Skip to main navigation Skip to search Skip to main content

A ThreatGet-Based Framework for Aligning System Security with the Cyber Resilience Act

    Research output: Chapter in Book or Conference ProceedingsConference Proceedings with Oral Presentationpeer-review

    Abstract

    The Cyber Resilience Act (CRA) is a recently published EU regulation that introduces guidelines to ensure the cybersecurity of digital components in Europe. It demands that manufacturers ensure the cybersecurity of products containing software and digital components. This represents a critical step toward advancing cybersecurity by enabling the integration of secure components throughout the system engineering lifecycle. As part of the AIMS5.0 project, we recognise the importance of the CRA in securing the future of digital components across Europe. Furthermore, we introduce a ThreatGet-based cybersecurity framework to facilitate alignment with the CRA. This paper presents the proposed framework, which integrates ThreatGet’s capabilities with the CRA’s key requirements and principles. While it does not aim to prove full compliance, it provides valuable support in guiding cybersecurity activities in the right direction. A smart indoor food production system is used as a case study to demonstrate the framework’s effectiveness and illustrate how ThreatGet can help ensure that cybersecurity activities within such systems’ lifecycle are consistent with the CRA context.
    Original languageEnglish
    Title of host publicationComputer Safety, Reliability, and Security. SAFECOMP 2025
    Subtitle of host publicationCoC3CPS, DECSoS, SASSUR, SENSEI, SRToITS, and WAISE, Stockholm, Sweden, September 9, 2025, Proceedings
    EditorsMartin Törngren, Elena Troubitsyna, Barbara Gallina, Erwin Schoitsch, Friedemann Bitsch
    Pages101-114
    Number of pages14
    Volume15955
    ISBN (Electronic)978-3-032-02018-5
    DOIs
    Publication statusPublished - 21 Aug 2025
    EventComputer Safety, Reliability, and Security. SAFECOMP 2025: 20th International Workshop on Dependable Smart Embedded Cyber-Physical Systems and Systems-of-Systems - Sweden, Stockholm, Sweden
    Duration: 9 Sept 202512 Sept 2025
    https://safecomp2025.se/

    Publication series

    Name Lecture Notes in Computer Science
    PublisherSpringer
    Volume15955
    ISSN (Print)0302-9743
    ISSN (Electronic)1611-3349

    Workshop

    WorkshopComputer Safety, Reliability, and Security. SAFECOMP 2025
    Abbreviated titleDECSoS 2025
    Country/TerritorySweden
    CityStockholm
    Period9/09/2512/09/25
    Internet address

    UN SDGs

    This output contributes to the following UN Sustainable Development Goals (SDGs)

    1. SDG 2 - Zero Hunger
      SDG 2 Zero Hunger

    Research Field

    • Dependable Systems Engineering

    Keywords

    • Cybersecurity
    • Cyber Resilience Act
    • IoT
    • Indoor Food Production

    Fingerprint

    Dive into the research topics of 'A ThreatGet-Based Framework for Aligning System Security with the Cyber Resilience Act'. Together they form a unique fingerprint.

    Cite this