Mapping EN 304 626 to embedded Linux systems. Quo Vadis?
Simone Weiß - Linutronix GmbHETSI EN 304 626 is becoming an important reference point for the cybersecurity of operating systems under the Cyber Resilience Act. But what happens when its applied to a real embedded Linux system?
Linux already provides good security functionality: privilege separation, access control, memory protection, isolation, cryptography, secure updates, logging, and hardening. Yet an embedded Linux system is more than a kernel, and not every requirement can be fulfilled by Linux itself.
This talk maps EN 304 626's requirements onto a real embedded Linux architecture and classifies them into three categories: what Linux directly satisfies, what Linux enables but the product must configure and prove, and what depends on hardware, firmware, or organizational process outside the OS.