漏洞处理记录
Vulnerability handling records 说明 manufacturer 如何在 support period 内发现、记录、评估、修复、披露和沟通漏洞。
流程义务
Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.
Regulation (EU) 2024/2847, Article 13(8)
义务在产品 placed on the market 时开始,并在 support period 内继续。它覆盖产品及其组件。
主要记录类型
Annex I 要求 manufacturer 识别和记录漏洞及组件,包括覆盖至少 top-level dependencies 的 SBOM。
记录应说明漏洞如何被评估、处理、修复,并在需要时通过安全更新分发。
Annex I 要求 coordinated vulnerability disclosure policy。Annex VII 要求该 policy,以及接收漏洞报告联系地址的证据。
Annex I 要求对产品安全进行有效、定期的测试和评审。Annex VII 要求纳入用于验证产品和流程符合性的测试报告。
Annex VII 连接
Annex VII 要求 technical documentation 包含 vulnerability-handling 流程所需信息和规范,包括 SBOM、coordinated vulnerability disclosure policy、报告联系地址和安全更新分发。
- 支撑产品漏洞历史的记录;
- 解释漏洞如何分诊和修复的记录;
- 显示更新分发和用户沟通的记录;
- 支撑 conformity assessment 的测试和评审报告。
草案 prEN 40000-1-3 页面更详细说明当前 vulnerability-handling 标准草案。
记录不是报告触发条件
这些记录支撑 vulnerability handling。Article 14 reporting 是单独义务,由 actively exploited vulnerabilities 和 severe product-security incidents 触发。