cra-kit: correct Art. 14 reporting mechanics (SRP/CSIRT/EUVD) and remove deleted ROADMAP references - #603
cra-kit: correct Art. 14 reporting mechanics (SRP/CSIRT/EUVD) and remove deleted ROADMAP references#603sameehj wants to merge 1 commit into
Conversation
e811cee to
84026d1
Compare
Fix a systematic inaccuracy across the kit: Art. 14 reports are not sent "to ENISA" directly. They are filed via the ENISA Single Reporting Platform (SRP) to the CSIRT designated as coordinator, with ENISA notified simultaneously (Art. 14/16), and fixed vulnerabilities are published to the EUVD. - vulnerability-handling-process.md: add "how a report is filed" (SRP -> CSIRT + ENISA -> EUVD) section; add the severe-incident track (Art. 14(3), 1-month final report); reframe on-call from a staffing gap to follow-the-sun coverage plus a compliance commitment; update diagram, SLA table, and references. - Link the EU Authorised Representative appointment to the coordinator-CSIRT reporting end-point (Art. 14(7)) in eu-authorised-representative.md. - Correct "notify ENISA" / "24h ENISA reporting" wording in the shortlist, cheat sheet, glossary, slide outline, and SKILL.md. - Add SRP / CSIRT / EUVD glossary entries; tighten support-period wording to match Art. 13(2) (at least 5 years unless shorter expected lifetime). - Remove internal-correspondence detail from conformity-assessment-route.md. - Delete ROADMAP.md and remove all remaining references to it. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
84026d1 to
07efe62
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #603
No scan targets match the changed files in this PR. Review skipped.
Direction is right and I've landed it. The SRP/CSIRT correction is worth having Citations corrected. These were the substantive ones:
Two things that would have misled a reader. Art. 14(7) isn't a single AR rule. With no EU main establishment it's an ordered More important, ENISA's guidance says coordinator-CSIRT validation runs in One place the correction overshot. Art. 14(1) requires notification Nits: canonical SRP URL (yours 301-redirects), and the Added: Art. 69(3) and Art. 71(2) to the references. Worth having explicitly, What I pulled back out, and why. The status flip to a committed Art. 13/14 statement, and the on-call rewrite, are One specific thing to fix before that lands: the PR asserted that the Related and worth a follow-up regardless: §4 of that same live policy still says Separately, a decision that lands on your AR bullet: we're not appointing an |
MarkAtwood
left a comment
There was a problem hiding this comment.
Mechanics corrections are right and verified against the OJ text. Fixes pushed to the branch; status change deferred to its own PR as noted above.
3a073d8 to
07efe62
Compare
MarkAtwood
left a comment
There was a problem hiding this comment.
Sorry for the mess on your branch, that was my doing and you were right to call it. I have reset the branch back to your commit, so this is yours again and you can merge it once these are in.
The SRP/CSIRT direction is right and worth landing before Art. 14 applies on 11 September. Findings below are mostly one-click suggestions. The two that matter are the CVD policy claim and three article cites.
Numbers verified against the OJ text of Regulation (EU) 2024/2847 and the latest consolidated 2019/1020.
Downgrading to comments. None of these block the merge; the citation corrections and the CVD-policy wording will land in a follow-up PR so this can go out for the webinar. Suggestions remain inline for reference.
MarkAtwood
left a comment
There was a problem hiding this comment.
Approving to unblock the webinar. The SRP/CSIRT correction is the right direction and is a clear improvement on what is on master.
Inline suggestions above are not blockers and stay for reference. I will land them in a follow-up PR of my own rather than touching this branch: three article citations (EUVD is 17(5) not 16(2), severe-incident deadlines are 14(4)(c) not 14(3), support period is 13(8) not 13(2)), the Art. 14(7) four-step cascade, the SRP validation wording, and the ASCII box alignment.
One to carry into whatever PR re-raises the status change: the published CVD policy still commits only to acknowledging "as they come in", with no hour targets, so the sentence claiming the 24h/72h targets are reflected there needs the numbers published first or the claim dropped.
|
Merging with an admin override, and that is on me. I pushed commits to this branch earlier, which I should not have done on someone else's PR, then pushed again to reset it back to @sameehj's commit. Branch protection requires the last push to be approved by someone other than the pusher, so my own approval does not count and this cannot merge normally. Sorry for the churn. Rather than make Sameeh push again to work around my mistake, I am overriding. CI is green across all 200+ jobs and the commit is entirely his. The citation corrections and the CVD-policy wording are deferred to a follow-up PR of mine. They are not blockers and this should not wait on them. |
Summary
Follow-up to #574. Fixes a systematic inaccuracy in the CRA kit and cleans up references to
ROADMAP.md(removed in this PR).SKILL.md.vulnerability-handling-process.md: adds a "how a report is filed (SRP → CSIRT + ENISA → EUVD)" section; adds the severe-incident track (Art. 14(3), 1-month final report); reframes on-call from a staffing gap to wolfSSL's existing follow-the-sun coverage plus an explicit compliance commitment; updates the diagram, SLA table, and references.00-INDEX.mdis updated to match so the index and the document agree.SRP/CSIRT/EUVDentries; tightened support-period wording to match Art. 13(2).conformity-assessment-route.md: removes internal-correspondence detail from a customer-facing template.ROADMAP.mdand all remaining links/text references to it.Test plan
cra-kit/scripts/validate.shpasses (auditor packet validation OK)cbom-draft.cdx.jsonstill parses as valid JSONROADMAPreferences incra-kit/00-INDEX.mdstatus matchesvulnerability-handling-process.md