1. Purpose and Scope
This policy establishes the internal procedures of Tarso-man S.L.U. for the identification, assessment, remediation and disclosure of vulnerabilities affecting its industrial remote control products with digital elements, ensuring compliance with Regulation (EU) 2024/2847 (Cyber Resilience Act – CRA). The policy applies to all hardware, firmware and software associated with the company's products throughout their entire lifecycle, including design, manufacturing and post-market support. In particular, Tarso-man S.L.U. shall provide technical support and security updates throughout the declared support period for each product (at least five years after the product has been placed on the market, unless the expected product lifetime is shorter). The objective of this policy is to ensure that Tarso-man S.L.U. proactively manages vulnerabilities reported from both internal and external sources and maintains its products free from exploitable vulnerabilities, as required by Annex I of the Cyber Resilience Act.
2. Vulnerability Reporting Channels
Tarso-man S.L.U. provides a designated single point of contact for the reporting of product vulnerabilities, in accordance with the requirements of the Cyber Resilience Act. The official reporting channels are:
- E-mail: [email protected]
- Telephone: +34 954 689 663
These communication channels are continuously monitored to ensure a timely response. As required by the CRA, the single point of contact shall be easily identifiable and shall allow users to communicate through multiple communication channels rather than relying solely on automated tools. All incoming vulnerability reports will be acknowledged by the responsible personnel, thereby initiating the vulnerability handling process.
3. Hardware and Firmware Traceability
To minimize the impact of potential vulnerabilities, Tarso-man S.L.U. maintains comprehensive traceability records for every product delivered. The company's internal ERP system associates each product serial number with its corresponding hardware configuration and installed firmware version. This enables compliance with the CRA requirement to identify the components incorporated into each product. In practice, this provides an up-to-date inventory, allowing Tarso-man S.L.U. to immediately identify which products, customers and serial numbers may be affected whenever a new vulnerability is identified. This traceability enables corrective actions to be targeted exclusively at the affected products.
4. Vulnerability Assessment and Remediation Procedure
Internal Procedure
- Initial Triage and Assessment: Upon receipt of a vulnerability report, the technical team shall verify its authenticity and reproduce the reported vulnerability in a controlled environment. The associated risk shall then be assessed, considering factors such as: likelihood of exploitation; impact on the safe operation of the machine controlled by the receiver; confidentiality, integrity and availability of data; overall impact on product security. Following this assessment, each vulnerability shall be classified according to its severity in order to establish the appropriate remediation priority.
- Critical: A vulnerability capable of compromising product security, enabling code execution, unauthorized access, or affecting the safe operation of the equipment. Corrective action: Highest priority remediation. Security updates shall be performed exclusively by authorized Tarso-man S.L.U. personnel at the company's facilities.
- High: A significant security risk with a realistic possibility of exploitation, although temporary mitigation measures may exist. Corrective action: High-priority remediation and intervention scheduled within the shortest technically feasible timeframe.
- Medium: Limited impact without immediate consequences for product security or safe operation. Corrective action: Security correction implemented during the next scheduled intervention or whenever the equipment is received at Tarso-man S.L.U.'s facilities.
- Low: Minor vulnerability with no significant impact on product security or data protection. Corrective action: Correction incorporated into future firmware maintenance releases when the equipment undergoes service at Tarso-man S.L.U.'s facilities.
- Development and Validation of the Solution: An appropriate firmware security patch or hardware/configuration mitigation shall be developed and thoroughly tested to ensure that the vulnerability is effectively resolved without introducing additional security or functional issues.
- Implementation: Once the corrective solution has been validated, Tarso-man S.L.U. shall determine the deployment method according to the severity of the vulnerability.
- Critical and High vulnerabilities, namely those capable of compromising product security, enabling unauthorized access, affecting firmware integrity or jeopardizing product availability or safe operation, shall be remediated as a priority through security updates performed exclusively by authorized Tarso-man S.L.U. personnel at the company's facilities. This approach ensures that every firmware update is carried out within a secure and controlled environment.
- Medium and Low vulnerabilities that do not compromise product security, data confidentiality or integrity, or the safe operation of the equipment shall be corrected by incorporating the corresponding security patch during the next scheduled service intervention or whenever the product is returned to Tarso-man S.L.U. for maintenance, inspection or repair.
- Record Keeping and Documentation: All reported vulnerabilities shall be documented internally, including their technical description, severity level, affected products identified by serial number, and all corrective actions implemented. The documentation shall also include details of the applied security patch, implementation dates and customer notification dates. All activities shall be performed in accordance with Tarso-man S.L.U.'s Coordinated Vulnerability Disclosure Policy, which defines the corresponding responsibilities, procedures and response timelines.
5. Communication and Disclosure Obligations
Communication Procedure
- Notification to Affected Customers: Customers whose products may be affected shall be informed proactively by e-mail. The communication shall include: a description of the vulnerability; identification of the affected products by serial number; recommended mitigation measures; where applicable, instructions for coordinating the application of the required security update with Tarso-man S.L.U. Whenever appropriate, a security advisory may also be published on the Tarso-man S.L.U. support website to ensure that all users are informed of the available corrective measures.
- Notification to Competent Authorities (ENISA / CSIRT): Where an actively exploited vulnerability or a significant cybersecurity incident is identified, Tarso-man S.L.U. shall notify both the designated national CSIRT and the European Union Agency for Cybersecurity (ENISA) through the Single Reporting Platform established under Article 14 of the Cyber Resilience Act. The statutory reporting deadlines shall be observed: early warning within 24 hours after becoming aware of the incident; complete notification within 72 hours; final report, including a detailed description of the vulnerability or incident, severity assessment, root cause analysis and implemented corrective measures, within 14 days after the remediation becomes available (or within 30 days for significant incidents). These notifications enable ENISA and the relevant CSIRTs to coordinate the response and, where appropriate, alert other potentially affected users.
- Security Updates: All security updates intended to remediate cybersecurity vulnerabilities shall be provided to customers free of charge throughout the declared support period. Due to the secure design of Tarso-man S.L.U. products, firmware updates may only be performed by authorized personnel at the company's facilities, thereby ensuring the authenticity, integrity and traceability of every firmware update. Tarso-man S.L.U. shall maintain documented records of all security updates performed, linking each intervention to the corresponding product serial number.
Through this policy, Tarso-man S.L.U. ensures a proactive and coordinated vulnerability management process in accordance with the essential cybersecurity requirements established by the Cyber Resilience Act. This policy shall be reviewed periodically to incorporate best practices and to adapt its procedures and response times in line with regulatory developments and evolving cybersecurity requirements.