2024-05-05 Version 2.3.3
Simple Search | Advanced Search | Pre-Defined Reports | Help

Details of 'DTR/CYBER-0094' Work Item
Work Item Reference ETSI Doc.
Number
STF Technical Body
in Charge
Download Standard

Download standrd ref:
DTR/CYBER-0094 (PDF Format) Download standrd ref:
DTR/CYBER-0094 (Word Format)
  DTR/CYBER-0094 TR 103 935   CYBER
  Current Status
(Click to View Full Schedule)
Latest
Version
Cover Date Standstill Creation Date
  Publication (2023-12-04) 1.1.1 2023-12-04 View Standstill Information 2022-09-20
  Rapporteur Technical Officer Harmonised Standard
  Meinhard Bohlen Laure Pourcin No
 
Title Cyber Security (CYBER); Assessment of cyber risk based on products’ properties to support market placement
Assessment of cyber risk based on products’ properties to support market placement 
Scope and Field
of Application
Industry sectors have addressed the assessment of cyber risks, particularly as regards software, in a largely silo manner. On the other hand, recently introduced – and even upcoming – legislation mandates a horizontal treatment of cyber risks that spans multiple industry sectors. And where such legislation holds for the placement of products and services in the EU Single Market, stringent requirements apply. Given that risk assessment is predominantly informed by the context in which products and services operate, the (re)use of sectorial risk assessments (e.g. consumer, industrial, medical, etc.) in the development of technical standards supportive to such horizontal legislations has been a complex and arduous exercise. Particularly so when it comes to subjective factors – inherent in any risk assessment – that should be kept under control. Currently, this is largely an open issue for the industry. Hence there is a need for an “adapter” concept (e.g. an approach, method, guidance, practice, or other suitable formalism) that facilitates reuse of the investment made by different industry sectors in the assessment of risk, while providing a uniform “interface” fit for the conformance assessment requirements and other legal concerns of such horizontal legislations. Such a unified “adapter” is currently lacking. This WI shall address this gap and analyse the areas where subjective factors play a role (and thus should be handled diligently) in this context. Moreover, it shall introduce the challenges that accompany the assessment of software-related risks in the context of market placement and present essential principles to inform the risk assessment of products based on their properties. Finally, a method to constrain and control subjectivity based on these principles and developed to address the challenges of said risk assessments shall be presented. 
Supporting
Organizations
HAGER GROUP, A.S.P., Schneider Electric Industries, HUAWEI TECH. GmbH, LEGRAND FRANCE 

 

Keywords Projects Clusters Frequencies Mandates Directives
  market placement
risk assessment
  Security
     
Official Journal
     
Remarks
2023-11-06 pourcinl TB approval proposal in contribution CYBER(23)35a019 was Accepted by CYBER (see RC CYBER(23)DEC138)
2023-10-23 pourcinl Draft contributed - V 1.0.1 contributed for Decision in CYBER(23)35a019 as Final draft for approval
2023-10-23 pourcinl A new draft is uploaded - V 1.0.1 with status: Final draft for approval
2023-10-13 gazis Draft contributed - V 1.0.0 contributed for Decision in CYBER(23)035005r3 as Final draft for approval
2023-10-13 gazis Final draft for approval proposal in contribution CYBER(23)035005r2 was Revised by CYBER
2023-10-13 gazis Draft contributed - V 1.0.0 contributed for Decision in CYBER(23)035005r2 as Final draft for approval
2023-10-13 gazis Final draft for approval proposal in contribution CYBER(23)035005r1 was Revised by CYBER
2023-10-12 gazis Draft contributed - V 1.0.0 contributed for Decision in CYBER(23)035005r1 as Final draft for approval
2023-10-06 pourcinl Final draft for approval proposal in contribution CYBER(23)035005 was Noted by CYBER
2023-09-05 gazis Draft contributed - V 1.0.0 contributed for Decision in CYBER(23)035005 as Final draft for approval
2023-09-05 gazis A new draft is uploaded - V 1.0.0 with status: Final draft for approval
2023-05-15 pourcinl Draft contributed - V 0.1.0 contributed for Discussion in CYBER(23)034016 as Stable draft
2023-05-09 gazis Draft contributed - V 0.1.0 contributed for Discussion in CYBER(23)034009 as Stable draft
2023-05-09 gazis A new draft is uploaded - V 0.1.0 with status: Stable draft - with comment: Stable draft version where no changes to chapters are further expected. Minor changes within chapters and editorial corrections are still expected.
2022-09-28 bohlen TB adoption of WI CYBER, see contribution CYBER(22)031016
2022-09-20 bohlen WI proposed to TB CYBER, see contribution CYBER(22)031016
 

Specific aspects
  User/consumer aspects
  Security/Privacy aspects
Displaying Item 8 of 61...

ETSI Home Page Any comments or problems with this application? Please let us know...