An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations
Fuente:
arXiv
Saved in:
| Main Authors: | , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866914093035683840 |
|---|---|
| author | Ruohonen, Jukka Kang, Eun-Young Ramadan, Qusai |
| author_facet | Ruohonen, Jukka Kang, Eun-Young Ramadan, Qusai |
| contents | The paper presents an alignment evaluation between the mitigations present in the MITRE's ATT&CK framework and the essential cyber security requirements of the recently introduced Cyber Resilience Act (CRA) in the European Union. In overall, the two align well with each other. With respect to the CRA, there are notable gaps only in terms of data minimization, data erasure, and vulnerability coordination. In terms of the ATT&CK framework, gaps are present only in terms of threat intelligence, training, out-of-band communication channels, and residual risks. The evaluation presented contributes to narrowing of a common disparity between law and technical frameworks. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2505_13641 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations Ruohonen, Jukka Kang, Eun-Young Ramadan, Qusai Cryptography and Security Software Engineering The paper presents an alignment evaluation between the mitigations present in the MITRE's ATT&CK framework and the essential cyber security requirements of the recently introduced Cyber Resilience Act (CRA) in the European Union. In overall, the two align well with each other. With respect to the CRA, there are notable gaps only in terms of data minimization, data erasure, and vulnerability coordination. In terms of the ATT&CK framework, gaps are present only in terms of threat intelligence, training, out-of-band communication channels, and residual risks. The evaluation presented contributes to narrowing of a common disparity between law and technical frameworks. |
| title | An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2505.13641 |