Mapping EN 304 626 to embedded Linux systems. Quo Vadis?
Simone Weiß - Linutronix GmbHETSI EN 304 626 is becoming an important reference point for the cybersecurity of operating systems under the Cyber Resilience Act. But what happens when its applied to a real embedded Linux system?
Linux already provides good security functionality: privilege separation, access control, memory protection, isolation, cryptography, secure updates, logging, and hardening. Yet an embedded Linux system is more than a kernel, and not every requirement can be fulfilled by Linux itself.
This talk maps EN 304 626's requirements onto a real embedded Linux architecture and classifies them into three categories: what Linux directly satisfies, what Linux enables but the product must configure and prove, and what depends on hardware, firmware, or organizational process outside the OS.
Short Bio:
Simone Weiß is has worked previously on practical implementation of emerging security standards, such as UNECE R 155 and UNECE R 156, and open source for safety applications and is serving as the General Member Representative in ELISAs (Enabling Linux in Safety Applications) Governing Board. Simone joined Linutronix in 2025 and worked on Compliance of Linutronix IGLOS Operating System with EN 304 626.