1.1 General The present document specifies technical requirements and corresponding assessment criteria for operating systems related to cybersecurity. The products with digital elements in scope, thereafter "the operating system": • are specified within the "technical description" of the "category of product" number 11 of Annex III, Class I by the Commission Implementing Regulation (EU) 2025/2392 as: "software products with digital elements that provide an abstract interface of the underlying hardware and control the execution of software, and that may provide services such as computing resource management and configuration, scheduling, input-output control, managing data, and providing an interface through which applications interact with system resources and peripherals. This category includes but is not limited to real time operating systems, general-purpose and special-purpose operating systems". • are only covered within the product context described in clause 4. The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 Annex I Part I under the conditions identified in Annex A. The use of harmonised standards is voluntary. 1.2 Products in scope 1.2.1 General Products in scope are products whose core function and intended or reasonably foreseeable use or misuse is as an operating system. Operating systems are defined in point 11 of Annex III, Class I of Regulation (EU) 2024/2847 and described in Commission Implementing Regulation (EU) 2025/2392 as "software products with digital elements that provide an abstract interface of the underlying hardware and control the execution of software, and that may provide services such as computing resource management and configuration, scheduling, input-output control, managing data, and providing an interface through which applications interact with system resources and peripherals. This category includes but is not limited to real-time operating systems, general-purpose and special-purpose operating systems". The present document applies equally to real-time, general-purpose, and special-purpose operating systems. Where a specific requirement depends on hardware or software features that not all operating system architectures provide, the applicability of that requirement is stated in the applicability field of the corresponding mitigation in clause 5. The underlying hardware may be virtualised to some degree, as when an operating system is running on a hypervisor. This category includes but is not limited to: • General purpose operating systems - Personal computing operating systems - Mobile operating systems - Server operating systems • Special purpose operating systems - Real-time operating systems - Embedded operating systems - Single-purpose operating systems Many products contain multiple operating systems which can affect the security functions of other operating system(s) in the product. For example, a Baseboard Management Controller (BMC) contains an operating system that can manage most or all of the hardware managed by the main system operating system. Radiofrequency transmission devices often have an embedded real-time operating system and the ability to read or write to system memory or trigger interrupts. Where a product contains multiple operating systems, the present document applies to each operating system in scope separately. From the perspective of the operating system under assessment, any other operating system in the product is part of its operational environment. Some of the operating systems may not always be readily available as separate products and are included as components of another product. Where there may be other specifications that target that product category, it may be more relevant to review the operating system as part of that larger system rather than independently via the present document. 1.2.2 Components of operating systems that are in scope The present document applies to the operating system as a whole. The following non-exhaustive list identifies common component types where the cybersecurity requirements of the present document most often have effect. The list is informative; all components of the operating system are covered by the requirements. The following non-exhaustive list of types of components are common to many operating systems and, when present, are considered security-relevant: • Kernel: The central component responsible for managing hardware resources and enforcing access controls. • Device Drivers: Software components supplied with the operating system that interact directly with hardware devices. • Cybersecurity Libraries: Libraries used to provide cybersecurity services, such as encryption, authentication, and authorisation. • Authentication Services: Authentication mechanisms required for operating system functionality. • Privileged Processes: Operating system processes running with elevated privileges or access to sensitive resources. • Software Update Mechanisms: Systems responsible for installing and updating software components supplied with the operating system. • Logging and Monitoring: Functions performed by the operating system that record cybersecurity-relevant events or monitor system behaviour. • Configuration Management: Management of the configuration of cybersecurity-relevant operating system settings, including provisioning of a secure-by-default configuration. A given component may fall under more than one category. The categories are illustrative and not mutually exclusive. 1.3 Products covered by other CRA harmonised standards Some product categories that provide functionality overlapping with an operating system are covered by their own CRA harmonised standard. Where such a standard exists for a product category, that standard applies to it. These categories include: • Hypervisors and container runtime systems that support virtualised execution of operating systems (Annex III, Class II, point 1 of Regulation (EU) 2024/2847). • Boot managers (Annex III, Class I, point 8 of Regulation (EU) 2024/2847). For products that embed or interact with an operating system while having a different core functionality, manufacturers may refer to the present document as one part of demonstrating compliance for the operating system component.
Nõutud väljad on tähistatud *
Saada