CRA
Latest posts
Understanding the CVSS Metrics for Exploitability
Instead of fixing hundreds of CVEs, manufacturers can provide enough security measures to make the exploitation unlikely. The decrease of the CVSS metrics is a useful indicator how effective the security measures are. This post is about understanding the CVSS metrics.
Running Example for CRA: Heat Pumps in Private Homes
From now on, I'll use heat pumps in private homes as the running example for my CRA articles.
Real and Imagined Consequences of Substantial Modifications
WRONG: substantial modification => new placing on the market. Logical somersaults needed to avoid infinite support periods and full conformity assessment for all legacy products. --- RIGHT: substantial modification => update conformity assessment. No trickery needed.
Fundamental Definitions of the Cyber Resilience Act
The definitions for making available on the market, placing on the market, intended purpose and substantial modification are crucial for understanding the CRA. The CRA, Blue Guide and Commission guidance interpret them differently. I am trying to sort out this mess.
EU CRA: Essential Requirements Related to Vulnerability Handling
The eight requirements define how the manufacturer's process for vulnerability handling must look. They include identifying, addressing and publishing of vulnerabilities as well as timely security updates and generating an SBoM. The post gives practical examples how to do this.