Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
From legislation to practice - a structured guide for the EU’s Cyber Resilience Act: Utilizing design science research to bridge theory and practice
University of Skövde, School of Informatics.
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

The increasing number of products with digital elements(PDE) has introduced several challenges in both industry and consumers as well as highlighted the importance of cybersecurity, The EU´s answer to this challenge is introducing new legislation namely the upcoming Cyber Resilience Act (CRA). The nature of this horizontal cybersecurity regulation poses challenges for manufacturers to navigate these legislative requirements into actionable steps. The goal of this thesis is to address this gap by developing a structured implementation guide for the CRA utilizing Design Science Research (DSR). The steps taken during the DSR included iterative development and validation of the implementation guide, incorporating feedback from stakeholders, and conducting evaluations in cooperation with industry partners. The resulting structured guide presents manufacturers with activities and tools to perform them covering different aspects of the CRA including five major areas: applicability and categorization of PDE, risk assessment, implementation of secure by design and by default PDEs, vulnerability management, conformity and maintenance during the PDE’s lifecycle. The designed guide incorporates established standards such as ETSI EN 303 645 and ISA/IEC 62443 4-1 to ensure alignment with internationally recognized standards and best practices. The results align and complement existing literature that emphasizes the necessity of practical tools and frameworks to bridge the gap between regulatory requirements and implementation. This study contributes to the field by providing a validated tool that can be used by practitioners for following CRA. The practical aspects of the implementation guide aim to address a gap in the field by providing insights into the CRA and upcoming trends in cybersecurity, thus the findings contribute to both academia and industry by presenting a resource for navigating the CRA. 

Place, publisher, year, edition, pages
2024. , p. 5, 67, vii
Keywords [en]
Cyber resilience act, CRA, EU cybersecurity legislation, design science research, cybersecurity standards, implementation guide, products with digital elements, IoT security, risk assessment, digital product security, EU regulations, vulnerability management, secure software development
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-24558OAI: oai:DiVA.org:his-24558DiVA, id: diva2:1900283
External cooperation
QRTECH AB
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2024-09-23 Created: 2024-09-23 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(3322 kB)1365 downloads
File information
File name FULLTEXT01.pdfFile size 3322 kBChecksum SHA-512
91c97741d648cb77bedbb06ea27554911f43f32d387106beec4944795dfe60c08d7581a90ad0401f3d5a2617b351442a1644c623aa20d1ee3f4c22c36dc7d8c6
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspects

Search outside of DiVA

GoogleGoogle Scholar
Total: 1365 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1901 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf