Module 3 of 8 · 40 min
Annex I Part I: secure-by-design essential requirements
The product-property requirements: risk-based design, secure defaults, update mechanisms, access control, data protection, attack-surface minimisation, and logging.
Learning objectives
- List the Annex I Part I essential requirements and what each demands of the shipped product
- Explain how the Article 13 cybersecurity risk assessment scopes which requirements apply and how
- Distinguish security updates enabled by default with opt-out from forced updates
- Identify which requirement a described product weakness violates
- Explain how harmonised standards create a presumption of conformity with Part I
A risk-based rulebook
Annex I Part I opens with the umbrella requirement: products must be designed, developed and produced to ensure an appropriate level of cybersecurity based on the risks. Every following requirement applies where applicable, meaning the manufacturer's own cybersecurity risk assessment under Article 13 decides how each requirement lands on the product. The risk assessment is not paperwork after the fact: it must be documented, kept up to date, and included in the technical documentation, and it must cover planning, design, development, production, delivery and maintenance.
Shipping clean and secure by default
Products must be made available on the market without known exploitable vulnerabilities and with a secure by default configuration, including the possibility to reset to that state. Security updates must be installed by default with a clear opt-out mechanism, distinguishing them where technically feasible from functionality updates. Protection from unauthorised access requires appropriate control mechanisms, including authentication and identity or access management, and reporting on possible unauthorised access.
Data, availability, and footprint
Confidentiality must be protected by encrypting relevant data at rest and in transit using state of the art mechanisms. Integrity protection covers data, commands, programs and configuration against unauthorised manipulation. Products must process only data that is adequate, relevant and limited to what is necessary for the intended purpose — data minimisation as a product requirement. Availability of essential and basic functions must be protected, including resilience against denial of service attacks, and products must minimise their own negative impact on the availability of services provided by other devices or networks.
Attack surface, mitigation, logging, and deletion
Products must be designed to limit attack surfaces, including external interfaces, and to reduce the impact of incidents using appropriate exploitation mitigation mechanisms and techniques. Security-relevant information must be recorded and monitored, such as access to or modification of data, services or functions, with an opt-out for the user. Finally, users must be able to securely and easily remove all data and settings on a permanent basis, and where data can be transferred, to do so securely.
Part I describes the product as shipped; Part II describes the process after shipping. Scenario questions often test whether you can tell which side of that line a failure sits on.
Official sources for this module
Module 3 quiz
10 questions, pass mark 70%, 3 attempts. Starting an attempt consumes it.
Enroll and confirm your email to take the quiz.