A Mapping Analysis of Requirements Between the CRA and the GDPR

Publikation: Kapitel i bog/rapport/konference-proceedingKonferencebidrag i proceedingsForskningpeer review

4 Downloads (Pure)

Abstract

A new Cyber Resilience Act (CRA) was recently agreed upon in the European Union (EU). The paper examines and elaborates what new requirements the CRA entails by contrasting it with the older General Data Protection Regulation (GDPR). According to the results, there are overlaps in terms confidentiality, integrity, and availability guarantees, data minimization, traceability, data erasure, and security testing. The CRA’s seven new essential requirements originate from obligations to (1) ship products without known exploitable vulnerabilities and (2) with secure defaults, to (3) provide security patches typically for a minimum of five years, to (4) minimize attack surfaces, to (5) develop and enable exploitation mitigation techniques, to (6) establish a software bill of materials (SBOM), and to (7) improve vulnerability coordination, including a mandate to establish a coordinated vulnerability disclosure policy. With these results and an accompanying discussion, the paper contributes to requirements engineering research specialized into legal requirements, demonstrating how new laws may affect existing requirements.
OriginalsprogEngelsk
Titel2025 IEEE 33rd International Requirements Engineering Conference Workshops (REW)
ForlagIEEE
Publikationsdatosep. 2025
Sider215-222
ISBN (Elektronisk)979-8-3315-3834-7
DOI
StatusUdgivet - sep. 2025
Begivenhed2025 IEEE 33rd International Requirements Engineering Conference Workshops (REW) - Valencia, Spanien
Varighed: 1. sep. 20255. sep. 2025

Konference

Konference2025 IEEE 33rd International Requirements Engineering Conference Workshops (REW)
Land/OmrådeSpanien
ByValencia
Periode01/09/202505/09/2025
NavnProceedings - IEEE International Requirements Engineering Conference Workshops (REW)
ISSN2770-6826

Fingeraftryk

Dyk ned i forskningsemnerne om 'A Mapping Analysis of Requirements Between the CRA and the GDPR'. Sammen danner de et unikt fingeraftryk.

Citationsformater