5 ms·
> CRA Well, how small business can report anything during 24 hours through weekends, long weekends, 1-week Christmas, 3-4-weeks summer vacations?
by kvemkon 23d ago
> CRA
Well, how small business can report anything during 24 hours through weekends, long weekends, 1-week Christmas, 3-4-weeks summer vacations?
- ghosty141 23d agoThose will obviously be exempt?
- kvemkon 23d agoIf the law wouldn't say 24 hours counting only working hours (3 working days for small business or even weeks during vacations), then it wouldn't be an exempt.
- ghosty141 23d agoNo you misunderstood it: https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions https://www.enisa.europa.eu/topics/product-security/single-r... > Reporting process starts at the moment manufacturer becomes aware of active exploitation of vulnerability or incident. If your business is closed (due to vacation or sickness for example) you don't become aware until you are back.
- kvemkon 22d agoThis is an interesting point of view. I've been thinking that only the moment counts, when the manufacturer has been made aware, regardless when the manufacturer has in fact actively become aware. Thanks!
- ghosty141 22d agoI have a lot of contact with the CRA at work and I actually think its a very good piece of regulation. There are barely any parts where I think they are straight up bad. I think it only hurts super small one man part time developers but even then: If I pay for a piece of software I expect it to be secure and have a bit of support.