The objective of this thesis is to explore the impact of the new European cyber security regulation, the Cyber Resilience Act (CRA), on the products of the company that hosted the curricular internship, defining the strategies required to achieve compliance. To this end, the work analyzes the feasibility of mapping the essential security requirements of the CRA into the security functional requirements of SESIP (Security Evaluation Standard for IoT Platforms), a certification scheme for assessing cybersecurity. Additionally, the research evaluates how the Security Assurance Framework, a collection of best practices by the IoT Security Foundation, can support the company in developing secure products. This methodological approach is finally applied to a concrete case study: the analysis of Rialto, a single-board computer serving as a network gateway developed by the company, to identify the necessary interventions to make it fully compliant with the new regulation.
L’obiettivo di questa tesi è esplorare l’impatto del nuovo regolamento europeo sulla sicurezza informatica, il Cyber Resilience Act (CRA), sui prodotti dell’azienda che ha ospitato il tirocinio curriculare, definendo le strategie necessarie per ottenerne la conformità. A questo scopo, il lavoro analizza la possibilità di mappare i requisiti essenziali di sicurezza del CRA nei requisiti funzionali del SESIP (Security Evaluation Standard for IoT Platforms), uno schema di certificazione per valutare la sicurezza informatica. In aggiunta, la ricerca valuta come il Security Assurance Framework, una raccolta di buone pratiche della IoT Security Foundation, possa supportare l'azienda nello sviluppo di prodotti sicuri. Questo approccio metodologico viene infine applicato a un caso di studio concreto: l'analisi di Rialto, un single board computer con funzioni di gateway di rete progettato dall'azienda, per identificare gli interventi necessari a renderlo pienamente conforme alla nuova normativa.
La conformità al Cyber Resilience Act tramite la certificazione SESIP
BUA CORONA, FRANCESCO
2025/2026
Abstract
The objective of this thesis is to explore the impact of the new European cyber security regulation, the Cyber Resilience Act (CRA), on the products of the company that hosted the curricular internship, defining the strategies required to achieve compliance. To this end, the work analyzes the feasibility of mapping the essential security requirements of the CRA into the security functional requirements of SESIP (Security Evaluation Standard for IoT Platforms), a certification scheme for assessing cybersecurity. Additionally, the research evaluates how the Security Assurance Framework, a collection of best practices by the IoT Security Foundation, can support the company in developing secure products. This methodological approach is finally applied to a concrete case study: the analysis of Rialto, a single-board computer serving as a network gateway developed by the company, to identify the necessary interventions to make it fully compliant with the new regulation.| File | Dimensione | Formato | |
|---|---|---|---|
|
BuaCorona_Francesco.pdf
accesso aperto
Dimensione
5.88 MB
Formato
Adobe PDF
|
5.88 MB | Adobe PDF | Visualizza/Apri |
The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License
https://hdl.handle.net/20.500.12608/111141