Skip to content

Commit 879e76f

Browse files
xeniapelfrancke
andauthored
Add CRA docs and Compliance docs structure (#786)
* Add CRA docs and Compliance docs structure * pre-commit fixes * update menu navbar * fix policies menu link * fix policies menu link * fix policies menu link * Initial content for CRA page * Add content to overview page * Spell out CRA in table of contents --------- Co-authored-by: Lars Francke <[email protected]>
1 parent 415d85e commit 879e76f

16 files changed

+134
-29
lines changed

antora.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ nav:
1111
- modules/ROOT/nav2.adoc # this is for the 'Management' link
1212
- modules/reference/nav.adoc
1313
- modules/contributor/nav.adoc
14+
- modules/compliance/nav.adoc
1415
- modules/ROOT/nav3.adoc # this is for the extra bits at the end of the menu
1516
# The prerelease setting affects version sorting.
1617
# Set to 'true' for nightly and false otherwise.

modules/ROOT/nav3.adoc

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1 @@
11
* xref:release-notes.adoc[Release notes]
2-
* xref:product-information.adoc[]
3-
* xref:policies.adoc[]
4-
* xref:licenses.adoc[Licenses]
5-
* xref:export.adoc[Export Control]
Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
1-
* xref:kubernetes/eks.adoc[]
2-
* xref:kubernetes/aks.adoc[]
3-
* xref:kubernetes/gke.adoc[]
4-
* xref:kubernetes/ionos-managed-k8s.adoc[]
5-
* xref:kubernetes/ionos-managed-stackable.adoc[]
6-
* xref:kubernetes/kind.adoc[]
7-
* xref:kubernetes/microk8s.adoc[]
8-
* xref:kubernetes/openshift.adoc[]
9-
* xref:kubernetes/suse-k3s.adoc[]
10-
* xref:kubernetes/suse-rancher.adoc[]
1+
* xref:ROOT:kubernetes/eks.adoc[]
2+
* xref:ROOT:kubernetes/aks.adoc[]
3+
* xref:ROOT:kubernetes/gke.adoc[]
4+
* xref:ROOT:kubernetes/ionos-managed-k8s.adoc[]
5+
* xref:ROOT:kubernetes/ionos-managed-stackable.adoc[]
6+
* xref:ROOT:kubernetes/kind.adoc[]
7+
* xref:ROOT:kubernetes/microk8s.adoc[]
8+
* xref:ROOT:kubernetes/openshift.adoc[]
9+
* xref:ROOT:kubernetes/suse-k3s.adoc[]
10+
* xref:ROOT:kubernetes/suse-rancher.adoc[]
Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
1-
* xref:kubernetes/huawei-cloud.adoc[]
2-
* xref:kubernetes/ibm-cloud.adoc[]
3-
* xref:kubernetes/ovh-mks.adoc[]
4-
* xref:kubernetes/plusserver.adoc[]
5-
* xref:kubernetes/ske.adoc[] (with the exception of missing public NodePorts)
6-
* xref:kubernetes/vmware_tanzu.adoc[]
7-
* xref:kubernetes/oke.adoc[]
1+
* xref:ROOT:kubernetes/huawei-cloud.adoc[]
2+
* xref:ROOT:kubernetes/ibm-cloud.adoc[]
3+
* xref:ROOT:kubernetes/ovh-mks.adoc[]
4+
* xref:ROOT:kubernetes/plusserver.adoc[]
5+
* xref:ROOT:kubernetes/ske.adoc[] (with the exception of missing public NodePorts)
6+
* xref:ROOT:kubernetes/vmware_tanzu.adoc[]
7+
* xref:ROOT:kubernetes/oke.adoc[]

modules/compliance/nav.adoc

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
* xref:index.adoc[Compliance]
2+
** xref:product-information.adoc[]
3+
** xref:policies.adoc[]
4+
** xref:licenses.adoc[Licenses]
5+
** xref:export.adoc[Export Control]
6+
** xref:cra.adoc[Cyber Resilience Act]

modules/compliance/pages/cra.adoc

Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
= Cyber Resilience Act (CRA)
2+
3+
NOTE: The https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847[Cyber Resilience Act (CRA)] is a European regulation that establishes cybersecurity requirements for products with digital elements placed on the EU market.
4+
It aims to ensure that hardware and software products are designed, developed, and maintained with adequate cybersecurity throughout their lifecycle.
5+
6+
This will be expanded over time.
7+
8+
== Target Audience & Content
9+
10+
This page serves as a central hub for
11+
12+
* users of the Stackable Data Platform (SDP),
13+
* market surveillance authorities,
14+
* and the https://single-market-economy.ec.europa.eu/single-market/goods/building-blocks/market-surveillance/organisation/adcos_en[Administrative Cooperation Group] (AdCo) established in Article 52(15)
15+
16+
to find all information mandated by the CRA in a single and central place.
17+
18+
== Stackable Data Platform (SDP) classification
19+
20+
The CRA defines multiple product categories that determine the conformity assessment procedure.
21+
We consider the Stackable Data Platform to be a default product (not Important or Critical).
22+
This means we perform a self-assessment of conformity rather than requiring third-party certification.
23+
24+
== Annex II: Information and instructions to the user
25+
26+
Annex II of the CRA specifies information that manufacturers must provide to users.
27+
The following items correspond to the numbered requirements in Annex II:
28+
29+
. **Contact Information**: You can find all our contact information on our homepage in the https://stackable.tech/en/imprint/[imprint] section.
30+
31+
. **Vulnerability Disclosure**: Please see our https://stackable.tech/en/vulnerability-disclosure-policy/[Vulnerability Disclosure Policy] for all information on how to report vulnerabilities in a coordinated way.
32+
33+
. **Product Identification**: The Stackable Data Platform (SDP) is a Kubernetes-based data platform for operating data applications.
34+
All our images are tagged and contain annotations to identify the product versions.
35+
Additional documentation will follow.
36+
37+
. **Intended Purpose and Security Properties**: Information about the intended purpose of SDP, the security environment, essential functionalities, and security properties will be documented here.
38+
39+
. **Known Cybersecurity Risks**: Information about known or foreseeable circumstances that may lead to significant cybersecurity risks will be documented here.
40+
41+
. **EU Declaration of Conformity**: The internet address at which the EU declaration of conformity can be accessed will be provided here when available.
42+
43+
. **Security Support and Support Period**: Please see our xref:policies.adoc[Lifecycle policies] for information on the type of security support offered and the support duration, including the period during which vulnerabilities will be handled and security updates provided for the Stackable Data Platform and the included products.
44+
45+
. **Security Instructions**: Detailed instructions on the following topics will be documented here:
46+
+
47+
--
48+
* Necessary measures during initial commissioning and throughout the product lifetime to ensure secure use
49+
* How changes to the product can affect data security
50+
* How to install security-relevant updates
51+
* Secure decommissioning of the product and secure removal of user data
52+
* How to manage automatic security update settings
53+
* Information for integrators on cybersecurity requirements (where applicable)
54+
--
55+
56+
. **Software Bill of Materials (SBOM)**: We provide https://sboms.stackable.tech/[SBOMs] for all container images in the Stackable Data Platform.
57+
Please see our xref:guides:viewing-and-verifying-sboms.adoc[SBOM documentation] for information on how to access, view, and verify SBOMs.

0 commit comments

Comments
 (0)