March Office Hours: Building Your CRA Vulnerability Management Plan TY Page
March Office Hours: Building Your CRA Vulnerability Management Plan
Transcript
00:00 Welcome and Agenda
01:01 What Is the CRA
01:45 Scope Fines and Classification
03:59 Key Dates and Core Duties
04:53 SBOM and Reporting Workflow
06:33 DefectDojo CRA Readiness
06:59 Locations Framework for SBOMs
08:32 Reporting Feature and End to End Flow
10:03 Getting Data In and Triage
11:22 Deduplication and Enrichment
14:16 Remediation SLAs and Verification
15:19 Practical Next Steps to Comply
17:28 New PSIRT Engine Preview
20:14 Q&A and Closing
Hi everyone. Happy Wednesday. Thanks for joining us today. My name is Greg Anderson. I'm the CEO and creator of DefectDojo.
And we've been getting a lot of questions around the CRA and so we wanted to put a webinar together to talk to the community about what it means in preparing this presentation. We have tried to look specifically at the letter of the law. There is a ton of blogs out around the CRA and so we wanted to make sure that everything we were pulling from was directly from the actual regulations and annexes that have been published.
What Is the CRA
And so, starting with what is the CRA? There's this new Cyber Resiliency Act in Europe and we've seen a ton of regulations in cybersecurity come and go. There have been some regulations in the past that people have been concerned about, and then they didn't turn into fruitful things that changed our industry. We believe that CRA will be different because it's heavily inspired by GDPR. GDPR is one of the most successful regulations in changing behavior. When it comes to the CRA, we expect to see similar impacts that happened with GDPR.
Scope Fines and Classification
The concern today is primarily in Europe. GDPR's notoriety drove the world to wake up to this regulation. Key takeaways about fines, penalties, and scope are that they are very similar to GDPR; they're meant to be scary and high to drive enforcement. This applies to any company doing business in Europe. Self-classification allows companies to decide how they report under this regulation.
Key Dates and Core Duties
Reporting obligations start this year, with full compliance required later. There will likely be widespread panic globally around enforcement starting December. Key duties include maintaining a comprehensive SBOM in specific formats and adhering to timelines for vulnerability management.
SBOM and Reporting Workflow
The regulation mandates specific formats such as Cyclone DX. Reporting obligations entail notifying authorities 24 hours after discovery and submitting a full report within 14 days following specific steps. Penalties for non-compliance are serious, comparable to GDPR enforceability.
DefectDojo CRA Readiness
DefectDojo is preparing for compliance, needing to implement key enhancements in SBO management. The locations framework is undergoing significant changes to provide a global view across all assets.
Locations Framework for SBOMs
The existing model of tracking vulnerable components is being replaced by a framework called locations, allowing a more comprehensive view of vulnerabilities across all assets.
Reporting Feature and End to End Flow
New reporting access management features are planned for implementation shortly.
Getting Data In and Triage
DefectDojo makes data import flexible. Various options are available for users to bring in data efficiently, such as API connectors, push options, and direct UI submissions.
Deduplication and Enrichment
The Dojo platform includes deduplication mechanisms to ensure accurate scan comparisons. Additionally, threat intel updates every 24 hours to inform users about vulnerabilities in the system.
Remediation SLAs and Verification
Custom SLAs should be created according to CRA regulations for asset management. Auto-remediation capabilities are being researched to enhance user experiences within the platform.
Practical Next Steps to Comply
Begin by inventorying products to establish compliance protocols around the CRA. Define SLAs that align with the requirements and continue monitoring compliance dashboards for progress.
New PSIRT Engine Preview
A new PSIRT engine is under development aimed at enhancing management tools for vulnerability insights from threat feeds. This feature is expected to improve the efficacy of security teams and provide better management for their risks.
Q&A Closing
I appreciate the time taken to engage with this content today and welcome any further questions regarding the platform or participation in our community.