Przejdź do treści

Zarządzanie lukami w zabezpieczeniach i zgłaszanie CVD dla produktów firmy IFA

Czy chcesz zgłosić lukę w zabezpieczeniach jednego z naszych produktów?

Tutaj znajdą Państwo procedurę skoordynowanego ujawniania luk w zabezpieczeniach (Coordinated Vulnerability Disclosure – CVD) firmy IFA Technology GmbH (zwanej dalej „IFA”)

Coordinated Vulnerability Disclosure (CVD) Policy

Compliance – IFA Governance

1. Basic details

Author
Andreas Dinnebier

Overall responsibility GL Elektrik
Christian Holl

Managing Director
Stefan Neumann

Aim and purpose
To ensure the proper coordinated disclosure of vulnerabilities in IFA systems.

Scope
This compliance policy applies to vulnerabilities relating to IFA products containing digital elements and associated services, in particular:

  • supplied control and automation software systems, including PLC programmes, visualisation and control system designs,
  • switchgear and control cabinets manufactured, insofar as the IFA configuration, parameterisation or software contained therein is affected,
  • remote maintenance and telecontrol access provided,
  • the websites www.ifa-technology.net and www.ifa-technology.de.

In the case of third-party components that IFA has integrated into its own deliveries, IFA will accept reports, assess the impact on its own delivery and coordinate the forwarding of the report to the relevant manufacturer, insofar as this is necessary to mitigate risk.

Not covered by the scope
In particular, the following are not the primary responsibility of IFA:

  • Vulnerabilities in unmodified third-party components purchased from third parties, provided that IFA did not cause them; however, reports are accepted and, where IFA’s deliveries may be affected, coordinated with the relevant manufacturer.
  • Equipment and systems that have been substantially modified by third parties, inso-far as the vulnerability is attributable to such modification.
  • Customers’ operational and network infrastructure, insofar as this is not part of an IFA delivery or IFA configuration.

Responsible (Role)
Managing Director: Overall responsibility, approval of key measures and escalation in the event of reportable incidents.
PSIRT / central reporting office: Receipt, documentation, assessment, coordination of technical measures, customer information and reporting to authorities.
Electrical/Automation/IT departments: technical analysis, risk assessment, development of updates, workarounds or other remedial measures.

Responsible for
Taking appropriate measures to ensure the coordinated disclosure of vulnerabilities in the IFA systems.

2. Contact

IFA Technology GmbH
Jurastraße 10, 86641 Rain am Lech, Germany
security@ifa-technology.de
+49 9090 70570-0

3. Basis of the Compliance Policy

IFA supplies process engineering systems incorporating control, automation and visualisation technology. Software and networked control systems form part of our supply. Despite careful development, vulnerabilities can never be completely ruled out. We are grateful to security researchers, customers, suppliers or regulatory authorities for bringing any potential vulnerabilities to our attention.

This Compliance Policy serves to fulfil the relevant requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act, CRA), in particular Annex I, Part II, point 5; Article 13(17); and Annex II, point 2.

4. Report vulnerabilities to

Email:security@ifa-technology.de

This is our single point of contact in accordance with Article 13(17) of the CRA. The address is also listed in our file www.ifa-technology.net/.well-known/security.txt in accordance with RFC 9116.

When reporting an incident, please provide the following details:

  1. Affected product, system or component, including, where possible, the type, project or version
  2. Description of the vulnerability and its potential impact
  3. Reproducible steps
  4. Your contact details and whether you wish to be named
  5. Whether you have any evidence that the vulnerability has already been exploited

Language
Deutsch oder Englisch.

Encryption
A suitable secure communication channel should be used for confidential technical details. IFA publishes or stores the current contact information, the preferred communication channel, the preferred languages and a reference to this policy in the file https://www.ifa-technology.net/.well-known/security.txt in accordance with RFC 9116.

5. Handling of reports

Acknowledgement of receipt
within 3 working days

Initial technical assessment (confirmed / not confirmed / further review)
within 10 working days

Status updates whilst the application is being processed
at least every 30 days

Resolution (update, configuration change or workaround)
as soon as technically and operationally possible; target 90 days from confirmation

In addition, we adhere to the following:

  • We treat your report confidentially and will only pass on your data to the extent that this is necessary to resolve the issue or is required by law.
  • We will inform affected customers of any necessary measures.
  • Upon request, we will credit you as the discoverer when the issue is published. We will not credit you without your express consent.
  • We do not pay any rewards. This policy is not a bug bounty programme.

6. Internal process, assessment and documentation

IFA documents every incoming vulnerability report in a traceable manner. The documentation includes, as a minimum, the date of receipt, the affected products or components, the technical assessment, the criticality rating, the basis for decision-making, the measures taken, customer communication, any reports to the authorities and the completion of the process.

The technical risk assessment is carried out in accordance with an appropriate and transparent procedure, e.g. based on exploitability, potential impact on the availability, integrity, confidentiality and security of the system, and existing mitigating measures. Critical and high risks are prioritised and, where necessary, escalated immediately to senior management.

Security updates, configuration changes, workarounds or other remedial measures are provided in such a way that users can understand the measures and apply them safely. Where necessary, IFA informs affected customers about the risk, the products affected, recommended measures, available updates and any residual risks.

6.1 Coordinated publishing

IFA generally publishes information on vulnerabilities in a coordinated and risk-based manner. As a rule, publication takes place as soon as a remedy is available and affected customers have been appropriately informed. In the case of actively exploited vulnerabilities or significant risks to customers, systems or users, a warning or risk information may also be required before a complete solution is made available.

  • Standard procedure: Coordinated disclosure 90 days after the report, or earlier once the fix has been rolled out.
  • In the case of actively exploited vulnerabilities, we inform affected customers immediately, even if a solution is not yet available.
  • For vulnerabilities in software for which IFA itself is responsible, IFA will assess whether to apply for a CVE identifier or coordinate this with the relevant authorities or manufacturers, and, where necessary, publish a security advisory at https://www.ifatechnology.net/en/security/.
  • If the deadline is insufficient in individual cases (e.g. because a system shutdown is required for the update), we will agree on an extension with you.

6.2 Rules for security testing (Safe Harbour) by the reporting party

Provided that reporters adhere to the following rules, IFA generally regards the investigation as having been coordinated in accordance with this policy and does not intend to assert its own legal claims arising from the investigation. This does not apply in cases of wilful damage, blackmail, unauthorised data exfiltration, endangering persons or plant, breach of applicable law or exceeding the limits set out below.

Permitted and encouraged

  • Investigation of systems belonging to the reporter or for which the reporter has the operator’s permission.
  • Notifying us before any details are disclosed to third parties or made public.

Not permitted

  • Interference with operational production facilities that may endanger people, disrupt processes or cause damage to property
  • Denial-of-service tests, load attacks, spam or social engineering directed at employees, customers or suppliers
  • Access to, alteration of or disclosure of thirdparty data beyond the minimum required for verification
  • Disclosure of details to third parties prior to the agreed publication

The Safe Harbour applies only to claims made by IFA. It is not binding on customers, operators or public authorities.

6.3 Statutory reporting obligations

Irrespective of this policy, IFA checks whether there are any statutory reporting obligations for every vulnerability report. Under Article 14 of the CRA, actively exploited vulnerabilities in products containing digital elements, as well as serious security incidents affecting the security of the product, must be reported simultaneously to ENISA and to the coordinating CSIRT responsible under Article 14(7) of the CRA via the single reporting platform provided for in Article 16 of the CRA.

For actively exploited vulnerabilities
the following are required in particular: an early warning without delay, at the latest within 24 hours of becoming aware of the issue; a vulnerability report without delay, at the latest within 72 hours of becoming aware of the issue; and a final report no later than 14 days after a corrective or risk mitigation measure becomes available.

For serious security incidents
an early warning must be issued within 24 hours, a report within 72 hours and, where necessary, a final report within one month of the 72-hour report.

Reporting to IFA may trigger such an investigation and, where applicable, a statutory reporting obligation. Personal data of reporting individuals will only be processed or disclosed to the extent necessary for handling the incident, mitigating risks or fulfilling statutory obligations.

Version V 1.0 | 24.09.2026