English: This document specifies general cybersecurity principles and general risk management activities for all products with digital elements. It addresses all phases of the product lifecycle to ensure and maintain an appropriate level of cybersecurity, taking into account the risks.
Ensures that cybersecurity measures are based on identified risks and are proportionate, taking into account the magnitude of loss or disruption and the likelihood of occurrence.
Cybersecurity measures are systematically implemented starting from the concept phase throughout the product lifecycle. Cybersecurity is a fundamental aspect of design, not an element to be added later.
指南
原则
中文
English
最小权限
实体仅获得执行功能绝对必要的访问权限
Entities receive only absolutely necessary access
攻击面最小化
尽可能减少攻击向量和访问点
Minimize attack vectors and access points
深度防御
多层安全措施防范广泛威胁
Multiple layers of security measures
安全编程实践
系统避免/检测缺陷和漏洞
Systematically avoid/detect defects and vulnerabilities
不依赖隐蔽性
不单纯依赖设计细节保密
No sole reliance on secrecy of design
以用户为中心
考虑使用环境,保护用户安全
Consider use context, protect user security
生命周期管理
全生命周期实施安全措施
Implement security throughout lifecycle
3. 默认安全 (Security by Default)
概要
语言
内容
中文
产品的默认行为对于预期用途和操作环境是安全的。安装后即安全配置,及时安装安全更新。
English
The default behavior of the product is secure for intended use and environment. Securely configured after installation, updates installed promptly.
指南
要求
中文
English
预设安全配置
安全配置作为默认设置
Secure configurations as default settings
最小攻击面
禁用不必要的接口
Disable unnecessary interfaces
用户通知
告知用户预设安全状态
Inform users of preset secure state
恢复机制
提供恢复到安全状态的方法
Provide method to restore secure state
更新选项
可推迟更新但需告知风险
May defer updates with risk information
4. 透明性 (Transparency)
概要
语言
内容
中文
向相关利益相关者传达和提供所需的网络安全信息,以支持实现和维持产品网络安全。
English
Communicate and make available cybersecurity information needed by relevant stakeholders to support achieving and maintaining product cybersecurity.
评论