ETSI EN 304 622 V1.0.0 (2026-08)
Cyber Security (CYBER); CRA; Cybersecurity requirements for Security information and event management (SIEM) systems
General Information
- Abstract
DEN/CYBER-EUS-0010
- Status
- Not Published
- Technical Committee
- CYBER EUSR - European Union Standardization Request
- Current Stage
- 7 - Dispatch to NSOs / TC
- Due Date
- 31-Oct-2026
Frequently Asked Questions
ETSI EN 304 622 V1.0.0 (2026-08) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "Cyber Security (CYBER); CRA; Cybersecurity requirements for Security information and event management (SIEM) systems". This standard covers: DEN/CYBER-EUS-0010
DEN/CYBER-EUS-0010
ETSI EN 304 622 V1.0.0 (2026-08) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
Draft ETSI EN 304 622 V1.0.0 (2026-08)
HARMONISED EUROPEAN STANDARD
Cyber Security (CYBER);
CRA;
Cybersecurity requirements for Security information and event
management (SIEM) systems
2 Draft ETSI EN 304 622 V1.0.0 (2026-08)
Reference
DEN/CYBER-EUS-0010
Keywords
CRA, Cybersecurity, SIEM
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871
Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.
Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part of this document may be reproduced in any form, by any means and in any media, without the prior written
authorization of ETSI and except as expressly permitted below.
By way of exception and when the document is a normative deliverable (European Standard (EN),
Technical Specification (TS), Group Specification (GS) or ETSI Standard (ES)), ETSI authorizes to reproduce
and incorporate into products, services and technical documentation only those extracts (e.g. templates) that are strictly
necessary for the technical implementation of the normative deliverable, to ensure compliance with the latter.
Nothing in this notice shall be construed as limiting any mandatory exceptions to copyright provided by applicable law.
© ETSI 2026.
All rights reserved.
ETSI
3 Draft ETSI EN 304 622 V1.0.0 (2026-08)
Contents
Intellectual Property Rights . 11
Foreword . 11
Modal verbs terminology . 12
Introduction . 12
1 Scope . 13
2 References . 13
2.1 Normative references . 13
2.2 Informative references . 13
3 Definition of terms, symbols and abbreviations . 14
3.1 Terms . 14
3.2 Symbols . 15
3.3 Abbreviations . 15
4 Product context . 15
4.0 Introduction . 15
4.1 Product Functions . 16
4.2 Product Architecture. 16
4.3 Operational Environment . 16
4.3.1 General description . 16
4.3.2 Physical/Hardware environment . 17
4.3.3 Logical/Software environment. 17
4.3.4 Connectivity aspects . 17
4.4 Distribution of Security Functions . 17
4.4.1 General . 17
4.4.2 Security functions provided by the product . 17
4.4.3 Security functions provided to the product . 18
4.5 Users . 18
4.6 Use Cases . 18
4.6.1 Overview . 18
4.6.2 Guidance . 18
4.6.3 UC-1-RESEARCH: Research SIEM . 18
4.6.4 UC-2-HOME: Home SIEM . 19
4.6.5 UC-3-FLEET: Fleet monitoring . 19
4.6.6 UC-4-IOT: IoT monitoring . 19
5 Technical requirements for products . 20
5.1 Introduction . 20
5.1.1 Applicability of the requirements . 20
5.1.2 Applicability of Annex K . 20
5.1.3 Applicability of Annex R . 20
5.2 Appropriate level of cybersecurity . 20
5.2.1 Overview . 20
5.2.2 REQ-ALC-01 . 20
5.2.2.1 Requirement . 20
5.2.2.2 Applicability. 20
5.2.3 REQ-ALC-02 . 21
5.2.3.1 Requirement . 21
5.2.3.2 Applicability. 21
5.2.4 Mapping of requirements to use cases . 21
5.3 No known exploitable vulnerabilities . 21
5.3.1 Overview . 21
5.3.2 REQ-KEV-01 . 21
5.3.2.1 Requirement . 21
5.3.2.2 Applicability. 21
5.3.2.3 Use-case applicability . 21
ETSI
4 Draft ETSI EN 304 622 V1.0.0 (2026-08)
5.3.3 Mapping of requirements to use cases . 22
5.4 Secure by default configuration . 22
5.4.1 Overview . 22
5.4.2 Requirements . 22
5.5 Security updates . 22
5.5.1 Overview . 22
5.5.2 REQ-SU-01. 22
5.5.2.1 Requirement . 22
5.5.2.2 Applicability. 22
5.5.3 Mapping of requirements to use cases . 23
5.6 Authentication and access control . 23
5.6.1 Overview . 23
5.6.2 REQ-AAC-01 . 23
5.6.2.1 Requirement . 23
5.6.2.2 Applicability. 23
5.6.3 Mapping of requirements to use cases . 23
5.7 Confidentiality protection . 23
5.7.1 Overview . 23
5.7.2 REQ-CON-01 . 23
5.7.2.1 Requirement . 23
5.7.2.2 Applicability. 23
5.7.3 REQ-CON-02 . 24
5.7.3.1 Requirement . 24
5.7.3.2 Applicability. 24
5.7.4 REQ-CON-03 . 24
5.7.4.1 Requirement . 24
5.7.4.2 Applicability. 24
5.7.5 Mapping of requirements to use cases . 24
5.8 Integrity protection . 24
5.8.1 Overview . 24
5.8.2 REQ-INT-01 . 24
5.8.2.1 Requirement . 24
5.8.2.2 Applicability. 25
5.8.3 REQ-INT-02 . 25
5.8.3.1 Requirement . 25
5.8.3.2 Applicability. 25
5.8.4 REQ-INT-03 . 25
5.8.4.1 Requirement . 25
5.8.4.2 Applicability. 25
5.8.5 Mapping of requirements to use cases . 25
5.9 Data minimisation . 25
5.9.1 Overview . 25
5.9.2 REQ-DM-01 . 26
5.9.2.1 Requirement . 26
5.9.2.2 Applicability. 26
5.9.3 Mapping of requirements to use cases . 26
5.10 Availability protection . 26
5.10.1 Overview . 26
5.10.2 REQ-AP-01. 26
5.10.2.1 Requirement . 26
5.10.2.2 Applicability. 26
5.10.3 REQ-AP-02. 26
5.10.3.1 Requirement . 26
5.10.3.2 Applicability. 26
5.10.4 REQ-AP-03. 27
5.10.4.1 Requirement . 27
5.10.4.2 Applicability. 27
5.10.5 REQ-AP-04. 27
5.10.5.1 Requirement . 27
5.10.5.2 Applicability. 27
5.10.6 Mapping of requirements to use cases . 27
5.11 Non-interference . 27
ETSI
5 Draft ETSI EN 304 622 V1.0.0 (2026-08)
5.11.1 Overview . 27
5.11.2 REQ-NI-01 . 28
5.11.2.1 Requirement . 28
5.11.2.2 Applicability. 28
5.11.3 REQ-NI-02 . 28
5.11.3.1 Requirement . 28
5.11.3.2 Applicability. 28
5.11.4 Mapping of requirements to use cases . 28
5.12 Attack surface minimisation . 28
5.12.1 Overview . 28
5.12.2 REQ-ASM-01 . 28
5.12.2.1 Requirement . 28
5.12.2.2 Applicability. 28
5.12.3 Mapping of requirements to use cases . 29
5.13 Exploit mitigation . 29
5.13.1 Overview . 29
5.13.2 REQ-EM-01 . 29
5.13.2.1 Requirement . 29
5.13.2.2 Applicability. 29
5.13.3 Other requirements . 29
5.13.4 Mapping of requirements to use cases . 30
5.14 Monitoring . 30
5.14.1 Overview . 30
5.14.2 REQ-MON-01 . 30
5.14.2.1 Requirement . 30
5.14.2.2 Applicability. 30
5.14.3 REQ-MON-02 . 30
5.14.3.1 Requirement . 30
5.14.3.2 Applicability. 30
5.14.4 REQ-MON-03 . 30
5.14.4.1 Requirement . 30
5.14.4.2 Applicability. 30
5.14.5 Mapping of requirements to use cases . 31
5.15 Factory reset and data portability . 31
5.15.1 Overview . 31
5.15.2 REQ-DRT-01 . 31
5.15.2.1 Requirement . 31
5.15.2.2 Applicability. 31
5.15.3 REQ-DRT-02 . 31
5.15.3.1 Requirement . 31
5.15.3.2 Applicability. 31
5.15.4 Mapping of requirements to use cases . 32
6 Assessment criteria for compliance with technical requirements . 32
6.1 Introduction . 32
6.1.1 General . 32
6.1.2 Guidance for identifying interfaces or data processing . 33
6.2 Appropriate level of cybersecurity . 33
6.2.1 Overview . 33
6.2.2 REQ-ALC-01 . 33
6.2.2.1 Objective . 33
6.2.2.2 Preparation . 34
6.2.2.3 Activities . 34
6.2.2.4 Verdict . 34
6.2.2.5 Evidence . 34
6.2.2.6 Guidance . 35
6.2.3 REQ-ALC-02 . 35
6.2.3.1 Objective . 35
6.2.3.2 Preparation . 35
6.2.3.3 Activities . 35
6.2.3.4 Verdict . 36
6.2.3.5 Evidence . 36
ETSI
6 Draft ETSI EN 304 622 V1.0.0 (2026-08)
6.3 No known exploitable vulnerabilities . 36
6.3.1 Overview . 36
6.3.2 REQ-KEV-01 . 36
6.3.2.1 Objective . 36
6.3.2.2 Preparation . 36
6.3.2.3 Activities . 36
6.3.2.4 Verdict . 36
6.3.2.5 Evidence . 36
6.4 Secure by default configuration . 37
6.4.1 Overview . 37
6.5 Security updates . 37
6.5.1 Overview . 37
6.5.2 REQ-SU-01. 37
6.5.2.1 Objective . 37
6.5.2.2 Preparation . 37
6.5.2.3 Activities . 37
6.5.2.4 Verdict . 37
6.5.2.5 Evidence . 37
6.5.2.6 Guidance . 37
6.6 Authentication and access control . 38
6.6.1 Overview . 38
6.6.2 REQ-AAC-01 . 38
6.6.2.1 Objective . 38
6.6.2.2 Preparation . 38
6.6.2.3 Activities . 38
6.6.2.4 Verdict . 38
6.6.2.5 Evidence . 38
6.7 Confidentiality protection . 38
6.7.1 Overview . 38
6.7.2 REQ-CON-01 . 38
6.7.2.1 Objective . 38
6.7.2.2 Preparation . 38
6.7.2.3 Activities . 39
6.7.2.4 Verdict . 39
6.7.2.5 Evidence . 39
6.7.3 REQ-CON-02 . 39
6.7.3.1 Objective . 39
6.7.3.2 Preparation . 39
6.7.3.3 Activities . 39
6.7.3.4 Verdict . 39
6.7.3.5 Evidence . 39
6.7.3.6 Guidance . 39
6.7.4 REQ-CON-03 . 40
6.7.4.1 Objective . 40
6.7.4.2 Preparation . 40
6.7.4.3 Activities . 40
6.7.4.4 Verdict . 40
6.7.4.5 Evidence . 40
6.8 Integrity protection . 40
6.8.1 Overview . 40
6.8.2 REQ-INT-01 . 40
6.8.2.1 Objective . 40
6.8.2.2 Preparation . 40
6.8.2.3 Activities . 40
6.8.2.4 Verdict . 41
6.8.2.5 Evidence . 41
6.8.3 REQ-INT-02 . 41
6.8.3.1 Objective . 41
6.8.3.2 Preparation . 41
6.8.3.3 Activities . 41
6.8.3.4 Verdict . 41
6.8.3.5 Evidence . 41
ETSI
7 Draft ETSI EN 304 622 V1.0.0 (2026-08)
6.8.3.6 Guidance . 41
6.8.4 REQ-INT-03 . 42
6.8.4.1 Objective . 42
6.8.4.2 Preparation . 42
6.8.4.3 Activities . 42
6.8.4.4 Verdict . 42
6.8.4.5 Evidence . 42
6.9 Data minimisation . 42
6.9.1 Overview . 42
6.9.2 REQ-DM-01 . 42
6.9.2.1 Objective . 42
6.9.2.2 Preparation .
...



