Standard

Available (1896)

Showing 1 - 12 per page



CRA SR M/606 PT3 Cybersecurity requirements for products with digital elements Part 1-3: Vulnerability handling

prEN 40000-1-3: Cybersecurity requirements for products with digital elements - Part 1-3: Vulnerability handling


These standards shall provide specifications applicable to vulnerability handling processes, covering all relevant product categories, to be put in place by manufacturers of the products with digital elements. Those processes shall at least allow to: (a) identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machinereadable format covering at the very least the top-level dependencies of the product; (b) in relation to the risks posed to the products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates; (c) apply effective and regular tests and reviews of the security of the product with digital elements; (d) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch; (e) put in place and enforce a policy on coordinated vulnerability disclosure; (f) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third party components contained in that product, including by providing a standardised contact address for the reporting of the vulnerabilities discovered in the product with digital elements; (g) provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner, and, where applicable for security updates, in an automatic manner; (h) ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.

CRA SR M/606 PT2 Cybersecurity requirements for products with digital elements - Generic security requirements

This document provides generic technical cybersecurity requirements for products with digital elements including their remote data processing solutions to fulfil the Essential Requirements of Annex I, Part I, (2)(a) through (2)(m) of the CRA. Where appropriate, multiple alternative requirements are provided that can be chosen from on a risk basis. The standard will include generic assessment criteria to support compliance of products with digital elements with the essential requirements of the CRA as listed above. Guidance will be provided to support the user of the standard in selecting the appropriate requirements to address the identified risks demonstrating the relation between cybersecurity threats and requirements. The EN 18031 series will be used as an input.

IEEE/IEC P63195-4 Assessment of Power Density of Human Exposure to Radio Frequency Fields Part 4

IEEE/IEC Draft International Standard - Assessment of Power Density of Human Exposure to Radio Frequency Fields from Wireless Devices in Close Proximity to the Head and Body (Frequency Range of 6 GHz to 300 GHz) Part 4: Computational Procedures for Absorbed Power Density

This document specifies computational procedures for conservative and reproducible computations of the absorbed power density (APD) or epithelial power density, which is a measure to quantify the dissipated electromagnetic power in the human head or body due to exposure to radiofrequency (RF) electromagnetic field (EMF) transmitting devices. The computational procedures described are finite-difference time-domain (FDTD) and finite element methods (FEM), which are used to determine electromagnetic quantities by solving Maxwell's equations. The procedures specified here apply to exposure evaluations for the significant majority of the population during the use of hand-held and body-worn RF transmitting devices with known uncertainty. The methods apply to devices with single or multiple transmitters or antennas that operate with their radiating structure(s) at distances up to 200 mm from the human head or body. This document can be employed to evaluate compliance with applicable APD limits of different types of RF transmitting wireless communication devices used in close proximity to the head and body, with or without RF transmitting or non-transmitting accessories, or of devices embedded in garments. The overall applicable frequency range of the specified protocols and procedures is from 6 GHz to 300 GHz. The categories of wireless communication devices covered in this document include mobile telephones, radio transmitters in personal computers, desktop and laptop devices, and multi-band and multi-antenna devices. The procedures of this document do not apply to APD evaluation of electromagnetic fields emitted or altered by devices or objects intended to be implanted in the body.

IEEE/IEC P63195-3 Assessment of Power Density of Human Exposure to Radio Frequency

IEEE/IEC Draft International Standard - Assessment of Power Density of Human Exposure to Radio Frequency Fields from Wireless Devices in Close Proximity to the Head and Body (Frequency Range of 6 GHz to 300 GHz) Part 3: Measurement Procedures for Absorbed Power Density

This document specifies protocols and test procedures for repeatable and reproducible measurements of the absorbed power density (APD) that provide conservative estimates of the exposure of the human head or body to radio-frequency (RF) electromagnetic fields (EMF) emitted by wireless communication devices, with a specified measurement uncertainty. These protocols and procedures apply to the evaluation of the exposure of the significant majority of the population during the use of hand-held and body-worn RF transmitting wireless communication devices. The methods apply to devices, with single or multiple transmitters or antennas, that operate with their radiating structure(s) at distances up to 200 mm from the human head or body. The methods of this document can be used to evaluate compliance with applicable APD limits of different types of RF transmitting wireless communication devices used in close proximity to the head and body, with or without RF transmitting or non-transmitting accessories, or of devices embedded in garments. The overall applicable frequency range of the specified protocols and procedures is from 6 GHz to 300 GHz. The categories of wireless communication devices covered in this document include mobile telephones, radio transmitters in personal computers, desktop and laptop devices, and multi-band and multi-antenna devices. The procedures of this document do not apply to APD evaluation of electromagnetic fields emitted or altered by devices or objects intended to be implanted in the body.

EUDI Wallet Held Assets Access Control, Operation and Management (prCEN/TS 18297)

This document specifies the functionality of the Wallet Unit for Access Control to Wallet Held Assets (WHAs) i.e. personal data relating to the Wallet User and stored in the Wallet Unit. It defines the Wallet Access Control decision Engine (WACE) and the corresponding functional requirements, resulting in recommendations to the user on decision to be made. This document aims at: 1) describing and specifying an Access Control Model supporting access control to the various possible operations on WHA(s); 2) providing the definitions and classification of the various types of data and metadata, and supporting access control to the various possible operations on WHA(s) ; 3) describing and specifying a W ACE controlling the access to the various possible operations on WHA(s) and the notification returned by the Wallet Access Control Decision Engine to a Wallet Unit; 4) identifying requirements applicable to the Wallet Access Control Decision Engine; This document also: 

  • identifies technical specifications and standards that can be used to support the concepts described herein;
  • specifies additional requirements for the use of the identified specifications to meet the above objectives; 
  • provides the missing technical specifications needed to meet the above objectives where needed; 
  • provides examples and use cases; The Access Control Model and Wallet Access Control Decision Engine defined in this document aim to comply with the regulator requirements regarding access control. 

    The following areas are out of the scope of this document: 1) content and encoding of the policies assigned for the disclosure of WHA(s), 2) implementation choice and encoding of Wallet Held Access Control Metadata; 3) encoding of electronic attestation(s) of attributes which are in the remit of ETSI/TC ESI.

ISO/WD TS 23258 Blockchain and distributed ledger technologies — Taxonomy and Ontology

This document specifies a taxonomy and an ontology for blockchain and distributed ledger technologies (DLT). The taxonomy includes a taxonomy of concepts, a taxonomy of DLT systems and a taxonomy of application domains, purposes and economy activity sections for use cases. The ontology includes classes and attributes as well as relations between concepts. The audience includes but is not limited to academics, architects, customers, users, tool developers, regulators, auditors and standards development organizations.

A working group has prepared a draft. Will replace ISO/TS 23258:2021

ISO 23257:2022 Blockchain and distributed ledger technologies — Reference architecture

This document specifies a reference architecture for Distributed Ledger Technology (DLT) systems including blockchain systems. The reference architecture addresses concepts, cross-cutting aspects, architectural considerations, and architecture views, including functional components, roles, activities, and their relationships for blockchain and DLT. Publication date 2022-02; International Standard to be revised.

ISO 22739:2024 Blockchain and distributed ledger technologies — Vocabulary

This document defines fundamental terminology for blockchain and distributed ledger technologies. Published in 01-2024; International Standard to be revised by ISO TC 307 WG1. 

Framework for Energy Efficiency Management (IETF -green-framework-02)

   Recognizing the urgent need for energy efficiency, this document   specifies a management framework focused on networks, devices and   device components within, or connected to, interconnected systems.   The framework aims to enable energy usage optimization, based on the   network condition while achieving the network's functional and   performance requirements (e.g., improving overall network   utilization) and also ensure interoperability across diverse systems.   Leveraging data from existing use cases, it delivers actionable   metrics to support effective energy management and informed decision-   making.  Furthermore, the framework defines mechanisms for   representing and organizing timestamped telemetry data using YANG   data models and metadata, enabling transparent and reliable   monitoring.  This structured approach facilitates improved energy   efficiency through consistent energy management practices.