General session image of Knowledge Forum E

How the CRA Addresses the Tool Security Gap for Embedded Systems

Development tools as attack targets: the Tool Security Gap and how the CRA introduces new requirements.

Topic

Data security / DLP / Know-how protectionGovernance, Riskmanagement and ComplianceAI & Quantum SecurityIndustry 4.0 / IoT / Edge Computing

When & Where

calendar_month

Thu, 10/29/2026 12:00 PM - 12:30 PM

location_on

Forum E, Booth 9-105

Download session as iCaldownload_for_offline

Details

  • Format:

    it-sa insights

  • Language:

    German

Session description

Speaker: Oscar Slotosch

The first part of this presentation introduces the tool security gap.
Development tools are digital products, often software products, that are used to develop embedded systems but are not themselves part of the final product.
Tools have frequently served as the starting point for highly sophisticated and far-reaching cybersecurity attacks, including the xz backdoor incident, the SolarWinds attack, and the well-known Stuxnet attack.

Functional safety standards such as IEC 61508, ISO 26262, and DO-178 address development tools through concepts such as Tool Confidence and Tool Qualification. These standards require risk analysis ("classification"), risk reduction ("qualification"), and the treatment of residual risks through safety manuals tha ...