落入陷阱:《网络弹性法案》对开源软件意味着什么.pdf

编号:1011968 PDF 17页 1.02MB 下载积分:VIP专享
下载报告请您先登录!

落入陷阱:《网络弹性法案》对开源软件意味着什么.pdf

1、Christian WalterCaught in the NetWhat the Cyber Resilience Act Means for Open-Source SoftwareCaught in the NetWhat the Cyber Resilience Act Means for Open-Source SoftwareChristian Walter9elements,Managing Director FirmwareOpen-Source Firmware Foundation,FounderSecurity Track CRA=First EU-wide cybers

2、ecurity regulation for digital products Applies to both hardware and software Open-Source Software is explicitly pulled into scopeWhy This MattersThe European CRA sets mandatory Cybersecurity Requirements for Hardware and Software throughout the entire lifecycleKey GoalsImprove Security across the w

3、hole LifecycleSecure DevelopmentMore TransparencyEnforce Vulnerability HandlingApplies to all Products with Digital Elements(PDEs)sold in the EUWhat is the Cyber Resilience ActTimelineCRA ClassesOCP S.A.F.E.Default CategoryImportant Product“Class 1”Important Product“Class 2”Critical ProductCategoryI

4、ndustrial PLCSmartphoneEV ChargersRouters,modems intended for connection to the Internet(incl.switches)Smart home virtual assistantsInternet connected toysSmart lockWearablesPhysical and virtual network interfacesOperating SystemsHypervisors and container runtime systemsFirewalls,intrusion detection

5、 and/or prevention systemsTamper-resistant MCUs/MPUsSmart meter gatewaysSmartcards and similar devices(including Secure Elements)Hardware devices with security boxesExamplesSelf-assessmentHarmonised standards(ensuring CRA principles are met)3rd Party product assessment(product and/or process)Common

6、Criteria certification(by default)ConformanceManufacturesAnyone selling or integrating PDEsImporters/DistributorsIf you place on the EU marketWhat about Open-Source Software?Who needs to comply?Open-Source not exempt by defaultNon-commercial projects are not in scopeBut:Once used commercially in sco

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(落入陷阱:《网络弹性法案》对开源软件意味着什么.pdf)为本站 (明日何其多) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠