Commit 7017716e authored by Giulio Di Clemente's avatar Giulio Di Clemente
Browse files

Edit EN-304-624.md Table A.1 first update

parent a8f85404
Loading
Loading
Loading
Loading
+4 −3
Original line number Diff line number Diff line
@@ -2080,9 +2080,10 @@ Once the present document is cited in the Official Journal of the European Union
</div>


|No |Description|Clause(s) of the present document	| 
|---|---|---|
|(1)| identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products;| 6.1				
|No |Description |Requirements of Regulation |Clause(s) of the present document |U/C |Condition | 
|---|---|---|---|---|
|(1)| Annex I, Part 1, (1)|“Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.” | Clause 5 | C | 	See mapping table on the applicability of the technical cybersecurity requirements in clause 5.1
			
|(2)| in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates;		| 6.1		
|(3)|	Apply effective and regular tests and reviews of the security of the product with digital elements;	| 6.1				
|(4)|	Donce a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch;	| 6.1