No. 74: Learnings from My First CRA Survival Bootcamps
I have run my first CRA Survival Bootcamps and learned a lot: manufacturers of white-labelled products, manual updates, opt-outs from automatic updates, taming the CVE flood with CVSS metrics and how to get the end date of the support period on the device or its packaging.
Read next
A Pragmatic Approach to CRA Risk Assessment
In less than 30 minutes, I can explain a pragmatic approach how to model the threats of an embedded system, assess the cybersecurity risks and document the risks in security decision records (SDRs). Here is the video from my talk at the Torizon CRA Summit in Munich.
How Can Manufacturers Address and Remediate 1000+ CVEs?
Fixing 1000+ CVEs one by one is too costly. Filtering them is arbitrary and might miss important ones. Making the exploitation of hundreds of CVEs unlikely by multiple security measures in one go is nothing else but defence in depth!