cra-kit: correct Art. 14 reporting mechanics (SRP/CSIRT/EUVD) and remove deleted ROADMAP references - #603
cra-kit: correct Art. 14 reporting mechanics (SRP/CSIRT/EUVD) and remove deleted ROADMAP references#603sameehj wants to merge 2 commits into
Conversation
e811cee to
84026d1
Compare
Fix a systematic inaccuracy across the kit: Art. 14 reports are not sent "to ENISA" directly. They are filed via the ENISA Single Reporting Platform (SRP) to the CSIRT designated as coordinator, with ENISA notified simultaneously (Art. 14/16), and fixed vulnerabilities are published to the EUVD. - vulnerability-handling-process.md: add "how a report is filed" (SRP -> CSIRT + ENISA -> EUVD) section; add the severe-incident track (Art. 14(3), 1-month final report); reframe on-call from a staffing gap to follow-the-sun coverage plus a compliance commitment; update diagram, SLA table, and references. - Link the EU Authorised Representative appointment to the coordinator-CSIRT reporting end-point (Art. 14(7)) in eu-authorised-representative.md. - Correct "notify ENISA" / "24h ENISA reporting" wording in the shortlist, cheat sheet, glossary, slide outline, and SKILL.md. - Add SRP / CSIRT / EUVD glossary entries; tighten support-period wording to match Art. 13(2) (at least 5 years unless shorter expected lifetime). - Remove internal-correspondence detail from conformity-assessment-route.md. - Delete ROADMAP.md and remove all remaining references to it. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
84026d1 to
07efe62
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #603
No scan targets match the changed files in this PR. Review skipped.
Direction is right and I've landed it. The SRP/CSIRT correction is worth having Citations corrected. These were the substantive ones:
Two things that would have misled a reader. Art. 14(7) isn't a single AR rule. With no EU main establishment it's an ordered More important, ENISA's guidance says coordinator-CSIRT validation runs in One place the correction overshot. Art. 14(1) requires notification Nits: canonical SRP URL (yours 301-redirects), and the Added: Art. 69(3) and Art. 71(2) to the references. Worth having explicitly, What I pulled back out, and why. The status flip to a committed Art. 13/14 statement, and the on-call rewrite, are One specific thing to fix before that lands: the PR asserted that the Related and worth a follow-up regardless: §4 of that same live policy still says Separately, a decision that lands on your AR bullet: we're not appointing an |
MarkAtwood
left a comment
There was a problem hiding this comment.
Mechanics corrections are right and verified against the OJ text. Fixes pushed to the branch; status change deferred to its own PR as noted above.
3a073d8 to
07efe62
Compare
MarkAtwood
left a comment
There was a problem hiding this comment.
Sorry for the mess on your branch, that was my doing and you were right to call it. I have reset the branch back to your commit, so this is yours again and you can merge it once these are in.
The SRP/CSIRT direction is right and worth landing before Art. 14 applies on 11 September. Findings below are mostly one-click suggestions. The two that matter are the CVD policy claim and three article cites.
Numbers verified against the OJ text of Regulation (EU) 2024/2847 and the latest consolidated 2019/1020.
Downgrading to comments. None of these block the merge; the citation corrections and the CVD-policy wording will land in a follow-up PR so this can go out for the webinar. Suggestions remain inline for reference.
MarkAtwood
left a comment
There was a problem hiding this comment.
Approving to unblock the webinar. The SRP/CSIRT correction is the right direction and is a clear improvement on what is on master.
Inline suggestions above are not blockers and stay for reference. I will land them in a follow-up PR of my own rather than touching this branch: three article citations (EUVD is 17(5) not 16(2), severe-incident deadlines are 14(4)(c) not 14(3), support period is 13(8) not 13(2)), the Art. 14(7) four-step cascade, the SRP validation wording, and the ASCII box alignment.
One to carry into whatever PR re-raises the status change: the published CVD policy still commits only to acknowledging "as they come in", with no hour targets, so the sentence claiming the 24h/72h targets are reflected there needs the numbers published first or the claim dropped.
|
Merging with an admin override, and that is on me. I pushed commits to this branch earlier, which I should not have done on someone else's PR, then pushed again to reset it back to @sameehj's commit. Branch protection requires the last push to be approved by someone other than the pusher, so my own approval does not count and this cannot merge normally. Sorry for the churn. Rather than make Sameeh push again to work around my mistake, I am overriding. CI is green across all 200+ jobs and the commit is entirely his. The citation corrections and the CVD-policy wording are deferred to a follow-up PR of mine. They are not blockers and this should not wait on them. |
Review fixes for wolfSSL#603. Corrects the citations the previous commit got wrong, and takes the public compliance commitments back out so they can land as their own PR with sign-off. Citations: - ENISA is a co-addressee by statute, not a copy recipient. Art. 14(1) requires notification simultaneously to the coordinator CSIRT and to ENISA; Art. 14(7) directs the submission to the CSIRT end-point, "simultaneously accessible to ENISA". Drop the "not sent to ENISA directly" framing, which overcorrected. - Art. 14(7) sets a four-step cascade where there is no EU main establishment (authorised representative, importer, distributor, Member State with the most users), not a single AR rule. - EUVD publication is Art. 17(5), not Art. 16(2), and carries the "in agreement with the manufacturer" qualifier. The EUVD itself is established under NIS2 Art. 12(2). Corrected in the process doc, the glossary and the references list. - Severe-incident deadlines are in Art. 14(4), with the one-month final report at 14(4)(c). Art. 14(3) is the duty to notify. - Support period is Art. 13(8); Art. 13(2) is the risk-assessment duty. - SRP user validation runs in parallel with reporting and is not a prerequisite for fulfilling the reporting obligation, so it cannot gate a filing. ENISA's "Assigned Representative" is a platform user role, not the Art. 18 authorised representative. - Triage box content line was one column wider than its border. Commitments deferred: - Restore the vulnerability-handling status to the pending-approval state, in the document and in 00-INDEX.md. - Restore the on-call section. The published CVD policy carries no 24h acknowledgement and no 72h triage target, so the packet cannot cite it as the public source for either. Also corrects the remaining "24h ENISA" wording in the 00-INDEX.md timeline, which the previous commit missed. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> Co-authored-by: Cursor <cursoragent@cursor.com>
|
Thanks Mark — all eight suggestions applied in 9a26efb, plus the scope change you asked for. Applied as suggested
Scope, per your line-3 comment Four changes beyond your suggestions — please check these
Left alone, needs its own PR
|
Review fixes for wolfSSL#603. Corrects the citations the previous commit got wrong, and takes the public compliance commitments back out so they can land as their own PR with sign-off. Citations: - ENISA is a co-addressee by statute, not a copy recipient. Art. 14(1) requires notification simultaneously to the coordinator CSIRT and to ENISA; Art. 14(7) directs the submission to the CSIRT end-point, "simultaneously accessible to ENISA". Drop the "not sent to ENISA directly" framing, which overcorrected. - Art. 14(7) sets a four-step cascade where there is no EU main establishment (authorised representative, importer, distributor, Member State with the most users), not a single AR rule. - EUVD publication is Art. 17(5), not Art. 16(2), and carries the "in agreement with the manufacturer" qualifier. The EUVD itself is established under NIS2 Art. 12(2). Corrected in the process doc, the glossary and the references list. - Severe-incident deadlines are in Art. 14(4), with the one-month final report at 14(4)(c). Art. 14(3) is the duty to notify. - Support period is Art. 13(8); Art. 13(2) is the risk-assessment duty. - SRP user validation runs in parallel with reporting and is not a prerequisite for fulfilling the reporting obligation, so it cannot gate a filing. ENISA's "Assigned Representative" is a platform user role, not the Art. 18 authorised representative. - Triage box content line was one column wider than its border. Commitments deferred: - Restore the vulnerability-handling status to the pending-approval state, in the document and in 00-INDEX.md. - Restore the on-call section. The published CVD policy carries no 24h acknowledgement and no 72h triage target, so the packet cannot cite it as the public source for either. Also corrects the remaining "24h ENISA" wording in the 00-INDEX.md timeline, which the previous commit missed. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
9a26efb to
7668535
Compare
Summary
Follow-up to #574. Fixes a systematic inaccuracy in the CRA kit and cleans up references to
ROADMAP.md(removed in this PR).SKILL.md.vulnerability-handling-process.md: adds a "how a report is filed (SRP → CSIRT + ENISA → EUVD)" section; adds the severe-incident track (Art. 14(3), 1-month final report); reframes on-call from a staffing gap to wolfSSL's existing follow-the-sun coverage plus an explicit compliance commitment; updates the diagram, SLA table, and references.00-INDEX.mdis updated to match so the index and the document agree.SRP/CSIRT/EUVDentries; tightened support-period wording to match Art. 13(2).conformity-assessment-route.md: removes internal-correspondence detail from a customer-facing template.ROADMAP.mdand all remaining links/text references to it.Test plan
cra-kit/scripts/validate.shpasses (auditor packet validation OK)cbom-draft.cdx.jsonstill parses as valid JSONROADMAPreferences incra-kit/00-INDEX.mdstatus matchesvulnerability-handling-process.md