Brian Sims
Editor

EU Cyber Resilience Act “raises the bar” for security technology providers

GENETEC – THE enterprise physical security software specialist – has issued guidance to help physical security leaders assess how technology providers design, maintain and support connected products as the European Union’s (EU) Cyber Resilience Act raises cyber security expectations right across the product lifecycle.

The Cyber Resilience Act establishes cyber security requirements for products with digital elements sold in the EU. It places greater emphasis on secure product development, vulnerability management, cyber security transparency and ongoing product support throughout the product lifecycle.

While the legislation primarily applies to manufacturers, the regulation will also affect those organisations that distribute, install, procure and operate connected devices.

"The Cyber Resilience Act reinforces many of the Secure by Design and lifecycle management principles that Genetec has been advocating for years,” explained Mathieu Chevalier, principal security architect at Genetec. “By raising expectations for product security and transparency, the Cyber Resilience Act gives buyers a clear basis for evaluating technology providers and the long-term cyber resilience of their products.”

With the Cyber Resilience Act’s vulnerability reporting obligations coming into force on 11 September, organisations will increasingly rely on technology providers to meet new cyber security and vulnerability handling requirements.

In order to help evaluate vendor readiness, Genetec encourages organisations to ask prospective technology providers five key questions:

How long will the product receive security updates and support?

The Cyber Resilience Act reinforces the importance of maintaining product security throughout its lifecycle. Security leaders should understand how long the provider will deliver updates, how it will address vulnerabilities and what support it will offer when products reach end-of-life.

The Cyber Resilience Act regulations require manufacturers to provide security updates and vulnerability handling for at least five years, making long-term support an important consideration when evaluating products.

Was cyber security built into the product from the beginning?

The principles of Secured by Design and Secure by Default are central to the Cyber Resilience Act. Ask the provider to explain how it incorporates cyber security into product design, development, testing and the product’s ongoing lifecycle. 

How does the provider identify, disclose and address vulnerabilities?

No software is immune to vulnerabilities. How a provider responds is a strong indicator of its commitment to cyber security. Look for an established vulnerability management programme that includes regular security testing, a co-ordinated vulnerability disclosure policy, risk-based remediation without undue delay, the secure delivery of security updates and clear advisories about fixed vulnerabilities.

Is the provider transparent about its own cyber security practices?

Cyber security is a shared responsibility. Responsible providers explain how they develop, test and maintain their products and give customers and integrators clear guidance for secure deployment.

Ask how the provider regularly tests and reviews product security, communicates vulnerabilities and security updates and provides system-hardening guidance.

How will the provider support your long-term cyber resilience?

Product cyber security doesn’t end at installation. Working with trusted technology partners is critical. Organisations should evaluate how the provider determines and communicates the product’s support period, handles vulnerabilities, delivers security updates, supports secure operation and manages the product’s end of life.

They should also ask what evidence the provider can supply to demonstrate that the product meets applicable cyber security requirements throughout its lifecycle.

“Organisations best positioned to manage future cyber threats treat cyber security as an ongoing partnership, not a one-time procurement decision,” concluded Chevalier. “The Cyber Resilience Act helps to reinforce that approach by setting common expectations for transparency, disciplined vulnerability management and long-term product support, thereby benefiting manufacturers, integrators and those organisations that depend on connected physical security systems.”

*Further information about cyber security Best Practice for physical security systems is available online at www.genetec.com/trust-cybersecurity

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up