arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CYBERFORT:为中小企业落实《网络弹性法案》的合规链平台

CYBERFORT: A Compliance-Chain Platform Operationalising the Cyber Resilience Act for SMEs

Nikolaos Kekatos, Georgios Koutidis, Mihaela Curcă, Angelos Fountoulakis, Marios Ioannou, Michael Ioannou, Elias Iosif, Paul Lacatus, Alexios Lekidis, Avgi Michael, Tom Nianios

arXiv 2610.09918首次发表:更新:

发表机构

Clone Systems; Eximprod Engineering; Columbia Shipmanagement; Bolton Technologies; Dealio; I-EnergyLink; University of Thessaly; Elias Neocleous & Co. LLC(Clone Systems; Eximprod工程公司; 哥伦比亚船舶管理公司; 博尔顿科技公司; Dealio; I-EnergyLink; 色萨利大学; Elias Neocleous律师事务所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对中小企业缺乏GRC能力的问题,提出开源合规平台CYBERFORT,通过合规链将产品风险、控制措施与CRA义务关联,实现可追溯合规,并在43个组织及SIEM/XDR案例中验证。

AI 中文摘要

欧盟《网络弹性法案》(CRA)将产品网络安全转变为在欧盟市场上销售带有数字元素的产品的制造商、进口商、分销商和集成商的整个生命周期的合规义务,这一负担主要落在很少拥有专门的治理、风险和合规(GRC)能力的中小企业(SMEs)身上。我们提出了CYBERFORT,一个开源的、以CRA为优先的合规平台,在欧盟数字欧洲计划下开发,是欧盟CRA集群中的十二个项目之一。CYBERFORT通过引导式范围自我评估、与附件一和漏洞处理义务相关的题库,以及一个合规检查引擎来落实CRA,该引擎将每个答案与控制措施、政策和机器认证的证据联系起来,仅在ISO/IEC 27001、NIS2和GDPR的控制措施与CRA义务一致时才重用它们。其核心贡献是合规链,这是一个可追溯的结构,将每个产品风险通过其控制措施和政策与它所满足的CRA义务联系起来,并进一步通过证据连接到技术文档文件和欧盟符合性声明,从而使每个操作差距都是可追溯的,并可以在市场投放之前被关闭。该平台已在此https URL上部署,面向首批43个组织,并展示了该链背后的工程、针对一个具有AI驱动修复功能的SIEM/XDR产品的已完成端到端案例研究的测量结果(涵盖CRA义务章节),以及仍在进行中的受控工作量研究。

英文摘要

The EU Cyber Resilience Act (CRA) turns product cybersecurity into a lifecycle compliance obligation for manufacturers, importers, distributors, and integrators of products with digital elements on the EU market, a load that falls largely on small and medium-sized enterprises (SMEs) that rarely have dedicated governance, risk, and compliance (GRC) capacity. We present CYBERFORT, an open-source CRA-first compliance platform developed under the EU Digital Europe Programme and one of twelve projects in the EU CRA cluster. CYBERFORT operationalises the CRA through a guided scope self-assessment, a question bank tied to Annex I and the vulnerability-handling obligations, and a compliance-checking engine that links every answer to controls, policies, and machine-attested evidence, reusing ISO/IEC 27001, NIS2, and GDPR controls only where they coincide with CRA obligations. Its central contribution is the compliance chain, a traceable structure linking each product risk through its controls and policies to the CRA obligations it satisfies, and onward through evidence to the technical-documentation file and EU declaration of conformity, so that every operational gap is traceable and can be closed before market placement. Deployed at https://access.cyber-fort.eu/ for a first cohort of 43 organisations, the platform is presented with the engineering behind the chain, measured results from a completed end-to-end case study on a SIEM/XDR product with AI-driven remediation spanning the CRA obligation chapters, and the controlled effort study that remains in progress.

Comments7 pages, 3 figures, 2 tables. Accepted at the 2026 IEEE International Conference on Cyber Security and Resilience (IEEE CSR 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑