Security News > 2023 > December > EU lawmakers finalize cyber security rules that panicked open source devs
Infosec in brief The European Union's Parliament and Council have reached an agreement on the Cyber Resilience Act, setting the long-awaited security regulation on a path to final approval and adoption, along with new rules exempting open source software.
The CRA was proposed by the European Commission in September 2022 and imposes mandatory cyber security requirements for all hardware and software products - from baby monitors to routers, as the EU Commission put it.
Included in the rule is a 24-hour disclosure period for any newly-discovered security flaw under active exploitation, five years of security patch support, thorough documentation of all security features, and more.
While better security is all well and good, concerns have been raised over the potential effect the CRA could have on open source software, which is often maintained by few people despite the importance it can often have to larger products.
"Only together will we be able to tackle successfully the cyber security emergency that awaits us in the coming years."
According to a letter sent to affected individuals, names, dates of birth and social security numbers may have been exposed - but Zeroed-In isn't entirely sure.
News URL
https://go.theregister.com/feed/www.theregister.com/2023/12/04/infosec_in_brief/
Related news
- Hottest cybersecurity open-source tools of the month: November 2024 (source)
- Top 5 Cyber Security Trends for 2025 (source)
- Shape the future of UK cyber security (source)
- Strengthening security posture with comprehensive cybersecurity assessments (source)
- Overlooking platform security weakens long-term cybersecurity posture (source)
- Vanir: Open-source security patch validation for Android (source)
- What open source means for cybersecurity (source)
- Hottest cybersecurity open-source tools of the month: December 2024 (source)
- Sara: Open-source RouterOS security inspector (source)
- What’s Next for Open Source Software Security in 2025? (source)