CRA Vulnerability Handling Policy

Home > CRA Vulnerability Handling Policy

Potential vulnerabilities affecting products delivered by Aisa can be reported to


To comply with cybersecurity best practices (Cyber Resilience Act – CRA), Aisa has established the vulnerability handling policy described below.
This policy applies, in particular, when:

  • an external party reports a potential vulnerability affecting a product provided by Aisa;
  • a vulnerability affecting a product provided by Aisa is disclosed publicly;
  • a vulnerability affecting a product provided by Aisa is identified internally.

How to report a vulnerability?

A vulnerability, when exploited, could negatively affect confidentiality, integrity, availability or safety of equipment provided by Aisa or its production environment.

Weaknesses resulting solely from the individual configuration of a customer installation, in the customer network, or from compromised access credentials, are not considered vulnerabilities under this policy, although Aisa may still respond to reports concerning such events.
Anyone who discovers a potential vulnerability affecting a product delivered by Aisa is encouraged to report it directly to Aisa at .

Where possible, the report should include:

  • the affected Aisa product with its serial number;
  • a description of the vulnerability and its potential impact;
  • relevant evidence or proof of concept;
  • whether the vulnerability has already been disclosed;
  • whether the reporter is willing to coordinate disclosure with Aisa.

Vulnerability handling

The vulnerability handling policy from Aisa consists of four main phases. Communication with relevant reporting entities, coordinating organizations and third parties takes place throughout the process.

  1. 1. Receipt
  2. 2. Verification
  3. 3. Remediation
  4. 4. Release

1. Receipt

Requirements
Acknowledge the reception of the report, establish communication with the reporting entity, open case ID.

Deliverables

  • Acknowledgement of reception of the report
  • Case ID for the reported vulnerability

2. Verification

Requirements
Assess the completeness of the reporting, check the validity, reproducibility and applicability of the vulnerability in the product context, assess the potential product impact of the reported vulnerability, determine whether third-party coordination is required.

Deliverables

  • Initial vulnerability record and evaluation in the product context.
  • Evidence or test cases confirming the vulnerability.
  • Risk assessment and product impact.
  • Status information for relevant parties.

3. Remediation

Requirements
Develop and validate appropriate remediation and/or mitigation, while reassessing severity as new information becomes available.

Deliverables

  • Validated remediation, where applicable.
  • Validated mitigations or risk-reduction recommendations, where applicable.
  • Status information for relevant parties.

4. Release

Requirements
Prepare security patching, communicate appropriate security information and close the vulnerability handling process.

Deliverables

  • Security patch and/or mitigation instructions, where applicable.
  • A security advisory or other customer notification.
  • Final communication to relevant parties.