CVD-Policy – Implementation of the Cyber Resilience Act (CRA) at GRAEF
For GRAEF, cyber security is an essential component of product quality and product safety. This applies in particular to products with digital functions, software, network and communication interfaces, and remote maintenance capabilities.
Our commitment
GRAEF takes cybersecurity risks into account right from the development stage and throughout the entire product lifecycle.
In doing so, we adhere in particular to the following principles:
- Security by Design: Cybersecurity is taken into account right from the product development stage.
- Secure default settings: Where possible, products are supplied with appropriate security settings.
- Protection of access and authorisations: Access to products and digital functions is adequately protected.
- Secure updates: Security-related software and firmware updates are provided as required.
- Continuous improvement: New findings and disclosed vulnerabilities are assessed and, where necessary, incorporated into improvement measures.
Dealing with security vulnerabilities
GRAEF monitors security risks relating to its products and takes reports of potential vulnerabilities seriously.
Reports can be submitted to GRAEF by customers, partners, suppliers, security researchers or other individuals via the contact details provided on our website.
Reported security vulnerabilities are investigated, assessed for risk and – where necessary – rectified through appropriate measures. This may take the form of, for example, software or firmware updates, configuration changes or security advisories.
We ask that you report security vulnerabilities responsibly and refrain from making any changes to products, systems or customer networks that go beyond what is necessary for testing and reporting purposes.
Implementation of the Cyber Resilience Act
GRAEF entwickelt seine Prozesse und Produkte schrittweise weiter, um die Anforderungen des Cyber Resilience Act (CRA) der Europäischen Union für Produkte mit digitalen Elementen zu erfüllen.
Hierzu gehören insbesondere die Berücksichtigung von Cybersicherheit bei der Produktentwicklung, die Behandlung von Schwachstellen, Sicherheitsupdates und die Einhaltung der geltenden gesetzlichen Meldepflichten.
Auch sicherheitsrelevante Komponenten und Software von Lieferanten und Entwicklungspartnern werden angemessen berücksichtigt.
Responsibility in product operation
Secure product design is an essential component of cybersecurity. Equally important is the secure and intended operation of the product by the operator.
For connected GRAEF products, particular attention must be paid to secure network access, user authorisations and remote maintenance connections. Operators should implement any security and software updates provided in a timely manner and follow the relevant security instructions.
Security Advisories
GRAEF welcomes responsible reports of potential security vulnerabilities in GRAEF products.
A security report should, where possible, include details of the affected product, the software or firmware version, a description of the vulnerability and – where available – information on how to reproduce the issue and its potential impact.
The current contact details for security reports can be found on the GRAEF website under ‘Security Report / Security Vulnerability’.
GRAEF
This information is reviewed regularly and updated as necessary to reflect new legal requirements, technical developments and findings.
CVD Security Registration Form for Connected Products
To be completed immediately in the event of any suspected IT vulnerability or cyber attack
Please enter your details in the form below.
Fields marked with ° are mandatory.