ISO/IEC 30111 漏洞處理流程

收到漏洞通報只是開始——驗證、分級、修補、部署的內部流水線,才是 CRA 真正在稽核的東西。

Book a Free Risk Diagnosis

ISO/IEC 30111:2019 規範廠商收到漏洞資訊後的內部處理流程:通報驗證與重現、嚴重度分級、根因分析、修補開發與測試、部署與後續監控。它與 ISO/IEC 29147(揭露)成對:29147 是對外介面、30111 是內部引擎。在 EU CRA 的官方標準對映(JRC 與 ENISA 聯合報告)中,EN ISO/IEC 30111 是漏洞處理類要求覆蓋度最高的單一標準——八項要求中對應五項。CRA 要求製造商「無不當延遲」修補漏洞、免費提供安全更新、維護 SBOM 以支持漏洞管理,並對支援期內的產品持續履行義務——這意味著漏洞處理不是事件式的救火,而是要在組織內常設、可稽核的流程。

CRA 漏洞處理八要求與 30111 的覆蓋

CRA 附件一第二部分列出漏洞識別與文件化(含 SBOM)、無延遲修補、定期測試、揭露政策、資訊分享、安全更新機制等八項。依官方對映,30111 直接覆蓋其中五項,搭配 29147 再補四項(部分重疊)——兩標準成對導入即覆蓋絕大多數條文,剩餘缺口以程序文件補齊。

與 SBOM/安全更新的銜接

30111 的修補流程必須接上兩個 CRA 硬要求:SBOM(知道產品裡有什麼,才知道哪個元件的漏洞與你有關)與安全更新交付機制(修了要能送到用戶手上)。積穗科研自身交付管線即每日產製、簽章並監測 SBOM——這套機制是輔導內容的活教材。

導入的組織設計

核心是把「誰收單、誰驗證、誰定級、誰修、誰發布、多快」寫成可稽核的流程與 SLA,並與既有的事件回應(ISO/IEC 27035)、供應商管理(27036)銜接。對多產品線廠商,還需設計漏洞影響面評估的橫向機制。

Who This Is For

  • 出口歐盟的含數位元素產品製造商(CRA 直接義務人)
  • 維護多版本韌體/軟體產品線的廠商
  • 被要求出示漏洞處理 SLA 與紀錄的供應商
  • 需建立 PSIRT 內部流程的組織

Related Deep Insights

In-depth analysis by Winners consultants, 6,000+ words per article

eu-comp

EU CRA and IEC 62443 Integration: A Compliance Guide for Taiwan Companies The EU Cyber Resilience Act (CRA) is set to be a transformative regulation, imposing strict cybersecurity requirements on digital products and services placed on the European market. For companies in Taiwan, many of which are part of the global electronics and industrial automation supply chain, compliance is no longer optional—it is a prerequisite for market access. The challenge lies in the fact that the EU CRA is a broad legislative framework, whereas IEC 62443 is a technical standard-set specifically designed for Industrial Automation and Control Systems (IACS). Integrating these two requires a strategic approach that bridges the gap between legal requirements and technical implementation. ### Understanding the EU CRA Landscape The EU CRA aims to ensure that all digital products—including software and hardware with digital elements—meet a baseline level of cybersecurity. This includes requirements for: - Risk-based security measures throughout the product lifecycle. - Vulnerability handling and incident reporting obligations. - Mandatory software-bill-of-materials (SBOM)-like transparency. - Restrictions on products with "high risk" profiles (e.g., critical infrastructure components). For companies operating in the industrial sector, these requirements often overlap with existing standards like IEC 62443, but the CRA adds a layer of legal accountability and market-wide uniformity that did not exist previously. ### The Role of IEC 62443 in CRA Compliance IEC 62443 is the most relevant technical standard for companies preparing for the EU CRA. It provides a structured approach to securing industrial systems through: - **Security Levels (SL):** Defined levels of resistance against different classes of threats. - **Lifecycle-based requirements:** Ensuring security is integrated from design through decommissioning. - **Component-level-to-system-level-assurance:** Addressing both individual products and the systems they inhabit. The EU CRA's risk-based approach aligns closely with the IEC 62443 concept of "security-by-design." However, the CRA's definition of "digital products" is broader than the traditional IACS scope of IEC 62443, meaning companies must be careful to identify which of their products fall under the regulation's jurisdiction. ### Strategic Integration: A Roadmap for Taiwan Companies To successfully navigate this dual requirement, we recommend a phased approach: 1. **Inventory and Classification:** Identify all digital products and components within your portfolio. Determine which products are subject to the EU CRA based on their intended use and risk profile. 2. **Gap Analysis:** Map your current IEC 62443 implementation against the specific requirements of the EU CRA. Pay close attention to the CRA's unique mandates, such as the obligation to report actively exploited vulnerabilities to ENISA within 24 hours. 3. **SBOM-Ready Documentation:** The EU CRA will require transparency regarding software components. Companies should be closely monitoring the development of the EU AI Act and the Cyber Resilience Act's specific technical standards, which will likely be published by CEN/CENELEC. 4. **Lifecycle Management:** Ensure that your product development lifecycle (SDLC) includes documented processes for vulnerability management, patch distribution, and end-of-life security measures as required by the CRA. ### Challenges and Considerations - **The "High Risk" Category:** Products used in critical infrastructure (e.g., energy, water, transport) will face stricter certification requirements under the CRA. Companies must be closely monitoring the EU's definition of these categories. - **Supply Chain Transparency:** The CRA places the burden of compliance on the "manufacturer" or importer. This means even if you are a component supplier, you must provide sufficient documentation to your EU-based customers to enable their compliance. - **Global vs. Regional Standards:** While IEC 62443 is a global standard, the EU CRA is a regional regulation. Companies must ensure their technical measures satisfy both the global industry expectation and the specific legal requirements of the EU market. ### About Our Company Winners Consulting Services Co., Ltd. (Winners) assists companies in navigating the complexities of international cybersecurity regulations. We specialize in aligning industrial practices with standards like IEC 62443 and emerging regulations like the EU CRA. Our team provides the technical expertise and strategic guidance necessary to ensure your digital products meet both regulatory and customer expectations, securing your position in the global marketplace. For a detailed assessment of your company's compliance status, please contact us to schedule a consultation.

Winners Consulting Services Co., Ltd. (Winners) has identified that if Taiwanese companies fail to complete simultaneous EU CRA and IEC 62443 certification by 2026, they face a risk of up to 30% order loss. We provide a four-step solution to help companies achieve compliance within 7 to 12 months.

eu-comp

EU CRA Compliance and IEC 62443 Gaps: Key Strategies for Taiwan Companies The EU Cyber Resilience Act (CRA) is set to be a transformative regulation, imposing strict cybersecurity requirements on digital products and services placed on the European market. For Taiwan companies, many of whom are integral parts of global electronics and industrial supply chains, the compliance burden is significant. A critical question for our clients is: How do the requirements of the EU CRA differ from the existing IEC 62443 standard, and how can we bridge these gaps? ### Understanding the Regulatory Landscape The EU CRA is a legally binding regulation, not just a technical standard. It mandates "security-by-design" principles, requiring manufacturers to be able to identify, be accountable for, and remediate digital vulnerabilities throughout the entire lifecycle of a product. IEC 62443, on the other hand, is a collection of standards and technical reports focused on the security of Industrial Automation and Control Systems (IACS). While IEC 62443 provides the technical "how-to," the EU CRA provides the legal "must-do." ### Key Differences and Challenges 1. **Scope and Application:** IEC 62443 is primarily focused on industrial environments (OT). The EU CRA has a much broader scope, covering any digital product with digital elements, including consumer electronics and IoT devices. 2. **Legal Liability:** The EU CRA introduces significant penalties for non-compliance, including fines of up to €15 million or 2.5% of global annual turnover. IEC 62443 is a voluntary standard; compliance is a market-driven decision rather than a legal obligation. 3. **Lifecycle Management:** The EU CRA explicitly requires ongoing vulnerability management, incident reporting to ENISA (European Union Agency for Cybersecurity), and a clear path for security updates. While IEC 62443 touches on lifecycle management, the CRA's requirements are more prescriptive and legally enforceable. 4. **Documentation and Transparency:** The EU CRA will require manufacturers to provide technical documentation, a declaration of conformity, and information for users on how to use the product securely. This level of transparency is more stringent than what is typically required under IEC 62443. ### Strategic Measures for Taiwan Companies To navigate these challenges, we recommend a three-pronged approach: **1. Conduct a Comprehensive Gap Analysis** The first step is to map your current security practices against the specific requirements of the EU CRA. This means evaluating your existing IEC 62443 implementation—or any other frameworks you currently follow—against the new regulations. We can assist in identifying which products fall under the CRA's scope and where your current controls fall short. **2. Integrate Security into the Product Development Lifecycle** The EU CRA's "security-by-design" requirement means that cybersecurity cannot be an afterthought. It must be integrated from the initial design phase through to decommissioning. This requires changes in processes, documentation, and team structures. We help companies implement these processes, ensuring that security considerations are documented and verifiable at every stage. **3. Establish Robust Vulnerability and Incident Management Processes** The EU CRA will be closely closely monitored by national authorities. Companies must be able to detect, report, and remediate vulnerabilities within strict timelines. This means establishing a dedicated team or process for vulnerability monitoring, patch management, and incident response. ### About the Company Winners Consulting Services Co., Ltd. (Winners) is a leading cybersecurity consultancy based in Taiwan, specializing in helping industrial and technology companies navigate complex regulatory landscapes. With deep expertise in both IEC 62443 and emerging regulations like the EU CRA, we provide the strategic guidance necessary to ensure our clients remain competitive in the global market. For more information on how to prepare your company for the EU CRA, please contact us at [insert contact information].

Winners Consulting Services Co., Ltd. (Winners) has identified that if Taiwanese companies fail to integrate EU CRA and IEC 62443 standards by September 2026, they face a risk of up to 30% order loss. Based on our latest research, this article outlines common pitfalls and provides a three-step solution.

FAQ

Q30111 和 29147 一定要一起導入嗎?

強烈建議。CRA 的漏洞義務同時涵蓋對外揭露與內部處理,兩標準的條文互相引用、流程互相銜接,分開導入會在交接面留下稽核缺口。

Q我們已有資安事件處理程序,夠嗎?

事件處理(27035)處理「已發生的攻擊」,漏洞處理(30111)處理「被回報的弱點」——觸發源、時限與輸出不同。既有事件流程是好基礎,但 CRA 稽核的是漏洞專屬流程與證據。

Q支援期內的舊產品也要管嗎?

要。CRA 義務及於產品的支援期間,製造商須明示支援期限並在期間內持續處理漏洞與提供更新——這是許多硬體廠商最大的制度缺口。

Q導入產出有哪些?

漏洞處理政策與流程文件、分級準則(如 CVSS 本地化準則)、處理紀錄與 SLA 報表機制、SBOM 銜接程序、與 29147 揭露端的介接文件——全部以「可被公告機構與客戶稽核」為標準。