@@ -834,7 +834,7 @@ Requirements that mitigate this threat: REQ-SSD, REQ-EMM, REQ-LOG
Mitigations for Likelihood:
* Medium to Low: REQ-SSD-02 (MI-SSCA), REQ-SSD-06 (MI-SCFS)
* High to Low: REQ-SSD-02 (MI-SSCA), (REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) or REQ-SSD-05 (MI-IMSL)), REQ-SSD-06 (MI-SCFS), REQ-EMM-02 (MI-NUTI-1), REQ-INT-05 (MI-NUTI-2)
* High to Low: REQ-SSD-02 (MI-SSCA), (REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN)), REQ-SSD-06 (MI-SCFS), REQ-EMM-02 (MI-NUTI-1), REQ-INT-05 (MI-NUTI-2)
Mitigations for Impact:
@@ -1388,7 +1388,7 @@ Table { seq tab }: Mapping of risks to requirements
@@ -18,9 +18,11 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
In alignment with the Cyber Resilience Act Annex I Part I (1), this section addresses overarching risks and mitigations regarding the secure design and development of the product that are not specifically treated by other categorical essential requirements (such as confidentiality, access control, or security updates). The requirements herein ensure the final product itself embodies security by design.
#### 5.2.1.2 Secure software design and development (MI-SSCA, MI-FZ95, MI-BTIN, MI-IMSL)
#### 5.2.1.2 Secure software design and development (MI-SSCA, MI-FZ95, MI-BTIN)
Use cases (as described in [clause 4.6](#use-cases) and [annex B](#annex-b-informative-security-analysis)) determine which of these controls should be utilized to mitigate threats around secure software design and development. In particular, across all use cases only one—at most—of the following three is called for when applied to a single product: REQ-SSD-03 (MI-FZ95), REQ-SSD-04 (MI-BTIN), REQ-SSD-05 (MI-IMSL). See B.TK for more information.
Use cases (as described in [clause 4.6](#use-cases) and [annex B](#annex-b-informative-security-analysis)) determine which of these controls should be utilized to mitigate threats around secure software design and development. In particular, across all use cases only one—at most—of the following two is called for when applied to a single product: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN). See B.TK for more information.
@@ -65,11 +67,11 @@ In addition to memory safety, compiled software is a potential target based on p
* UC-1: not required
* UC-2: not required
* UC-3: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) or REQ-SSD-05 (MI-IMSL) apply
* UC-4: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) or REQ-SSD-05 (MI-IMSL) apply
* UC-5: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) or REQ-SSD-05 (MI-IMSL) apply
* UC-6: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) or REQ-SSD-05 (MI-IMSL) apply
* UC-7: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) or REQ-SSD-05 (MI-IMSL) apply
* UC-3: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-4: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-5: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-6: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-7: REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
### 5.2.4 REQ-SSD-04 (MI-BTIN) Boundary testing of inputs that may cause memory errors
@@ -81,28 +83,11 @@ The product's technical documentation shall record any memory errors along with
* UC-1: not required
* UC-2: not required
* UC-3: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-05 (MI-IMSL) apply
* UC-4: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-05 (MI-IMSL) apply
* UC-5: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-05 (MI-IMSL) apply
* UC-6: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-05 (MI-IMSL) apply
* UC-7: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-05 (MI-IMSL) apply
### 5.2.5 REQ-SSD-05 (MI-IMSL) Implement in a memory-safe language
#### 5.2.5.1 Requirement
1.**REQ-SSD-05 (MI-IMSL)-1** The product shall employ implementation practices, tooling, or language features that mitigate memory corruption vulnerabilities, and
2.**REQ-SSD-05 (MI-IMSL)-2** any use of unsafe memory features in the product’s own code has corresponding evidence of both necessity and the specific mitigations applied to reduce residual risk.
#### 5.2.5.2 Applicability
* UC-1: not required
* UC-2: not required
* UC-3: REQ-SSD-05 (MI-IMSL) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-4: REQ-SSD-05 (MI-IMSL) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-5: REQ-SSD-05 (MI-IMSL) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-6: REQ-SSD-05 (MI-IMSL) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-7: REQ-SSD-05 (MI-IMSL) or REQ-SSD-03 (MI-FZ95) or REQ-SSD-04 (MI-BTIN) apply
* UC-3: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) apply
* UC-4: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) apply
* UC-5: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) apply
* UC-6: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) apply
* UC-7: REQ-SSD-04 (MI-BTIN) or REQ-SSD-03 (MI-FZ95) apply
### 6.2.5 REQ-SSD-05 (MI-IMSL) Implement in a memory-safe language
#### 6.2.5.1 Objective
Prevent unauthorized memory access.
#### 6.2.5.2 Preparation
None.
#### 6.2.5.3 Activities
Review source code to determine its language and what exceptions to memory safety exist
#### 6.2.5.4 Verdict
PASS if **all** of the following are fulfilled:
* The product employs implementation practices, tooling, or language features that mitigate memory corruption vulnerabilities, and
* each instance of unsafe memory features in the product’s own code or in dependencies has corresponding documentation demonstrating evidence of necessity, and that the applied mitigations reduce the residual cybersecurity risk to an acceptable level.