@@ -233,7 +233,6 @@ For the purposes of the present document, the following abbreviations apply:
<mark>Editor's Note: Please only keep the abbreviations that are used in the present document and avoid using the same abbreviation with different meaning in the CRA vertical standards.</mark>
`ACM Agreed Cryptographic Mechanisms`
`ADEF Authorization Required by Default`
`ADM Availability and Skill of Administration`
`API Application Programming Interface`
`AHHS Harm to Host System Via Unauthorized Access Through the Network`
@@ -241,8 +240,6 @@ For the purposes of the present document, the following abbreviations apply:
`AUTH Authentication`
`AVAI Availability`
`BTIN Boundary Testing of Inputs`
`CDST Confidentiality of Stored Data`
`CDTX Confidentiality of Transmitted Data`
`CEN Comité Européen de Normalisation`
`COM Complexity of Product Functions`
`CONF Configuration (Errors)`
@@ -251,99 +248,45 @@ For the purposes of the present document, the following abbreviations apply:
`CPU Central Processing Unit`
`CRA Cyber Resilience Act`
`CVE Common Vulnerabilities and Exposures`
`DCTX Detect Corruption of Transmitted Data`
`DCST Detect Corruption of Stored Data`
`DDOS Denial of Service (Attack)`
`DECT Digital Enhanced Cordless Telecommunications`
`DECT2020 NR Digital Enhanced Cordless Telecommunications New Radio Plus`
`DELE Secure Deletion Via Secure Delete Function`
`DJST Document and Justify Processed Data`
`DMIN Data Minimization`
`DOCC Documentation of Risk of Confiential Data Transfer`
`DOST Documentation of Risk Transfer to Operational Environment`
`DPAH Documentation of Product Assets Accessible from Host`
`ER Essential Security Requirement`
`FAIR Fair Resource Usage and Prioritization`
`FDRP Fast Packet Drop`
`FUN Sensitivity of Functions`
`IDST Integrity of Stored Data`
`IDTX Integrity of Transmitted Data`
`IMSL Implement in Memory Safe Language`
`INST Secure Deletion Via Reinstallation`
`INT Integration in Host System`
`IoT Internet of Things`
`ISP Internet Service Provider`
`IrDA Infrared Data Association`
`IT Information Technology`
`IXP Internet Exchange Point`
`JSTY Document and Justify Exposed Interfaces`
`KEV Known Exploitable Vulnerability`
`KEVU Known Exploitable Vulnerability`
`LIS Ease of Reading From Transmission Media of Directly Attached Network by Unauthorized Agents`
`LMAS Minimize Exposed Interfaces`
`LMEM Limited Memory Usage`
`LMII Limit Incident Impact`
`LOGG Logging and Monitoring`
`INI Operational environment of initial setup`
`MACsec Media Access Control Security`
`MDOC Document Transfer of Risk Minimizing Impact on Operational Environment`
`MI Mitigation`
`MINI Minimization of Impact on Other Devices`
`MPHY Preventing Attack at Physical Layer`
`MQSE Masquerading Authorized Server (Attack)`
`MSA Market Surveillance Authority`
`MSAF Memory Safety`
`MZRO Memory Stack Zeroing`
`NDDI Network Device Driver Interface`
`NET Degree of Public Access to Attached Network`
`NI Network Interface`
`NKEV No Known Exploitable Vulnerabilities`
`NTFY Watchdog and Notification of Host`
`OS Operating System`
`OT Operational Technology`
`PC Personal Computer`
`PCIe Peripheral Component Interconnect Express`
`PDDI Protect, Document, or Disable Interface`
`PDOS Denial of Service Attack on Product Functions`
`PHY Physical Layer`
`PHYS Acquistion of Physical Product`
`PII Personally Identifiable Information`
`PXE Preboot Execution Environment`
`RDPS Remote Data Processing Solution`
`ROM Read Only Memory`
`RSET Secure Deletion Via Reset`
`RTOS Real Time Operating System`
`SBOM Software Bill of Materials`
`SCAN No Easily Scannable Vulnerabilities`
`SCDL Secure Deletion`
`SCFS Secure Completion Flags`
`SCUD Secure Updates`
`SDEF Secure Default Configuration`
`SDS Sensitivity of Data Stored`
`SDRF Secure Data Read From Product`
`SDT Sensitivity of Data Transfered`
`SDTR Secure Data Read and Transfer`
`SFT Sensitivity of Data Stored`
`SSCA Static Source Code Analysis`
`SSDD Secure Design and Development`
`SUAP Automatic Secure Update Via Product`
`SUAO Automatic Secure Update Provided by Operational Environment`
`SUDC Documentation of Secure Update`
`SUOE Secure Update Provided by Operational Enivronment`
`SUVP Secure Update Via Product`
`SP Security Profile`
`SYS Impact of Access to Host System Assets`
`TH Threat`
`TV Television`
`UADT Unauthorised access to confidential data transmitted`
`UC Use Case`
`UEVU Unknown Exploitable Vulnerabilities`
`USB Universal Serial Bus`
`VI Virtual Interface`
`VNI Virtual Network Interface`
`VPN Virtual Private Network`
`VULH Vulnerability Handling`
`WD Wired Interface`
`WDOG Watchdog and Self-initiated Reset`
`WL Wireless Interface`
`WPA2 Wi-Fi Protected Access 2`
@@ -2123,7 +2066,7 @@ Fail otherwise.
# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 - the Cyber Resilience Act
# Annex A (informative): Relationship between the present document and the CRA
<mark>Editor's Note: Even if informative, this Annex is mandatory in Harmonised Standards.</mark>