漏洞处理记录

Vulnerability handling records 说明 manufacturer 如何在 support period 内发现、记录、评估、修复、披露和沟通漏洞。

流程义务

Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.

Regulation (EU) 2024/2847, Article 13(8)

义务在产品 placed on the market 时开始,并在 support period 内继续。它覆盖产品及其组件。

主要记录类型

Annex VII 连接

Annex VII 要求 technical documentation 包含 vulnerability-handling 流程所需信息和规范,包括 SBOM、coordinated vulnerability disclosure policy、报告联系地址和安全更新分发。

  • 支撑产品漏洞历史的记录;
  • 解释漏洞如何分诊和修复的记录;
  • 显示更新分发和用户沟通的记录;
  • 支撑 conformity assessment 的测试和评审报告。

草案 prEN 40000-1-3 页面更详细说明当前 vulnerability-handling 标准草案。

记录不是报告触发条件

这些记录支撑 vulnerability handling。Article 14 reporting 是单独义务,由 actively exploited vulnerabilities 和 severe product-security incidents 触发。

Sources