{
  "bam_id": "CRA-002a-CVE",
  "regulation": "CRA",
  "article": "Anh. I §2a + Art. 14",
  "status": "ausstehend",
  "tags": [
    "cve",
    "schwachstellen",
    "patch",
    "enisa"
  ],
  "cross_refs": [
    "NIS-2 Art. 21 §2e",
    "ISO 27001 A.12.6.1"
  ],
  "requirement": {
    "text": "Systematisches Schwachstellenmanagement über den gesamten Produktlebenszyklus – CVE-Identifikation, Bewertung, Behebung und Meldung aktiv ausgenutzter Schwachstellen an ENISA innerhalb von 24 Stunden.",
    "source": "CRA Anh. I §2a + Art. 14",
    "priority": "hoch"
  },
  "gap_check": {
    "question": "Existiert ein dokumentierter CVE-Prozess mit Vulnerability-Tracking, definierten SLAs und aktivem ENISA-Meldeprozess für ausgenutzte Schwachstellen?",
    "if_yes": "SLAs und ENISA-Meldeprozess regelmäßig testen und dokumentieren.",
    "if_no": "Kein CVE-Prozess – CRA-Kernpflicht für alle Hersteller digitaler Produkte.",
    "if_partial": "Schwachstellenmanagement vorhanden aber kein ENISA-Meldeprozess."
  },
  "remediation": {
    "summary": "Vollständigen CVE-Prozess mit ENISA-Meldepflicht aufbauen",
    "steps": [
      "CVE-Tracking-System einrichten (CVE-Datenbank, NVD-Feed)",
      "SLAs definieren: aktiv ausgenutzte Schwachstellen → 24h Meldung an ENISA",
      "ENISA-Meldekanal und Kontaktdaten hinterlegen",
      "SBOM (Software Bill of Materials) für alle Produkte erstellen"
    ],
    "effort": "hoch",
    "deadline": "mittelfristig",
    "tools": [
      "CVE-Tracker",
      "SBOM-Tool",
      "ENISA-Meldeportal"
    ],
    "book_reference": {
      "book": "Cyber Resilience Act in der Praxis",
      "chapter": "Kap. 7.1 – Vulnerability Management"
    },
    "cost_estimate": {
      "pt_min": 8,
      "pt_max": 15,
      "note": "CVE-Prozess + SBOM + ENISA-Meldung"
    }
  },
  "risk": {
    "likelihood": 3,
    "impact": 4,
    "score": 7,
    "description": "Fehlende ENISA-Meldung aktiv ausgenutzter Schwachstellen ist direkter CRA-Verstoß.",
    "regulatory_fine": {
      "max_eur": 15000000,
      "max_pct": "2,5% Jahresumsatz",
      "basis": "CRA Art. 64 – je nachdem was höher ist"
    }
  },
  "control": {
    "measure": "CVE-Prozess mit SLAs, SBOM und ENISA-Meldeprozess für aktiv ausgenutzte Schwachstellen",
    "priority": "sofort",
    "type": "technisch"
  },
  "evidence": {
    "type": "CVE-Register + SBOM + ENISA-Meldungsnachweise",
    "template": "CRA Schwachstellenmanagement-Prozess",
    "audit_ready": true
  },
  "iso27001_mapping": {
    "controls": [
      "A.12.6.1",
      "A.14.2.3",
      "A.16.1.3"
    ],
    "coverage": "teilweise",
    "note": "ISO A.12.6.1 (Handhabung von Schwachstellen) deckt CVE-Prozess ab. ENISA-Meldung (24h) und SBOM sind CRA-spezifisch ohne ISO-Äquivalent."
  },
  "iso27001_2022_controls": [
    "5.5",
    "8.8"
  ],
  "_bam_uri": "https://bam.brain-media.de/id/CRA-002a-CVE",
  "_model_version": "2.0",
  "_service": "Compliance Trace",
  "_license": "CC BY-SA 4.0 (see LICENSE-DATA)",
  "_attribution": "Brain-Media Audit Model (BAM), Dr. Holger Reibold, brain-media.de"
}