CRA 必需要求与 ATT&CK 缓解措施的对齐
密码学与安全
2025-10-16 v2 软件工程
摘要
本文呈现了将MITRE ATT&CK 框架中的缓解措施与欧盟新近制定的《网络韧性法案》(CRA)的基本网络安全要求进行对齐评估的结果。总体而言,两者基本一致。就CRA而言,仅在数据最小化、数据擦除和漏洞协调方面存在显著差距。就ATT&CK框架而言,仅在威胁情报、培训、带外通信渠道和残余风险方面存在差距。本次评估有助于缩小法律框架与技术框架之间的常见差异。
引用
@article{arxiv.2505.13641,
title = {An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations},
author = {Jukka Ruohonen and Eun-Young Kang and Qusai Ramadan},
journal= {arXiv preprint arXiv:2505.13641},
year = {2025}
}
备注
Proceedings of the IEEE 33rd International Requirements Engineering Conference Workshops (REW 2025), Valencia, IEEE, 2025, pp. 209-214