EN 18031
The EN 18031 series of cybersecurity standards for the Radio Equipment Directive (RED) (Directive 2014/53/EU and Delegated Regulation (EU) 2022/30).
Written by CEN/CLC/JTC 13/WG 8 to cover essential requirements 3.3 (d), (e) and (f) under RED.
- EN 18031-1 covering article 3.3 (d) “radio equipment does not harm the network or its functioning nor misuse network resources, thereby causing an unacceptable degradation of service”
- EN 18031-2 covering article 3.3 (e) “processing data, namely Internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment”
- EN 18031-3 covering article 3.3 (f) “radio equipment processing virtual money or monetary value”
Security-by-Design
Structured Risk Assesment (e.g. STRIDE-Modells):
- Spoofing
- Tampering
- Repudiation
- Information disclosure
- Denial of service
- Elevation of privilege
Categorization of security measures
- Identification of Security Risks
- Preventing or limiting security incidents
- Detecting security incidents
- Appropriate action in the event of identified incidents
- Recovery from a security incident
Requirements
- Access control mechanism (ACM)
- Authentication mechanism (AUM)
- Secure update mechanism (SUM)
- Secure storage Mechanism (SSM)
- Secure communication mechanism (SCM)
- Logging Mechanism (LGM)
- Deletion mechanism (DLM)
- User notification mechanism (UNM)
- Resilience mechanism (RLM)
- Network monitoring mechanism (NMM)
- Traffic control mechanism (TCM)
- Confidential cryptographic keys (CCK)
- General equipment capabilities (GEC)
- Cryptography (CRY)