
How the CRA Addresses the Tool Security Gap for Embedded Systems
Development tools as attack targets: the Tool Security Gap and how the CRA introduces new requirements.
Topic
When & Where
Details
Format:
it-sa insights
Language:
German
Session description
Speaker: Oscar Slotosch
The first part of this presentation introduces the tool security gap.
Development tools are digital products, often software products, that are used to develop embedded systems but are not themselves part of the final product.
Tools have frequently served as the starting point for highly sophisticated and far-reaching cybersecurity attacks, including the xz backdoor incident, the SolarWinds attack, and the well-known Stuxnet attack.
Functional safety standards such as IEC 61508, ISO 26262, and DO-178 address development tools through concepts such as Tool Confidence and Tool Qualification. These standards require risk analysis ("classification"), risk reduction ("qualification"), and the treatment of residual risks through safety manuals tha ...


