[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
[
List Home]
|
Re: [open-regulatory-compliance] Stewards cybersecurity policy, should it be a public document?
|
For your 2. question, I am mostly wondering what attaches to the choice once a steward is deciding per requester who gets the (full) policy. Selective disclosure to a party invited to rely on the document looks less like publication and more like a representation to a counterparty. That applies even with no money changing hands; monetization of CRA attestation is only the sharper case. So I wonder whether discrimination there opens a liability door that publishing from the start simply does not and one the CRA's steward protections may not reach, being a contract rather than CRA liability.
Hi everyone,
Following up on a recent chat discussion, we are bringing a topic to the broader list regarding how Open Source Software Stewards plan to handle their Cyber Resilience Act (CRA) cybersecurity policies.
Core question - Are most stewards planning to publish their CRA cybersecurity policies publicly, or keep them internal until requested by a Market Surveillance Authority?
Key Perspectives & Insights
Regulatory Baseline: The CRA does not strictly require the entire cybersecurity policy to be public, only documented in a verifiable manner and available to an MSA upon reasoned request. However, community-facing elements (e.g., vulnerability disclosure procedures and reporting channels) must naturally be public.
Manufacturer Due Diligence: Publishing policies publicly could significantly streamline due diligence and risk assessments for downstream vendors embedding OSS components into commercial products.
Hybrid Approach: A practical middle ground discussed is keeping formal administrative policy internal while publicly documenting its practical execution (e.g., secure development practices, security support structures, and reporting protocols).
Resources
Discussion questions for the mailing list and the next meeting on Tuesday
What approach is your organisation or project planning to take?
Do you see public availability as essential for vendor trust, or does public documentation of security procedures suffice?
Looking forward to hearing your thoughts and experiences.
Juan
-- Juan Rico
Eclipse Foundation: The Community for Open Collaboration and Innovation
Berliner Allee 47, 64295 Darmstadt
Handelsregister: Darmstadt HRB 92821
Managing Directors: Gaël Blondelle, Mike Milinkovich, Michael Plagge
_______________________________________________
open-regulatory-compliance mailing list
open-regulatory-compliance@xxxxxxxxxxx
To unsubscribe from this list, visit https://accounts.eclipse.org
--