用户信息和说明
CRA user information 是随产品提供的资料,帮助用户安全安装、运行、更新、报告漏洞并退役产品。它面向用户、集成方、所有者和运营者,而不只是 manufacturer 的内部文件。
面向用户的信息
Manufacturers shall ensure that products with digital elements are accompanied by the information and instructions to the user set out in Annex II, in paper or electronic form. Such information and instructions shall be provided in a language which can be easily understood by users and market surveillance authorities. They shall be clear, understandable, intelligible and legible. They shall allow for the secure installation, operation and use of products with digital elements. Manufacturers shall keep the information and instructions to the user set out in Annex II at the disposal of users and market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. Where such information and instructions are provided online, manufacturers shall ensure that they are accessible, user-friendly and available online for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.
Regulation (EU) 2024/2847, Article 13(18)
信息可以用纸质或电子形式提供。语言必须让用户和 market surveillance authorities 易于理解。如果在线提供,信息必须在规定期间内保持可访问且易用。
面向用户的资料
说明用户需要的安全使用、support、更新、联系路径和风险信息。
证据文件的一部分
Annex VII 也把 Annex II 用户信息放入 technical documentation。
Annex II 内容
Annex II 是最低内容清单。它结合产品身份、support 信息、安全使用说明和漏洞联系信息。
Annex II 要求 manufacturer 名称、联系方式、可用时的网站,以及足以唯一识别产品的产品信息。
用户必须知道如何报告和接收漏洞信息,以及如何找到 coordinated vulnerability disclosure policy。
信息必须说明 intended purpose、安全环境、essential functions、安全属性,以及任何可能导致重大网络安全风险的已知或可预见情形。
Annex II 要求说明技术安全支持类型和 support-period end date。它也要求说明如何安装 security-relevant updates。
Annex II 要求安全 commissioning、整个生命周期内的安全使用、安全退役、数据删除、自动更新设置,以及产品拟集成到另一产品时所需的集成信息。
安全使用说明
CRA 要求的不是通用安全建议。说明应匹配产品、intended purpose、foreseeable use,以及会安装或运行产品的用户。
Annex II point 8 是清单中最实用的部分。它要求提供说明,或指向说明的链接,内容包括:
- 初始 commissioning 和整个产品生命周期内所需措施;
- 产品变更如何影响数据安全;
- security-relevant updates 如何安装;
- 安全退役和安全删除用户数据;
- 默认启用自动安全更新时,如何关闭该设置;
- 其他 manufacturer 或集成方需要的集成信息。
清楚说明不能替代设计
User information 可以解释假设和剩余风险,但不能用来放弃处理产品安全要求。
购买时的 support 日期
Article 13(19) 要求 support-period end date 在购买时清楚可见。日期至少必须包括月份和年份。如果技术上可行,产品到达 end of support 时也必须通知用户。
购买时
用户应在依赖产品之前看到 support end date。
使用期间
用户需要与产品实际更新方法匹配的更新说明。
技术文件边界
User information 和 technical documentation 面向不同读者。User information 用于安全使用。Technical documentation 是用于证明 CRA 符合性的证据文件。
Annex VII 将 Annex II user information 纳入 technical documentation,但它还要求内部证据,例如设计信息、架构、vulnerability-handling 流程信息、cybersecurity risk assessment、support-period 理由、使用的标准和测试报告。