An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ruohonen, Jukka, Kang, Eun-Young, Ramadan, Qusai
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914093035683840
author Ruohonen, Jukka
Kang, Eun-Young
Ramadan, Qusai
author_facet Ruohonen, Jukka
Kang, Eun-Young
Ramadan, Qusai
contents The paper presents an alignment evaluation between the mitigations present in the MITRE's ATT&CK framework and the essential cyber security requirements of the recently introduced Cyber Resilience Act (CRA) in the European Union. In overall, the two align well with each other. With respect to the CRA, there are notable gaps only in terms of data minimization, data erasure, and vulnerability coordination. In terms of the ATT&CK framework, gaps are present only in terms of threat intelligence, training, out-of-band communication channels, and residual risks. The evaluation presented contributes to narrowing of a common disparity between law and technical frameworks.
format Preprint
id arxiv_https___arxiv_org_abs_2505_13641
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations
Ruohonen, Jukka
Kang, Eun-Young
Ramadan, Qusai
Cryptography and Security
Software Engineering
The paper presents an alignment evaluation between the mitigations present in the MITRE's ATT&CK framework and the essential cyber security requirements of the recently introduced Cyber Resilience Act (CRA) in the European Union. In overall, the two align well with each other. With respect to the CRA, there are notable gaps only in terms of data minimization, data erasure, and vulnerability coordination. In terms of the ATT&CK framework, gaps are present only in terms of threat intelligence, training, out-of-band communication channels, and residual risks. The evaluation presented contributes to narrowing of a common disparity between law and technical frameworks.
title An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2505.13641