Cybersecurity
Cybersecurity already during development For us, cybersecurity is part of the development of transport systems, not just their subsequent operation. For the software and technologies we develop, we take security requirements into account already during the architectural design and throughout the entire development process. We also consider security aspects when selecting third-party technologies and components. The goal is to identify and address security risks as early as possible – before the system is put into operation.
Secure Software Development
We integrate security requirements directly into the software development process.
Depending on the nature of the specific solution, we focus on, for example:
- secure software architecture design,
- security risk analysis,
- checking the software components and libraries used,
- identifying known vulnerabilities,
- security testing,
- source code control,
- change and version control,
- security of updates and patches,
- documentation of security-relevant changes.
Security is therefore not a separate phase at the end of development. It is part of the individual steps of the development process.
Security throughout the product life cycle
Development is only one part of the software life cycle. We also address security after it is put into operation.
We monitor relevant security information and vulnerabilities of the components used and, depending on their severity, evaluate the need for corrective measures.
This approach also includes preparing security updates and verifying them before deployment.
For transport systems, it is necessary to simultaneously take into account the requirements for stability and availability of operation. Security updates must therefore be technically validated and suitable for the specific environment in which the system is operated.
Cyber Resilience Act
Requirements for cybersecurity of software and hardware products are gradually becoming more precise in the European Union. One of the important regulations is the Cyber Resilience Act (CRA).
We take the CRA requirements into account when developing our development and security processes. This applies in particular to areas such as:
security requirements in product design and development,
vulnerability management during the life cycle,
security updates,
identification and resolution of security issues,
documentation of product security features,
processes for responding to newly identified vulnerabilities.
We see the CRA primarily as a framework for a systematic approach to product security throughout their life cycle.
ISO/IEC 27001
We also address cybersecurity at the company level.
CROSS has an established and certified information security management system (ISMS) according to the ISO/IEC 27001 standard. The certification confirms that information security, risk management and related processes are managed systematically in our company.
ISO/IEC 27001 is part of a framework for us that supports information protection, security risk management and continuous improvement of our processes.
Testing and verification
We verify the security features of the software using appropriate technical means depending on the type and risk of the specific solution.
The development process may include, for example, automated checks, source code analysis, dependency checking, application testing or other forms of security testing.
We determine the scope of testing according to the nature of the product, its architecture and method of use.
Third-party software and dependencies
Modern software is based on a number of third-party components, libraries and other technologies. Their security is therefore part of the overall product evaluation.
As part of development, we also record the components used and monitor known vulnerabilities that may affect them.
This approach allows us to more quickly assess the impact of a newly discovered vulnerability on a specific product and decide on further action.
Reporting security vulnerabilities
If you discover a potential security vulnerability in one of our products or solutions, you can report it to us.
For an effective assessment of the problem, it is advisable to indicate in particular the affected product, its version, a description of the vulnerability and the information needed to reproduce it.
We will then technically assess the notification and determine the next step based on its nature.
Security as part of development
Cybersecurity of transport systems is not only a question of their configuration after deployment. A significant part of security can be influenced during the design and development of the product itself.
Therefore, we address security requirements together with software architecture, development, testing and subsequent maintenance.
From the first design to product support in operation.