regulation (EU) 2024/2847. OJ L, 2024/2847, 20.11.2024 13.
    3. ISO and SAE International. ISO/SAE 21434:2021. https://www.iso.org/standard/70918.html. Clause numbers and titles from a licensed copy, 2026-09-05.
    4. IEC. IEC 62443-4-1:2018. https://webstore.iec.ch/en/publication/33615. Practice names from a licensed copy, 2026-09-05.
    5. ISO/IEC. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html. Control numbers and titles from a licensed copy, 2026-09-05. ISO/IEC 27001:2022 clause titles: ISO Online Browsing Platform.
    6. NIST. NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29. Category names from Appendix A.

    Sources

    1. 1EU Publications Office CELEX 42025X0005 para. 7.2.2.2 · verified 2026-09-05
    2. 2EU Publications Office CELEX 42025X0005 paras. 7.2.2.2, 7.2.2.5, 7.3.3 and 8.1 · verified 2026-09-05
    3. 3EU Publications Office CELEX 32024R2847 Art. 13(2) to 13(4), 13(12), 13(13) and 22 · verified 2026-09-05
    4. 4ISO/SAE 21434:2021 clause 6.4.7, licensed copy · verified 2026-09-05
    5. 5ISO/SAE 21434:2021 clauses 5.4.1, 5.4.7, 6.4.1 and 7.4.3, licensed copy · verified 2026-09-05
    6. 6IEC 62443-4-1:2018 practices 1 to 8, licensed copy · verified 2026-09-05
    7. 7ISO/IEC 27001:2022 clauses 5.3 and 8.1, iso.org/obp · verified 2026-09-03
    8. 8ISO/IEC 27002:2022 controls 5.8, 8.25 and 8.27, licensed copy · verified 2026-09-05
    9. 9NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-05
    10. 10ISO/IEC 27002:2022 control 5.8, licensed copy · verified 2026-09-05
    11. 11EU Publications Office CELEX 42025X0005 para. 7.3.1 · verified 2026-09-05
    12. 12EU Publications Office CELEX 42025X0005, full text · verified 2026-09-05
    13. 13EU Publications Office CELEX 32024R2847, full text · verified 2026-09-05